Description
Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Recall Management). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Depot Repair accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Depot Repair. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality breach and partial denial of service
Action: Patch Now
AI Analysis

Impact

A low‑privileged attacker with network access over HTTP can exploit a flaw in Oracle Depot Repair’s Recall Management component. The vulnerability allows the attacker to read sensitive data or gain full access to all data exposed by Oracle Depot Repair and, if desired, induce a partial denial of service. The vulnerability maps to CWE-400. The impact is high on confidentiality and low on availability, as indicated by the CVSS vector.

Affected Systems

The affected product is Oracle Depot Repair for Oracle E‑Business Suite, specifically versions 12.2.3 through 12.2.15. This applies only to the Recall Management module within the depot repair component of the suite.

Risk and Exploitability

The CVSS score of 7.1 reflects a medium‑to‑high severity, with a low exploitation probability (EPSS < 1%) and no listing in the CISA KEV catalog. The attack vector is network based and requires only low privilege access, implying that anyone with network connectivity to the application could potentially exploit this without local system access. Because the vulnerability allows unauthorized data access and partial service disruption, organizations with exposed Depot Repair in the network should treat this as an immediate patching priority.

Generated by OpenCVE AI on September 22, 2026 at 00:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle’s latest patch or upgrade to a supported release of Oracle Depot Repair that addresses this recall management vulnerability
  • Restrict external HTTP access to the Oracle Depot Repair service using firewalls or VPN tunnels so that only trusted internal users can reach it
  • Ensure that database accounts used by Oracle Depot Repair are run with the minimum privileges necessary and consider disabling unused Recall Management functions until a patch is applied

Generated by OpenCVE AI on September 22, 2026 at 00:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Oracle Depot Repair Recall Management Vulnerability Enables Unauthorized Data Access and Partial Denial of Service

Mon, 21 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Recall Management Module in Oracle Depot Repair Enables Unauthorized Data Access over HTTP
Weaknesses CWE-200
CWE-284

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title Recall Management Module in Oracle Depot Repair Enables Unauthorized Data Access over HTTP
Weaknesses CWE-200
CWE-284

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Oracle Depot Repair Recall Management Vulnerability Allows Unauthorized Data Access and Partial Denial of Service
Weaknesses CWE-269
CWE-284

Wed, 16 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Oracle Depot Repair Recall Management Vulnerability Allows Unauthorized Data Access and Partial Denial of Service
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Recall Management). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Depot Repair accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Depot Repair. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
First Time appeared Oracle
Oracle depot Repair
CPEs cpe:2.3:a:oracle:depot_repair:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle depot Repair
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


Subscriptions

Oracle Depot Repair
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T19:37:31.394Z

Reserved: 2026-08-31T15:40:57.359Z

Link: CVE-2026-83436

cve-icon Vulnrichment

Updated: 2026-09-21T19:37:19.550Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:52.180

Modified: 2026-09-21T20:17:35.240

Link: CVE-2026-83436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T00:30:18Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption