Description
Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Depot Repair Diagnostics). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Depot Repair accessible data as well as unauthorized access to critical data or complete access to all Oracle Depot Repair accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Access Control Bypass allowing unauthorized data modification and access
Action: Assess Impact
AI Analysis

Impact

The Oracle Depot Repair product of Oracle E‑Business Suite (Depot Repair Diagnostics module) contains a vulnerability that can be exploited by an attacker who already has high privileges on the network and can reach the service over HTTP. The flaw permits the creation, deletion or modification of critical data, or provides unauthorized access to all data stored in the Depot Repair component. This results in loss of confidentiality and integrity for all data that the component accesses.

Affected Systems

Oracle Corporation’s Oracle Depot Repair component, part of Oracle E‑Business Suite. Affected versions are 12.2.3 through 12.2.15. Systems running any of these releases should verify whether the vulnerability is present.

Risk and Exploitability

The CVSS 3.1 Base Score of 6.5 reflects a moderate severity with high confidentiality and integrity impact. The EPSS score of less than 1% indicates a low probability of exploitation at present, and it is not catalogued in the CISA KEV list. Exploitation requires an attacker to have high privileges on the network and able to access the service via HTTP; the attack complexity is low, so a knowledgeable adversary could carry out the attack without advanced skills.

Generated by OpenCVE AI on September 20, 2026 at 07:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available update or fix released by Oracle for Oracle Depot Repair 12.2.3 through 12.2.15.
  • Restrict HTTP access to the Depot Repair service to trusted hosts or networks to limit exposure to attackers with high privileges.
  • Enforce strict role‑based access controls within the Depot Repair diagnostics component to prevent unauthorized data modifications.

Generated by OpenCVE AI on September 20, 2026 at 07:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title High Privilege Access Control Bypass in Oracle Depot Repair via HTTP
Weaknesses CWE-285

Wed, 16 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title High Privilege Access Control Bypass in Oracle Depot Repair via HTTP
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Depot Repair Diagnostics). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Depot Repair accessible data as well as unauthorized access to critical data or complete access to all Oracle Depot Repair accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle depot Repair
CPEs cpe:2.3:a:oracle:depot_repair:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle depot Repair
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Depot Repair
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:47.831Z

Reserved: 2026-08-31T15:40:57.358Z

Link: CVE-2026-83433

cve-icon Vulnrichment

Updated: 2026-09-18T18:15:33.657Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:51.817

Modified: 2026-09-18T19:16:59.560

Link: CVE-2026-83433

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:15:16Z

Weaknesses