Description
Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. Successful attacks of this vulnerability can result in takeover of Oracle Document Management and Collaboration. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Takeover of Oracle Document Management
Action: Patch Now
AI Analysis

Impact

The Oracle Document Management and Collaboration product contains an easily exploitable flaw that allows a low‑privileged attacker with network access via HTTP to compromise the system and ultimately take over the application. The flaw can expose confidentiality, integrity, and availability of all data managed by the application. The weakness is consistent with improper authorization, enabling an attacker to act beyond intended privileges.

Affected Systems

Affected is Oracle Corporation’s Document Management and Collaboration component of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15. The product is widely deployed in enterprise environments.

Risk and Exploitability

The CVSS base score of 8.8 indicates high severity, while the EPSS score of less than 1% suggests that exploit attempts are currently uncommon. The flaw requires only low‑privileged network access and does not require user interaction from the network alone. Because the vulnerability is not listed in the CISA KEV catalog, it has not yet been confirmed as widely exploited but should be treated as a serious risk. The likely attack vector is remote over the network to the HTTP interface.

Generated by OpenCVE AI on September 20, 2026 at 06:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch or upgrade Oracle Document Management and Collaboration to version 12.2.16 or later as recommended in Oracle’s security advisory.
  • Restrict network access to the Document Management component’s HTTP interface to trusted IP ranges or through a VPN to reduce exposure.
  • Enforce least‑privilege access control and enable multi‑factor authentication for internal users to limit the impact of any low‑privileged compromise.

Generated by OpenCVE AI on September 20, 2026 at 06:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Takeover Vulnerability in Oracle Document Management

Fri, 18 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Compromise in Oracle Document Management
Weaknesses CWE-260
CWE-285

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Compromise in Oracle Document Management
Weaknesses CWE-260
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. Successful attacks of this vulnerability can result in takeover of Oracle Document Management and Collaboration. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle document Management And Collaboration
CPEs cpe:2.3:a:oracle:document_management_and_collaboration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle document Management And Collaboration
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Document Management And Collaboration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:23.518Z

Reserved: 2026-08-31T15:40:57.360Z

Link: CVE-2026-83454

cve-icon Vulnrichment

Updated: 2026-09-17T12:58:29.806Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:54.167

Modified: 2026-09-17T14:17:44.500

Link: CVE-2026-83454

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:00:08Z

Weaknesses
  • CWE-269

    Improper Privilege Management