PatchSiren

Oracle Corporation CVE debriefs · Page 5

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83356

A high-severity vulnerability exists in Oracle E-Business Suite's Enterprise Command Center Framework, allowing low-privileged attackers with network access via HTTP to compromise the framework and potentially impact additional products. Successful attacks can result in unauthorized access to critical data. The vulnerability is in the Security component of Enterprise Command Center Framework in V16. Defen [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83354

A vulnerability in Oracle Coherence of Oracle Fusion Middleware allows low-privileged attackers with network access via HTTP to potentially compromise Oracle Coherence and access critical data. The CVSS score is 6.3, indicating a medium severity. This vulnerability is difficult to exploit and may significantly impact additional products. Successful attacks can result in unauthorized access to critical dat [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83352

A high-severity vulnerability exists in Oracle XML Gateway, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-83352, allows a low-privileged attacker with network access via HTTP to compromise the Oracle XML Gateway. Successful attacks can result in unauthorized access to critical data and partial denial of service. This vulnerability affects versions 12.2.3-12.2.15 of Oracle [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83347

A vulnerability in Oracle Net Services of Oracle Database Server has been identified. The vulnerability is easily exploitable and allows an unauthenticated attacker with network access via TCPS to compromise Oracle Net Services, potentially leading to a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score is 6.5 with Availability impacts.

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83346

A vulnerability in Oracle Fusion Middleware Control allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products. Successful attacks require human interaction and can result in unauthorized data access and modifications. The vulnerability, tracked as CVE-2026-83346, is a medium-severity issue with a CVSS 3.1 Base Score of 5.4, indicating [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83345

A high-severity vulnerability exists in Oracle XML Gateway, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-83345, allows a low-privileged attacker with network access via HTTP to compromise the Oracle XML Gateway. Successful attacks can result in unauthorized access to critical data and partial denial of service. The vulnerability affects versions 12.2.3-12.2.15 of Oracle E [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83343

The CVE-2026-83343 vulnerability affects Oracle Utilities Network Management System, specifically versions 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A, and 25.12.0.0.0-25.12.0.0.3. This vulnerability is exploitable via HTTP by unauthenticated attackers, potentially leading to unauthorized access to critical data or complete access to all accessible data, as well as unauthorized update [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83341

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:47.470Z and has not been modified since then. The Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone) is vulnerable to unauthorized access. Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unau [truncated]

CRITICAL Oracle Corporation CVE published 2026-09-15

CVE-2026-83339

A critical vulnerability exists in Oracle WebCenter Enterprise Capture, allowing unauthenticated attackers to compromise the system via HTTP. Defenders should assess exposure and prioritize remediation due to the high CVSS score of 9.8 and potential for system takeover. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0 of the product. It is crucial for defenders to verify the integrity of the s [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83334

A high-severity vulnerability exists in Oracle Web Services Manager, a component of Oracle Fusion Middleware. This vulnerability, tracked as CVE-2026-83334, has a CVSS score of 7.4 and can allow an unauthenticated attacker with network access via SOAP to compromise the manager, potentially leading to unauthorized access to critical data or complete access to all Oracle Web Services Manager accessible data [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83332

A vulnerability in Oracle Applications Framework, a component of Oracle E-Business Suite, allows low-privileged attackers with network access via HTTP to compromise the framework. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data, as well as unauthorized update, insert, or delete access to some of Oracle Applicatio [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83330

CVE-2026-83330 is a high-severity vulnerability in Oracle's Helidon product, affecting versions 4.0.0-4.5.4. An unauthenticated attacker with network access via HTTP can exploit this vulnerability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. The CVSS 3.1 Base Score is 7.5, indicating a high availability impact. This vulnerability is located in the WebSocket component and allow [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83326

A high-severity vulnerability exists in the Siebel CRM Integration product of Oracle Siebel CRM, specifically in the Open Integration component. The vulnerability, which has a CVSS score of 7.5, allows an unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration and gain unauthorized access to critical data. This could lead to significant data breaches and disruptions in b [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83324

A vulnerability in Oracle Business Intelligence Enterprise Edition allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data, as well as unauthorized read acc [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83321

A vulnerability in Oracle Business Intelligence Enterprise Edition, specifically in the Analytics Actions component, allows low-privileged attackers with network access via HTTP to compromise the product. This could potentially impact additional products, allowing unauthorized access to critical data or update, insert, or delete access to some data. The vulnerability is easily exploitable and has a high s [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83320

A vulnerability in the Oracle BI Publisher product, specifically in the Administration component, allows low-privileged attackers with network access via HTTP to compromise the product. This vulnerability, CVE-2026-83320, is characterized as easily exploitable and requires human interaction from a person other than the attacker. Successful attacks can result in unauthorized access to critical data or comp [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83319

A vulnerability in Oracle BI Publisher's Web Service API allows low-privileged attackers with network access via SOAP to compromise the product, potentially impacting additional products and allowing unauthorized access to critical data. This high-severity vulnerability, with a CVSS 3.1 Base Score of 7.7, affects Oracle BI Publisher version 12.2.1.4.0. Defenders should prioritize verifying exposure, asses [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83318

A vulnerability in Oracle BI Publisher (component: Administration) allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in takeover of Oracle BI Publisher. This vulnerability has a high severity level and requires immediate attention from defenders. The affected versions are 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Defenders should assess ex [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83315

A vulnerability in Oracle BI Publisher allows low-privileged attackers with network access via SOAP to compromise the product, potentially leading to takeover. Oracle has released a security patch for this issue. The vulnerability, tracked as CVE-2026-83315, has a CVSS score of 8.8, indicating high risk. It affects Oracle BI Publisher versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Administrators and sec [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83314

A high-severity vulnerability exists in Oracle BI Publisher's Web Service API component, affecting versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. An attacker with low privileges and network access via SOAP can exploit this vulnerability, potentially leading to unauthorized data modifications and service disruptions. The vulnerability allows low-privileged attackers to compromise the system, which can re [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83313

A high-severity vulnerability exists in Oracle BI Publisher, specifically in the BI Platform Security component. This vulnerability allows low-privileged attackers with network access via HTTP to compromise the product, potentially leading to unauthorized access to critical data. The affected versions include 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0. Defenders should assess exposure and prioritize remediati [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83312

A vulnerability in Oracle BI Publisher, a component of Oracle Analytics, allows low-privileged attackers with network access via HTTP to compromise the product. This could potentially impact additional products and allow unauthorized access to critical data. The vulnerability is in the E-Business Suite - XDO component. Defenders should assess exposure, especially for versions 8.2.0.0.0, 12.2.1.4.0, and 26 [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83311

A high-severity vulnerability exists in Oracle BI Publisher, allowing low-privileged attackers with network access via SOAP to compromise the product. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data, as well as unauthorized update, insert, or delete access to some of Oracle BI Publisher accessible data.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83310

A vulnerability in Oracle BI Publisher of Oracle Analytics allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products. Successful attacks require human interaction and can result in unauthorized data access or modification. The vulnerability affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 of Oracle BI Publisher. Defenders shoul [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83309

A vulnerability in Oracle BI Publisher's Web Server component allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products and allowing unauthorized access to critical data or update, insert, or delete access to some data. The vulnerability, tracked as CVE-2026-83309, has a CVSS 3.1 Base Score of 8.5, indicating high severity. Defenders [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83308

A high-severity vulnerability exists in Oracle BI Publisher, allowing low-privileged attackers with network access via SOAP to compromise the system. Successful attacks can lead to unauthorized data modification and service disruption. The vulnerability is in the BI Platform Security component of Oracle BI Publisher. It allows low-privileged attackers with network access via SOAP to compromise Oracle BI P [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83307

A vulnerability in Oracle BI Publisher of Oracle Analytics allows low-privileged attackers with network access via HTTP to compromise the product, potentially leading to unauthorized data access, modification, and partial denial of service. The vulnerability affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 of Oracle BI Publisher. Successful attacks can result in unauthorized creation, deletion, or [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83305

The CVE-2026-83305 vulnerability affects Oracle BI Publisher, a component of Oracle Analytics. This high-severity vulnerability allows unauthenticated attackers with network access via HTTP to compromise the system, potentially leading to unauthorized access to critical data, update, insert or delete access to some data, and partial denial of service. The CVSS 3.1 Base Score is 8.6, indicating high severi [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83304

A vulnerability in Oracle Business Intelligence Enterprise Edition allows unauthenticated attackers with network access via HTTP to compromise the product, potentially impacting additional products. Successful attacks can result in unauthorized data access, modification, and partial denial of service. This high-severity vulnerability, tracked as CVE-2026-83304, requires immediate attention from Oracle Bus [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83303

A high-severity vulnerability exists in Oracle BI Publisher, allowing low-privileged attackers with network access via SOAP to compromise the product. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle BI Publisher accessible data, as well as unauthorized read access to a subset of Oracle BI Publisher accessible data.