Description
Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: WebUI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Product Workbench, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Product Workbench accessible data as well as unauthorized read access to a subset of Oracle Product Workbench accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-09-15
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Modification and Disclosure
Action: Patch
AI Analysis

Impact

The vulnerability exists in the Oracle Product Workbench WebUI component and permits a low‑privileged attacker with HTTP network access to modify, insert, or delete data, as well as read restricted information. The flaw requires the attacker to compel another user to interact, enabling unauthorized access to data that should be protected by proper authorization controls.

Affected Systems

Oracle Product Workbench, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected. The vulnerability may also influence other Oracle products because of a scope change.

Risk and Exploitability

The CVSS 3.1 base score of 5.4 indicates moderate effects on confidentiality and integrity, while the EPSS score below 1% suggests a low probability of exploitation. The flaw is not listed in CISA’s KEV catalog. Successful exploitation requires network connectivity to the Product Workbench WebUI and the cooperation of a separate user, after which the attacker can modify, delete, or read data and potentially impact other Oracle applications due to the scope change.

Generated by OpenCVE AI on September 21, 2026 at 23:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest official Oracle patch or update that addresses the vulnerability for Product Workbench versions 12.2.3 to 12.2.15.
  • Limit HTTP access to the Product Workbench WebUI to trusted networks, VPNs, or internal firewalls.
  • Enforce strict access controls and enable detailed logging for data modification and read operations to detect unauthorized activity.

Generated by OpenCVE AI on September 21, 2026 at 23:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Oracle Product Workbench WebUI Data Modification and Disclosure Vulnerability

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure via Low-Privilege HTTP Access in Oracle Product Workbench
Weaknesses CWE-284

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure via Low-Privilege HTTP Access in Oracle Product Workbench
Weaknesses CWE-284

Fri, 18 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Title Oracle Product Workbench WebUI Vulnerability Allows Unauthorized Data Modification with Network Access
Weaknesses CWE-284

Wed, 16 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Oracle Product Workbench WebUI Vulnerability Allows Unauthorized Data Modification with Network Access
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: WebUI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Product Workbench, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Product Workbench accessible data as well as unauthorized read access to a subset of Oracle Product Workbench accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle product Workbench
CPEs cpe:2.3:a:oracle:product_workbench:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Workbench
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Product Workbench
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T19:24:01.298Z

Reserved: 2026-08-31T15:40:57.358Z

Link: CVE-2026-83431

cve-icon Vulnrichment

Updated: 2026-09-21T19:23:56.760Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:51.577

Modified: 2026-09-21T20:17:35.113

Link: CVE-2026-83431

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T23:30:18Z

Weaknesses