PatchSiren

Oracle Corporation CVE debriefs · Page 6

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83302

A vulnerability in Oracle BI Publisher's BI Publisher Security component allows low-privileged attackers with network access via HTTP to compromise the product. This could lead to unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data, and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. The vulnerability has a CVSS [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83300

A vulnerability in Oracle XML Gateway of Oracle E-Business Suite (component: Install) allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle XML Gateway.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83297

A high-severity vulnerability exists in Oracle BI Publisher, allowing low-privileged attackers with network access via LDAP to compromise the system. Successful attacks can lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to critical or all accessible data. This vulnerability, tracked as CVE-2026-83297, affects Oracle BI Publisher versions 8.2.0.0.0 [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83287

A vulnerability in Oracle Business Intelligence Enterprise Edition's Presentation Services component allows low-privileged attackers with network access via SOAP to compromise the product. This could potentially impact additional products, allowing unauthorized access to critical data. The vulnerability has a CVSS 3.1 Base Score of 7.7, indicating high severity. Defenders should prioritize verifying expos [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83285

A vulnerability in Oracle Business Intelligence Enterprise Edition allows low-privileged attackers with network access via HTTP to compromise the product, potentially leading to unauthorized data access, modification, or partial denial of service. The vulnerability affects version 12.2.1.4.0 and has a CVSS score of 8.3, indicating high severity. Oracle Business Intelligence Enterprise Edition administrato [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83284

A vulnerability in Oracle BI Publisher of Oracle Analytics allows unauthenticated attackers with network access via SOAP to compromise the product. Successful attacks can result in unauthorized ability to cause a hang or frequently repeatable crash of Oracle BI Publisher as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized read access to a [truncated]

CRITICAL Oracle Corporation CVE published 2026-09-15

CVE-2026-83283

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:40.927Z and has not been modified since then. The vulnerability in Oracle Business Intelligence Enterprise Edition (component: Platform Security) allows an unauthenticated attacker with network access via HTTP to compromise the product. Successful attacks can result in takeover of Oracle Bu [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83281

CVE-2026-83281 is a high-severity vulnerability in Oracle's Helidon product, affecting versions 4.0.0-4.5.4. An unauthenticated attacker with network access via TCP can exploit this vulnerability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. The CVSS 3.1 Base Score is 7.5, indicating a high availability impact. This vulnerability is in the helidon-webserver component. Defenders [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83280

CVE-2026-83280 is a high-severity vulnerability in Oracle's Helidon product, affecting versions 4.0.0-4.5.4. An unauthenticated attacker with network access via HTTP/2 can exploit this vulnerability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. The CVSS 3.1 Base Score is 7.5, indicating a high availability impact. Defenders should prioritize verifying exposure and assessing pot [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83279

A vulnerability exists in Oracle Agile PLM MCAD Connector, allowing a low-privileged attacker with logon access to compromise the system and gain unauthorized access to critical data. The vulnerability is located in the CAX Client component of Oracle Agile PLM MCAD Connector version 3.6. This vulnerability has a medium CVSS score, indicating a need for verification and potential remediation to prevent dat [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83278

A vulnerability in Helidon, a product of Oracle Fusion Middleware, has been identified. The vulnerability affects versions 3.0.0-3.2.20 and 4.0.0-4.5.4. It is difficult to exploit and allows an unauthenticated attacker with access to the physical communication segment to compromise Helidon. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Hel [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83277

A vulnerability exists in Oracle Agile PLM MCAD Connector, allowing a low-privileged attacker with logon access to compromise the system, potentially impacting additional products. Successful attacks can result in unauthorized data access and modification. The vulnerability is in the CAX Client component, version 3.6, and has a high severity score of 7.3. Defenders should prioritize verifying exposure, as [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83276

CVE-2026-83276 is a high-severity vulnerability in Oracle's Helidon product, affecting versions 4.0.0-4.5.4. An unauthenticated attacker with network access via HTTP/2 can exploit this vulnerability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. The CVSS 3.1 Base Score is 7.5, indicating a high availability impact. Defenders should prioritize verifying exposure and assessing pot [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83274

A vulnerability exists in Oracle Agile PLM MCAD Connector, a medium-severity issue allowing low-privileged attackers with logon access to compromise the system and gain unauthorized access to critical data. This vulnerability, tracked as CVE-2026-83274, affects version 3.6 of the product and has a CVSS 3.1 Base Score of 5.5, indicating a significant risk to confidentiality. Defenders responsible for deplo [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83270

A vulnerability in Oracle Business Intelligence Enterprise Edition allows unauthenticated attackers to access critical data via HTTP. Defenders should assess exposure, prioritize remediation, and verify data access controls. The vulnerability affects versions 8.2.0.0.0 and 26.01.0.0.0, and defenders should review the official advisory for specific guidance on affected scope and remediation steps. Successf [truncated]

CRITICAL Oracle Corporation CVE published 2026-09-15

CVE-2026-83269

A critical vulnerability exists in Oracle BI Publisher, specifically in the BI Platform Security component, allowing unauthenticated attackers with network access via HTTP to compromise the system. This vulnerability has a high CVSS score of 9.8, indicating a critical severity level. Defenders should assess exposure and prioritize remediation due to the potential for system takeover and high risk of confi [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83267

A vulnerability in Oracle BI Publisher allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products and allowing unauthorized access to critical data or update, insert, or delete access to some data. The vulnerability, with a CVSS score of 8.5, is easily exploitable and affects versions 8.2.0.0.0, 12.2.1.4.0, and 26.01.0.0.0 of Oracle BI [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83266

A vulnerability in Oracle JDeveloper allows unauthenticated network attackers to compromise the product, access critical data, and cause partial denial of service. The CVE record was published on 2026-09-15T20:18:38.957Z and has not been modified since then. The NVD entry is currently Deferred. This vulnerability affects Oracle JDeveloper versions 12.2.1.4.0 and 14.1.2.0.0, and the CVSS score is 8.2, indi [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83265

A vulnerability in Oracle Web Services Manager allows unauthenticated attackers to compromise the product via HTTP, potentially leading to unauthorized access to critical data or update, insert, or delete access to some data. The vulnerability, tracked as CVE-2026-83265, is a high-severity issue that can result in significant data breaches or integrity issues. Oracle Web Services Manager administrators an [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83264

A vulnerability in Oracle Product Lifecycle Analytics allows low-privileged attackers with logon access to compromise the product, potentially impacting additional products. Successful attacks can result in unauthorized data access or modification. This high-severity vulnerability, tracked as CVE-2026-83264, affects Oracle Product Lifecycle Analytics version 3.6.1 and has a CVSS score of 8.4. Defenders sh [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83259

A vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows low-privileged attackers with network access via HTTP to compromise the product, potentially leading to unauthorized access to critical data or partial denial of service. The vulnerability affects version 11.4.0 and has a CVSS score of 7.1, indicating high severity. Defenders should assess exposure and potential i [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83252

A high-severity vulnerability exists in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, which could allow an unauthenticated attacker with network access via HTTP to compromise the product. Successful attacks could result in unauthorized access to critical data, unauthorized update, insert or delete access to some data, and a partial denial of service.

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83251

A vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Forge) allows unauthenticated attackers with network access via TLS to compromise the product, potentially causing a hang or crash and unauthorized read access to a subset of accessible data. The vulnerability requires verification of exposure and assessment of potential impact, focusing on network access con [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83250

A vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Forge) allows unauthenticated attackers with network access via HTTP to compromise the product. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83248

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:36.963Z and has not been modified since then. The vulnerability affects Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically component: Forge, with version 11.4.0 being vulnerable. The vulnerability allows for DOS and unauthorized data read, with a CVSS score of [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83244

A high-severity vulnerability exists in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. This difficult-to-exploit vulnerability allows unauthenticated attackers with physical access to the communication segment to compromise the product, potentially leading to unauthorized data access, modification, and system disruption.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83243

A vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products and allowing unauthorized access to critical data. The vulnerability is easily exploitable and has a CVSS 3.1 Base Score of 7.7, indicating high severity. Defenders should prioritize verifying [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83242

A vulnerability exists in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. An unauthenticated attacker with network access via HTTP can exploit this vulnerability to compromise the product, resulting in unauthorized update, insert or delete access to some accessible data, unauthorized read access to a subset of accessible data, and a partial denial of service (partial DOS).

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83240

A vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (component: Forge) allows low-privileged attackers with logon access to compromise the product. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to ca [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83238

A vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows low-privileged attackers with network access via HTTP to compromise the product, potentially leading to unauthorized access to critical data or partial denial of service. The vulnerability affects version 11.4.0 and successful attacks can result in unauthorized access to critical data or complete access to all Ora [truncated]