PatchSiren

Oracle Corporation CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87154

A high-severity vulnerability exists in Oracle Product Hub, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-87154, allows a low-privileged attacker with network access via HTTP to compromise the Oracle Product Hub. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Product Hub accessible data, as well as un [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87153

A high-severity vulnerability exists in Oracle Product Hub, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-87153, allows a low-privileged attacker with network access via HTTP to compromise the Oracle Product Hub. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Product Hub accessible data, as well as un [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87152

A vulnerability in Oracle Installed Base of Oracle E-Business Suite (component: Create Item Instance) allows low-privileged attackers with network access via HTTP to compromise the product. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Installed Base accessible data, as well as unauthorized access to critical data or complete access [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87151

A high-severity vulnerability exists in Oracle Bills of Material, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-87151, allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Bills of Material accessible data.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87149

A high-severity vulnerability exists in Oracle Contract Lifecycle Management for Public Sector within Oracle E-Business Suite, specifically in the Award/PO component. This issue, tracked as CVE-2026-87149, allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation can lead to unauthorized access to critical data and potentially allow unauthorized update [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87147

A high-severity vulnerability exists in Oracle Hyperion Data Relationship Management 11.2.26.0.000. This difficult-to-exploit vulnerability requires high privileges and network access via HTTP to compromise the product. Successful attacks can lead to unauthorized creation, deletion, or modification of critical data and unauthorized access to critical or all accessible data within the product.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87146

A vulnerability in Oracle Hyperion Data Relationship Management allows low-privileged attackers with network access via HTTP to compromise the product, potentially leading to unauthorized access to critical data or update, insert, or delete access to some data. The vulnerability affects the Access and security component of Oracle Hyperion Data Relationship Management, version 11.2.26.0.000. Successful att [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87145

A vulnerability in Oracle Hyperion Data Relationship Management allows unauthenticated attackers to compromise the product via HTTP, potentially leading to unauthorized data access and partial denial of service. The vulnerability affects the Access and security component of Oracle Hyperion Data Relationship Management, version 11.2.26.0.000. Successful attacks can result in unauthorized update, insert or [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87143

A high-severity vulnerability exists in Oracle Hyperion Data Relationship Management, affecting version 11.2.26.0.000. This difficult-to-exploit vulnerability allows unauthenticated attackers with network access via TCP to compromise the product, potentially leading to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical or all accessible data.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87136

CVE-2026-87136 is a high-severity vulnerability in Oracle Hyperion Data Relationship Management, allowing unauthenticated attackers to access critical data via HTTP. Defenders should assess exposure, prioritize remediation, and verify inventory. The vulnerability affects version 11.2.26.0.000 and has a CVSS 3.1 Base Score of 7.5 with confidentiality impacts. Defenders must review the CVE record and NVD en [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87135

A vulnerability in Oracle Hyperion Data Relationship Management, a component of Oracle Hyperion, allows low-privileged attackers with network access via HTTP to compromise the product. This high-severity issue, with a CVSS score of 7.1, can lead to unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data, as well as unauthorized update, in [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87134

A vulnerability in Oracle Hyperion Data Relationship Management allows low-privileged attackers with network access to compromise the product, potentially impacting additional products and allowing unauthorized access to critical data. The vulnerability is in the Access and security component, and its CVSS 3.1 Base Score is 7.7, indicating high severity. Defenders should assess exposure and potential impa [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87133

A high-severity vulnerability exists in Oracle Hyperion Data Relationship Management, allowing high-privileged attackers with network access via HTTP to compromise the product and potentially impact additional products. Successful attacks can result in unauthorized access to critical data or complete access to all accessible data, as well as unauthorized update, insert, or delete access to some data.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87132

A vulnerability in Oracle Hyperion Data Relationship Management allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products. Successful attacks require human interaction and can result in unauthorized access to critical data or complete access to all accessible data, as well as unauthorized update, insert, or delete access to some data.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87131

A vulnerability in Oracle Hyperion Data Relationship Management allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products and allowing unauthorized access to critical data or update, insert, or delete access to some data. This vulnerability, tracked as CVE-2026-87131, affects Oracle Hyperion Data Relationship Management version 11.2.2 [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87130

A high-severity vulnerability exists in Oracle Hyperion Data Relationship Management 11.2.26.0.000, a product used for data management. The vulnerability, located in the Access and security component, allows unauthenticated attackers with network access via SMTP to compromise the product. This could lead to unauthorized creation, deletion, or modification of critical data. Defenders should assess exposure [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87127

CVE-2026-87127 is a high-severity vulnerability in the Oracle Purchasing product of Oracle E-Business Suite, specifically in the G-Invoicing component, affecting versions 12.2.10-12.2.15. The vulnerability allows low-privileged attackers with network access via HTTP to compromise Oracle Purchasing, potentially impacting additional products. Successful attacks can result in unauthorized access to critical [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87126

A vulnerability in Oracle Report Manager of Oracle E-Business Suite allows low-privileged attackers with network access via HTTP to compromise the manager, potentially leading to unauthorized data access and partial denial of service. Defenders should assess exposure, prioritize remediation, and verify affected versions and remediation with Oracle.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87125

A vulnerability in Oracle Financials for Asia/Pacific affects versions 12.2.8-12.2.15, allowing low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can lead to unauthorized data modification, access to critical data, and partial denial of service. The vulnerability has a high CVSS score of 8.3, indicating significant confidentiality, integrity, and availabili [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-87124

A vulnerability in Oracle iRecruitment, a component of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle iRecruitment accessible data. The vulnerability affects versions 12.2.3-12.2.15 and has a CVSS 3.1 Base Score of 7.7 (Confidentiality im [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83491

A vulnerability in Oracle iRecruitment of Oracle E-Business Suite (component: Internal Operations) allows an unauthenticated attacker with access to the physical communication segment to compromise Oracle iRecruitment. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle iRecruitment accessible data as well as unauthorized access to critic [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83490

A vulnerability in Oracle iRecruitment of Oracle E-Business Suite (component: Internal Operations) has been identified. The supported versions affected are 12.2.3-12.2.15. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle iRecruitment. While the vulnerability is in Oracle iRecruitment, attacks may significantly impact additional products (scope change). [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83488

A vulnerability in Helidon, a product of Oracle Fusion Middleware, has been identified. The vulnerability affects versions 4.0.0 through 4.5.4 and allows a low-privileged attacker with network access via HTTP to compromise Helidon. Successful attacks can result in unauthorized update, insert, or delete access to some Helidon accessible data, as well as unauthorized read access to a subset of Helidon accessible data.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83485

The CVE-2026-83485 vulnerability affects Oracle Product Hub's Item Catalog component in versions 12.2.3-12.2.15. This easily exploitable vulnerability allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Product Hub accessible [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83484

A vulnerability in Oracle US Federal Human Resources, an easily exploitable issue allowing low-privileged attackers with network access via HTTP to compromise the product, potentially leading to unauthorized data modification and read access. This high-severity issue, with a CVSS 3.1 Base Score of 7.1, affects versions 12.2.3-12.2.15 of Oracle E-Business Suite. Defenders managing Oracle E-Business Suite d [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83480

A vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket) has been identified. Supported versions that are affected are 4.0.0-4.5.4. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Helidon, potentially leading to a partial denial of service (partial DOS). The vulnerability can be exploited through HTTP, and defenders should v [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83477

A vulnerability in Oracle Work in Process (component: Workbenches) allows unauthenticated attackers with access to the physical communication segment to compromise the system, potentially leading to unauthorized creation, deletion, or modification of critical data. The CVE record was published on 2026-09-15T20:18:55.473Z and has not been modified since then. Defenders responsible for Oracle Work in Proces [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83465

CVE-2026-83465 is a high-severity vulnerability in Oracle Mobile Application Server, a component of Oracle E-Business Suite. The vulnerability, located in the MWA Terminal Server, allows unauthenticated attackers with network access via HTTP to compromise the server. Successful attacks require human interaction and can result in a hang or crash of the server and unauthorized access to some data. Defenders [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83461

A high-severity vulnerability exists in Oracle Mobile Application Server, a component of Oracle E-Business Suite. This vulnerability, tracked as CVE-2026-83461, allows unauthenticated attackers with network access via TCP to potentially access critical data and cause a partial denial of service. Oracle Mobile Application Server versions 12.2.3 through 12.2.15 are affected. The CVSS 3.1 Base Score for this [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83460

A vulnerability in Helidon, a product of Oracle Fusion Middleware, has been identified. The vulnerability affects versions 4.0.0 through 4.5.4 and allows an unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks can result in unauthorized update, insert, or delete access to some Helidon accessible data, as well as unauthorized read access to a subset of Helidon acc [truncated]