Description
Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.13-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. While the vulnerability is in Oracle Bills of Material, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Bills of Material accessible data as well as unauthorized access to critical data or complete access to all Oracle Bills of Material accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification within Oracle Bills of Material
Action: Immediate Patch
AI Analysis

Impact

The flaw in Oracle Bills of Material permits a low‑privilege attacker with network access over HTTP to create, delete, or modify critical data. This is a broken access control weakness that compromises confidentiality and integrity of billing information and can extend to other components of the E‑Business Suite by broadening the scope of the compromise. The vulnerability is classified as CWE‑284 and can cause unauthorized data modification and potential full data exposure.

Affected Systems

Oracle Bills of Material (Oracle E‑Business Suite) versions 12.2.13 through 12.2.15 are affected. These releases expose Bills traffic without proper authorization checks, enabling low‑privileged users to act like administrators.

Risk and Exploitability

The CVSS 3.1 base score of 8.2 reflects high confidentiality and integrity impact. The EPSS score is less than 1%, indicating a low probability of exploitation, and the flaw is not listed in CISA KEV. Based on the description, the likely attack vector is HTTP from a network attacker with low privileges, which, if successful, can alter or delete data and potentially affect other Oracle E‑Business Suite components.

Generated by OpenCVE AI on September 18, 2026 at 17:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade to a fixed Oracle Bills of Material version as announced in Oracle’s security advisory.
  • Restrict HTTP access to the Bills of Material service to trusted networks or authenticated users, enforcing least privilege.
  • If the service is not required externally, isolate or disable it from public networks.

Generated by OpenCVE AI on September 18, 2026 at 17:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Bills of Material via HTTP

Thu, 17 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Bills of Material via HTTP
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.13-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. While the vulnerability is in Oracle Bills of Material, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Bills of Material accessible data as well as unauthorized access to critical data or complete access to all Oracle Bills of Material accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle bills Of Material
CPEs cpe:2.3:a:oracle:bills_of_material:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bills Of Material
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Bills Of Material
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:47.356Z

Reserved: 2026-08-31T15:40:57.359Z

Link: CVE-2026-83435

cve-icon Vulnrichment

Updated: 2026-09-18T18:15:26.850Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:52.060

Modified: 2026-09-18T19:17:00.650

Link: CVE-2026-83435

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T18:00:11Z

Weaknesses