Description
Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Assets. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Assets accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to critical data
Action: Apply Patch
AI Analysis

Impact

The vulnerability in the Oracle Assets component of Oracle E-Business Suite permits a low‑privileged attacker with network access over HTTP to obtain unauthorized access to critical or all data stored within Oracle Assets. It carries a confidentiality impact as reflected by the CVSS score of 6.5 and the vector indicating a high confidentiality impact without integrity or availability consequences.

Affected Systems

Oracle Corporation’s Oracle Assets product, part of the Oracle E-Business Suite's Internal Operations component, is affected. Versions 12.2.3 through 12.2.15 are vulnerable. Any installation of these releases that is reachable via HTTP is susceptible.

Risk and Exploitability

The risk is moderate with a CVSS base score of 6.5. The EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely using network access to the HTTP interface, requiring only low privileges and no user interaction. The vulnerability can be exploited by an attacker who can reach the application.

Generated by OpenCVE AI on September 21, 2026 at 23:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade to a non‑affected version as advised in Oracle’s security alert.
  • Restrict network access to the Oracle Assets HTTP service to trusted hosts or subnets.
  • Monitor logs and network traffic for anomalous activity against the Oracle Assets endpoint.

Generated by OpenCVE AI on September 21, 2026 at 23:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Allows Unauthorized Data Access in Oracle Assets

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Data Access in Oracle Assets
Weaknesses CWE-284

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Data Access in Oracle Assets
Weaknesses CWE-284

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Oracle Assets Unauthorized Data Access via Low‑Privilege HTTP Exploit
Weaknesses CWE-284

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Oracle Assets Unauthorized Data Access via Low‑Privilege HTTP Exploit
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Assets. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Assets accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle assets
CPEs cpe:2.3:a:oracle:assets:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle assets
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T19:09:09.961Z

Reserved: 2026-08-31T15:40:57.359Z

Link: CVE-2026-83443

cve-icon Vulnrichment

Updated: 2026-09-21T19:09:04.197Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:52.960

Modified: 2026-09-21T20:17:35.493

Link: CVE-2026-83443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T00:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor