Description
Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Bills of Material accessible data as well as unauthorized access to critical data or complete access to all Oracle Bills of Material accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification and access
Action: Immediate patch
AI Analysis

Impact

The vulnerability allows a low‑privileged attacker who can reach Oracle Bills of Material over HTTP to create, delete or modify critical data. Successful exploitation results in unauthorized access to or manipulation of all Oracle Bills of Material data, compromising confidentiality and integrity. The weakness arises from inadequate access control in the Internal Operations component, permitting privilege‑level actions beyond those granted to the attacker.

Affected Systems

Oracle Bills of Material component of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15. An attacker with network access to the HTTP interface can exploit the issue.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 indicates a high‑severity impact. The EPSS score of less than 1% suggests that widespread is not listed in the CISA KEV catalog. The low exploitation probability, combined with the requirement for network access and the lack of special privileges, means the vulnerability is most relevant to internal threat actors or attackers who have compromised the network perimeter.

Generated by OpenCVE AI on September 18, 2026 at 17:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply vendor patch to Oracle Bills of Material version >12.2.15.
  • Restrict HTTP access to the Oracle Bills of Material interface to trusted IP ranges or internal users.
  • Enable and review logging of data modifications to detect unauthorized activity.

Generated by OpenCVE AI on September 18, 2026 at 17:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Access Enables Unauthorized Data Modification in Oracle Bills of Material

Wed, 16 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Access Enables Unauthorized Data Modification in Oracle Bills of Material
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Bills of Material accessible data as well as unauthorized access to critical data or complete access to all Oracle Bills of Material accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle bills Of Material
CPEs cpe:2.3:a:oracle:bills_of_material:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle bills Of Material
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Bills Of Material
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:46.462Z

Reserved: 2026-08-31T15:40:57.359Z

Link: CVE-2026-83448

cve-icon Vulnrichment

Updated: 2026-09-18T18:15:01.154Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:53.507

Modified: 2026-09-18T19:17:04.213

Link: CVE-2026-83448

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T18:00:11Z

Weaknesses