Description
Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Demand Signal Repository accessible data as well as unauthorized access to critical data or complete access to all Oracle Demand Signal Repository accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized remote data modification and access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Oracle Demand Signal Repository allows a low‑privileged attacker who can reach the system over HTTP to create, delete, or modify critical data and to gain unauthorized read or full access to all repository data. The flaw enables both confidentiality and integrity compromise, which means attackers can read sensitive information, corrupt data, or remove critical records. The weakness stems from improper authorization checks. As listed, the CVSS v3.1 base score is 8.1, indicating a high impact when the attack succeeds.

Affected Systems

Affected products are Oracle Demand Signal Repository for Oracle E‑Business Suite, versions 12.2.3 through 12.2.15. The affected component is Internal Operations. The issue applies to every installation that has not applied the latest release or patch.

Risk and Exploitability

The CVSS score of 8.1 reflects strong confidentiality and integrity damage but no availability impact. The EPSS score is below 1 %, suggesting that exploitation is low‑probability, yet the vulnerability is still capable of being exploited over the network without user interaction. The flaw is not listed in CISA’s KEV catalog, but the high score and direct HTTP access mean that an attacker could reach the target from any connected network segment. The attack path requires only network connectivity to the HTTP service and does not require privileged credentials.

Generated by OpenCVE AI on September 20, 2026 at 07:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Oracle’s latest security patch for Demand Signal Repository, which addresses the authorization flaw.
  • Limit HTTP access to the repository to trusted administrative networks and block traffic from untrusted sources.
  • Enforce strict role‑based access controls, ensuring that users only have the privileges required for their job functions, and regularly review user permissions.
  • Monitor audit logs for anomalous data creation, modification, or deletion activities.
  • If an immediate patch is not available, isolate the repository from external networks until the fix can be applied.

Generated by OpenCVE AI on September 20, 2026 at 07:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle Demand Signal Repository

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation and Access in Oracle Demand Signal Repository
Weaknesses CWE-285

Wed, 16 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation and Access in Oracle Demand Signal Repository
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Demand Signal Repository accessible data as well as unauthorized access to critical data or complete access to all Oracle Demand Signal Repository accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle demand Signal Repository
CPEs cpe:2.3:a:oracle:demand_signal_repository:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle demand Signal Repository
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Demand Signal Repository
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:46.310Z

Reserved: 2026-08-31T15:40:57.360Z

Link: CVE-2026-83455

cve-icon Vulnrichment

Updated: 2026-09-18T18:14:57.759Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:54.280

Modified: 2026-09-18T19:17:05.397

Link: CVE-2026-83455

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:30:17Z

Weaknesses