PatchSiren

Oracle Corporation CVE debriefs · Page 7

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83237

A high-severity vulnerability exists in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, allowing low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized access to critical data and partial denial of service. The vulnerability affects the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Ma [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83236

A vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows unauthenticated attackers to compromise the product via HTTP. Successful attacks require human interaction and can result in unauthorized access to critical data or complete access to all accessible data as well as unauthorized update, insert or delete access to some accessible data.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83235

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:35.460Z and has not been modified since then. This high-severity vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0 allows unauthenticated attackers with network access via HTTP to compromise the product and access critical data. Defenders should prio [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83234

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:35.340Z and has not been modified since then. The vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0 allows unauthenticated attackers with network access via HTTP to compromise the system, potentially leading to unauthorized access to critical data an [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83228

A high-severity vulnerability exists in Oracle Siebel CRM Deployment, affecting versions 17.0-26.7. This easily exploitable vulnerability allows unauthenticated attackers with network access via TCP to compromise Siebel CRM Deployment, potentially causing a hang or frequently repeatable crash (complete DOS). The vulnerability exists in the Server Infrastructure component and has a CVSS 3.1 Base Score of 7 [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83225

A high-severity vulnerability exists in Oracle Siebel CRM Deployment, specifically in the Server Infrastructure component. The vulnerability, tracked as CVE-2026-83225, allows an unauthenticated attacker with network access via TCP to compromise Siebel CRM Deployment, potentially leading to a hang or frequently repeatable crash (complete DOS) of the affected system.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83222

A vulnerability in Siebel CRM Deployment, an Oracle Siebel CRM product component, allows unauthenticated attackers with network access to cause a hang or crash of Siebel CRM Deployment. The CVSS 3.1 Base Score is 7.5, indicating high severity. Oracle Siebel CRM versions 17.0-26.7 are affected. This vulnerability can lead to a Denial of Service (DOS) attack, emphasizing the need for prompt verification and [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83221

A high-severity vulnerability exists in the Siebel CRM Integration product of Oracle Siebel CRM. The vulnerability, which has a CVSS score of 7.1, allows a low-privileged attacker with network access via SOAP to compromise Siebel CRM Integration, potentially leading to unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data, as well as unauthorized update, ins [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83220

A high-severity vulnerability exists in the Siebel CRM Integration product of Oracle Siebel CRM. The vulnerability, which has a CVSS score of 8.1, allows an unauthenticated attacker with access to the physical communication segment to compromise Siebel CRM Integration, potentially leading to unauthorized creation, deletion, or modification of critical data.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83219

A vulnerability in Siebel CRM Deployment, part of Oracle Siebel CRM, allows low-privileged attackers with logon access to compromise the deployment, potentially leading to unauthorized data access and modification. The vulnerability has a CVSS score of 7.1 and is considered high severity. It affects versions 17.0-26.7 and can result in unauthorized creation, deletion, or modification access to critical da [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83218

A high-severity vulnerability exists in Oracle Siebel CRM Deployment, affecting versions 17.0-26.7. This difficult-to-exploit vulnerability allows unauthenticated attackers with network access via HTTP to compromise Siebel CRM Deployment, potentially leading to unauthorized data creation, deletion, modification, or access. The vulnerability's high severity and potential impact necessitate immediate attent [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83217

A high-severity vulnerability exists in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI). The vulnerability allows a low-privileged attacker with network access via HTTP to compromise Siebel CRM End User, potentially leading to unauthorized access to critical data or complete access to all Siebel CRM End User accessible data, as well as unauthorized update, insert or delete access [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83215

CVE-2026-83215 is a high-severity vulnerability in Siebel CRM Deployment's Server Infrastructure component. Unaffected versions are not listed. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise Siebel CRM Deployment, potentially leading to unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data, as well as unauthorize [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83213

A high-severity vulnerability exists in the Siebel CRM End User product of Oracle Siebel CRM, affecting versions 17.0-26.7. This vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User, potentially leading to unauthorized access to critical data. The vulnerability's impact on confidentiality is significant, with a CVSS 3.1 Base Score of 7.5. Defender [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83210

A vulnerability in Siebel CRM Deployment, an Oracle Siebel CRM product component, allows a low-privileged attacker with network access via SQL to compromise the deployment. Successful attacks can result in a takeover of Siebel CRM Deployment. The CVSS 3.1 Base Score is 8.8, indicating high severity. This vulnerability is easily exploitable and affects versions 17.0-26.7 of Siebel CRM Deployment.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83208

A high-severity vulnerability exists in Oracle Siebel CRM Deployment, affecting versions 17.0-26.7. This easily exploitable vulnerability allows a low-privileged attacker with network access via SQL to compromise Siebel CRM Deployment, potentially leading to a takeover. The vulnerability is in the Migration component and has a CVSS 3.1 Base Score of 8.8, indicating high severity. Defenders and administrat [truncated]

CRITICAL Oracle Corporation CVE published 2026-09-15

CVE-2026-83202

A critical vulnerability exists in Oracle Siebel CRM Deployment, affecting versions 17.0-26.7. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise Siebel CRM Deployment, potentially leading to unauthorized creation, deletion, or modification of critical data. The vulnerability exists in the Server Infrastructure component and has a CVSS 3.1 Bas [truncated]

CRITICAL Oracle Corporation CVE published 2026-09-15

CVE-2026-83201

A critical vulnerability exists in Oracle Siebel CRM Deployment, affecting versions 17.0-26.7. This easily exploitable vulnerability allows unauthenticated attackers with network access via HTTP to compromise Siebel CRM Deployment, potentially leading to unauthorized creation, deletion, or modification of critical data. The vulnerability exists in the Server Infrastructure component and has a CVSS score o [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83198

A vulnerability in Oracle Field Service, a component of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks require human interaction and can result in unauthorized update, insert, or delete access to some accessible data, as well as unauthorized read access to a subset of accessible data.

CRITICAL Oracle Corporation CVE published 2026-09-15

CVE-2026-83197

A critical vulnerability exists in Oracle Siebel CRM's Siebel Apps - Financial Services product, specifically in the Financial Accounts component. This vulnerability, tracked as CVE-2026-83197, allows unauthenticated attackers with network access via HTTP to compromise the system. Successful attacks could lead to unauthorized access to critical data and the ability to cause system hangs or crashes. Oracle [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83183

CVE-2026-83183 is a high-severity vulnerability in Oracle Siebel CRM Deployment's Server Infrastructure component. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise Siebel CRM Deployment, potentially causing a hang or frequently repeatable crash (complete DOS). Oracle Siebel CRM versions 17.0-26.7 are affected. CVSS 3.1 Base Score is 7.5 (Availability impacts).

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83177

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:28.790Z and has not been modified since then. This high-severity vulnerability in Oracle One-to-One Fulfillment allows low-privileged attackers to potentially access or modify critical data. The vulnerability affects versions 12.2.3-12.2.15 and has a CVSS score of 8.1. Defenders should veri [truncated]

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83175

A vulnerability in Oracle Application Object Library of Oracle E-Business Suite (component: Core) allows an attacker with low privileges and network access via HTTP to compromise the library, potentially leading to unauthorized access to critical data. This medium-severity vulnerability, with a CVSS score of 6.5, affects versions 12.2.3-12.2.15 of Oracle E-Business Suite. Defenders managing these environm [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83174

The CVE-2026-83174 vulnerability affects Oracle CRM Technical Foundation, a component of Oracle E-Business Suite. This high-severity vulnerability allows low-privileged attackers with network access via HTTP to compromise data integrity and confidentiality. The vulnerability has a CVSS 3.1 Base Score of 8.1, indicating a high impact on confidentiality and integrity. Defenders should prioritize verifying e [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83173

A vulnerability in Oracle One-to-One Fulfillment, a component of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized access to critical data and partial denial of service. The vulnerability affects versions 12.2.3-12.2.15 and has a CVSS 3.1 Base Score of 7.1, indicating high severity. Defenders shou [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83172

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:28.210Z and has not been modified since then. The vulnerability in Oracle Sales Online (component: OSO Other) allows a low-privileged attacker with network access via HTTP to compromise the system, potentially impacting additional products. Successful attacks can result in unauthorized acce [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83171

A high-severity vulnerability exists in Oracle One-to-One Fulfillment, a component of Oracle E-Business Suite. The vulnerability, which has a CVSS score of 7.1, allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized access to critical data and partial denial of service.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83167

A vulnerability exists in Oracle Application Object Library, a component of Oracle E-Business Suite. The vulnerability is easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the library, potentially leading to unauthorized access to critical data. This vulnerability affects versions 12.2.3-12.2.15 of Oracle Application Object Library. Defenders should revie [truncated]

CRITICAL Oracle Corporation CVE published 2026-09-15

CVE-2026-83154

A critical vulnerability exists in Oracle Siebel CRM End User product, specifically in the Open UI component. This vulnerability allows an unauthenticated attacker with network access via SOAP to compromise Siebel CRM End User, potentially leading to unauthorized creation, deletion, or modification access to critical data or all Siebel CRM End User accessible data, as well as unauthorized access to critic [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83152

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:25.967Z and has not been modified since then. This vulnerability affects Oracle Project Intelligence, allowing low-privileged attackers with network access via HTTP to compromise the product. The vulnerability could result in unauthorized creation, deletion, or modification access to critic [truncated]