Description
Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self-serv What-if Analysis). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. While the vulnerability is in Oracle Advanced Benefits, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Advanced Benefits. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides within the Self‑serv What‑if Analysis component of Oracle Advanced Benefits and enables a high‑privileged attacker with network access over HTTP to compromise the application. Successful exploitation results in full control of Oracle Advanced Benefits, affecting confidentiality, integrity, and availability of the data and services it manages. The attack requires a network connection to the application and benefits from a lack of proper access control.

Affected Systems

Oracle Corporation’s Oracle Advanced Benefits, versions 12.2.3 through 12.2.15, are impacted. The vulnerability is specific to the Self‑serv What‑if Analysis component but can have broader implications for other products in the Oracle E‑Business Suite ecosystem.

Risk and Exploitability

The CVSS v3.1 Base Score of 8.0 reflects high severity, with the attack requiring network access, high privileges, and no user interaction. The EPSS score of less than 1% indicates a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the vulnerability allows a high‑privileged attacker to take over Oracle Advanced Benefits, it represents a significant threat, especially if the attacker already has network access. The likely attack path involves sending a specially crafted HTTP request to the Self‑serv What‑if Analysis endpoint, exploiting insufficient authorization checks to gain elevated privileges.

Generated by OpenCVE AI on September 17, 2026 at 23:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle Advanced Benefits security patch that addresses this vulnerability.
  • Restrict HTTP access to the Advanced Benefits application to trusted IP addresses or internal networks only.
  • Configure the application to run with the least privilege necessary and review user role permissions for the Self‑serv What‑if Analysis function.
  • Monitor application logs for unauthorized access attempts and abnormal activity related to Self‑serv What‑if Analysis.

Generated by OpenCVE AI on September 17, 2026 at 23:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Title High Privilege Escalation via Self‑Serv What‑if Analysis in Oracle Advanced Benefits
Weaknesses CWE-277
CWE-284

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title High Privilege Escalation via Self‑Serv What‑if Analysis in Oracle Advanced Benefits
Weaknesses CWE-277
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self-serv What-if Analysis). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. While the vulnerability is in Oracle Advanced Benefits, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Advanced Benefits. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle advanced Benefits
CPEs cpe:2.3:a:oracle:advanced_benefits:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle advanced Benefits
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Advanced Benefits
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T13:00:22.443Z

Reserved: 2026-08-31T15:40:57.362Z

Link: CVE-2026-83483

cve-icon Vulnrichment

Updated: 2026-09-17T12:58:04.323Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:56.030

Modified: 2026-09-17T14:17:45.410

Link: CVE-2026-83483

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T23:45:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management