Description
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.12-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. While the vulnerability is in Oracle Complex Maintenance, Repair and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair and Overhaul accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 8.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L).
Published: 2026-09-15
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data access and partial denial of service
Action: Immediate Patch
AI Analysis

Impact

A flaw in Oracle Complex Maintenance, Repair and Overhaul allows an attacker with low privileges to reach the system over HTTP, read confidential information, obtain full access to all exposed data, and trigger a partial denial of service. The weakness results in a high confidentiality impact and a low availability impact as documented by the CVSS Base Score of 8.5.

Affected Systems

The vulnerability applies to Oracle E‑Business Suite instances of the Complex Maintenance, Repair and Overhaul component, specifically supported releases 12.2.12 through 12.2.15. The affected portion is the Internal Operations module, with the potential to extend across other Oracle products due to the scope change flag in the CVSS vector.

Risk and Exploitability

EPSS indicates a below‑1 % probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, yet the high CVSS score signals a serious risk. Attackers can launch the exploit remotely from any network host capable of reaching the service, requiring only low privileges to initiate the breach. If successful, the attacker can compromise data confidentiality completely and disrupt service availability to a partial degree, impacting business operations.

Generated by OpenCVE AI on September 20, 2026 at 07:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle patches for the 12.2.12‑12.2.15 releases to remove the flaw.
  • Restrict HTTP access to the service by configuring firewall or VPN rules that allow only trusted internal hosts.
  • Enforce strict privilege limits for all accounts accessing the product, removing unnecessary low‑privileged users.
  • Monitor system logs for anomalous login attempts or unusual data retrieval patterns and set alerts for such activity.

Generated by OpenCVE AI on September 20, 2026 at 07:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title Remote Data Exposure and Partial Denial of Service via HTTP in Oracle Complex Maintenance
Weaknesses CWE-200
CWE-285

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Partial Denial of Service via Network HTTP in Oracle Complex Maintenance, Repair and Overhaul
Weaknesses CWE-200
CWE-284

Wed, 16 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Partial Denial of Service via Network HTTP in Oracle Complex Maintenance, Repair and Overhaul
Weaknesses CWE-200
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.12-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. While the vulnerability is in Oracle Complex Maintenance, Repair and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair and Overhaul accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 8.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L).
First Time appeared Oracle
Oracle complex Maintenance Repair And Overhaul
CPEs cpe:2.3:a:oracle:complex_maintenance__repair_and_overhaul:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle complex Maintenance Repair And Overhaul
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Oracle Complex Maintenance Repair And Overhaul
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-22T14:24:21.521Z

Reserved: 2026-08-31T15:40:57.358Z

Link: CVE-2026-83425

cve-icon Vulnrichment

Updated: 2026-09-22T14:22:39.559Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:51.133

Modified: 2026-09-22T15:17:18.437

Link: CVE-2026-83425

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:15:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-285

    Improper Authorization