PatchSiren

Oracle Corporation CVE debriefs · Page 4

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83457

A high-severity vulnerability exists in Oracle Demand Signal Repository, a component of Oracle E-Business Suite. The vulnerability, which has a CVSS score of 8.1, allows a low-privileged attacker with network access via HTTP to compromise the repository, potentially leading to unauthorized data modifications and service disruptions. This vulnerability is particularly concerning as it can be exploited by a [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83455

A vulnerability in Oracle Demand Signal Repository of Oracle E-Business Suite (component: Internal Operations) allows a low-privileged attacker with network access via HTTP to compromise the repository. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Demand Signal Repository accessible data, as well as unauthorized access to critical [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83449

A vulnerability in Oracle Bills of Material, a component of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized access to critical data and partial denial of service. The vulnerability affects versions 12.2.3-12.2.15 and has a CVSS 3.1 Base Score of 8.5 with Confidentiality and Availability impacts. [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83448

A high-severity vulnerability exists in Oracle Bills of Material, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-83448, allows a low-privileged attacker with network access via HTTP to compromise the system, potentially leading to unauthorized data access and modification. This vulnerability is easily exploitable and can result in unauthorized creation, deletion, or modific [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83447

A high-severity vulnerability exists in Oracle Bills of Material, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-83447, allows a low-privileged attacker with network access via HTTP to compromise the system, potentially leading to unauthorized data access and modification. This vulnerability has a CVSS score of 8.1, indicating high impacts on confidentiality and integrity. [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83446

The CVE-2026-83446 vulnerability affects Oracle Financials Common Modules, specifically versions 12.2.3-12.2.15. It is a high-severity issue allowing low-privileged attackers with network access via HTTP to potentially access or modify critical data. The vulnerability has a CVSS 3.1 Base Score of 8.1, indicating high impacts on confidentiality and integrity. Defenders should prioritize verifying exposure [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83443

A vulnerability in Oracle Assets, a component of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to compromise the system and gain unauthorized access to critical data. The CVSS score is 6.5, indicating a medium severity. This vulnerability affects versions 12.2.3-12.2.15 of Oracle E-Business Suite. Defenders should verify exposure and assess the impact on their syst [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83441

A vulnerability in Oracle Product Hub of Oracle E-Business Suite (component: Internal Operations) allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Product Hub accessible data, as well as unauthorized access to critical data or complete access to al [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83439

A vulnerability in Helidon, a product of Oracle Fusion Middleware, has been identified. The vulnerability affects versions 3.0.0-3.2.20 and 4.0.0-4.5.4, allowing a low-privileged attacker with network access via HTTP to compromise Helidon. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Helidon accessible data, as well as unauthorized access [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83438

A high-severity vulnerability exists in Oracle Engineering within Oracle E-Business Suite, affecting versions 12.2.3-12.2.15. This difficult-to-exploit vulnerability allows a low-privileged attacker with network access via HTTP to compromise Oracle Engineering, potentially impacting additional products. Successful attacks can result in unauthorized creation, deletion, or modification access to critical da [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83437

A vulnerability in Oracle Engineering, a component of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to compromise the system, potentially impacting additional products. Successful attacks can result in unauthorized access to critical data. The vulnerability affects versions 12.2.3-12.2.15 of Oracle E-Business Suite and has a CVSS 3.1 Base Score of 7.7, indicating h [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83436

A vulnerability in Oracle Depot Repair, a component of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to compromise the system. Successful attacks can result in unauthorized access to critical data and partial denial of service. The vulnerability affects versions 12.2.3-12.2.15 and has a CVSS 3.1 Base Score of 7.1, indicating high severity. Defenders should prioriti [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83435

A high-severity vulnerability exists in Oracle Bills of Material, a component of Oracle E-Business Suite. This vulnerability, tracked as CVE-2026-83435, has a CVSS score of 8.2 and can allow a low-privileged attacker with network access via HTTP to compromise the product. While the vulnerability is specific to Oracle Bills of Material, successful attacks could significantly impact additional products. The [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83434

A vulnerability in Oracle Product Workbench of Oracle E-Business Suite (component: Internal Operations) allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Product Workbench accessible data, as well as unauthorized access to critical data or complete [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83433

A vulnerability in Oracle Depot Repair, a component of Oracle E-Business Suite, allows high-privileged attackers with network access via HTTP to compromise the system. This could lead to unauthorized data access and modification. The vulnerability affects versions 12.2.3-12.2.15 of Oracle E-Business Suite and has a CVSS 3.1 Base Score of 6.5, indicating medium severity. Defenders should assess exposure an [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83432

A vulnerability in Oracle Depot Repair, a component of Oracle E-Business Suite, allows low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can lead to unauthorized creation, deletion, or modification of critical data or all Oracle Depot Repair accessible data, as well as unauthorized access to critical data or complete access to all Oracle Depot Repair accessible data.

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83431

A vulnerability exists in Oracle Product Workbench, a component of Oracle E-Business Suite. The vulnerability is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks require human interaction and can result in unauthorized update, insert, or delete access to some accessible data, as well as unauthorized read access [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83430

A high-severity vulnerability exists in Oracle Product Workbench, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-83430, allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Product Workbench accessible data, as well as u [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83429

The CVE-2026-83429 vulnerability affects Oracle Demand Signal Repository versions 12.2.3-12.2.15, allowing low-privileged attackers with network access via HTTP to compromise data integrity and confidentiality. Defenders should prioritize verifying exposure and assessing potential impact. The vulnerability has a CVSS 3.1 Base Score of 8.1, indicating high severity. The CVE record was published on 2026-09- [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83428

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:51.247Z and has not been modified since then. This vulnerability in Oracle Demand Signal Repository allows low-privileged attackers with network access via HTTP to compromise the repository, potentially leading to unauthorized data access or modification. Defenders managing Oracle Demand Si [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83425

A vulnerability in Oracle Complex Maintenance, Repair and Overhaul, a product of Oracle E-Business Suite, has been identified. The vulnerability affects versions 12.2.12-12.2.15 and allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized access to critical data and partial denial of service.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83424

The CVE-2026-83424 vulnerability affects Oracle JDeveloper, specifically versions 12.2.1.4.0 and 14.1.2.0.0. This high-severity vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle JDeveloper, potentially leading to unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. Defenders should prioritize verifying exposure of [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83422

PatchSiren debrief of CVE-2026-83422, a high-severity vulnerability in Oracle Identity Manager's OIM Legacy UI component. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise the system, requiring human interaction. Successful attacks can result in unauthorized data access and modification, with potential impacts including data breaches. Defenders should prioritize [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83419

A vulnerability in Oracle Communications Cloud Native Core Security Edge Protection Proxy allows low-privileged attackers with network access via HTTP to compromise the product, potentially leading to unauthorized data updates, insertions, deletions, and read access. The vulnerability affects Oracle Communications Cloud Native Core Security Edge Protection Proxy versions 26.1.200 and 25.2.201. Successful [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83418

A high-severity vulnerability exists in Oracle Communications Cloud Native Core Security Edge Protection Proxy (SEPP), a component of Oracle Communications. This difficult-to-exploit vulnerability allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products. The vulnerability can result in unauthorized creation, deletion, or modification [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83417

A high-severity vulnerability exists in Oracle Communications Cloud Native Core Security Edge Protection Proxy (SEPP). An unauthenticated attacker with physical access to the communication segment can compromise the product, leading to unauthorized data access and modification. The vulnerability affects versions 26.1.200 and 25.2.201. Defenders should prioritize verifying exposure and applying patches due [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83416

A vulnerability in Oracle Coherence of Oracle Fusion Middleware allows low-privileged attackers with network access via HTTP to compromise the product, potentially causing a partial denial of service. The CVSS score is 4.3, indicating a medium severity. This vulnerability affects Oracle Coherence versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Defenders should assess exposure and potential im [truncated]

LOW Oracle Corporation CVE published 2026-09-15

CVE-2026-83413

A vulnerability in Oracle Coherence of Oracle Fusion Middleware allows high-privileged attackers with logon access to the infrastructure to potentially update, insert or delete some accessible data. The CVSS score is 1.9, indicating a low severity. This vulnerability requires attention from Oracle Coherence administrators and users with high privileges to assess exposure and prioritize verification and pa [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83412

A vulnerability in Oracle Coherence of Oracle Fusion Middleware allows low-privileged attackers with network access via TCP to compromise the product, potentially leading to unauthorized data access or modification. The vulnerability affects versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, and 15.1.1.0.0. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data [truncated]

LOW Oracle Corporation CVE published 2026-09-15

CVE-2026-83369

A vulnerability in Oracle Access Manager allows a low-privileged attacker with network access via HTTP to cause a partial denial of service. The CVSS score is 3.1, indicating a low severity. This vulnerability affects Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0. Defenders should assess exposure and verify the impact on their systems, especially those using these versions. The vulnerability ca [truncated]