PatchSiren

Oracle Corporation CVE debriefs · Page 8

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Oracle Corporation CVE published 2026-09-15

CVE-2026-83149

A critical vulnerability exists in Oracle Application Testing Suite version 13.3.0.1. A low-privileged attacker with network access via HTTP can compromise the suite, potentially impacting additional products. Successful attacks can result in unauthorized access to critical data, update, insert or delete access to some data, and partial denial of service.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83146

A vulnerability in Siebel CRM End User product of Oracle Siebel CRM (component: Open UI) has been identified. The vulnerability is difficult to exploit, allowing a low-privileged attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks require human interaction and can result in unauthorized creation, deletion, or modification access to critical data or all Siebel CRM En [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83145

A vulnerability in Siebel Apps - Customer Order Management of Oracle Siebel CRM allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks require human interaction and can result in unauthorized creation, deletion, or modification access to critical data or all Siebel Apps - Customer Order Management accessible data, as well as unauthorized access to criti [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83144

A vulnerability in Siebel Apps - Customer Order Management of Oracle Siebel CRM allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks require human interaction and can result in unauthorized creation, deletion, or modification access to critical data or all Siebel Apps - Customer Order Management accessible data, as well as unauthorized access to criti [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83143

A vulnerability in Siebel Apps - Life Sciences of Oracle Siebel CRM (component: eDetailing) allows an unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Life Sciences. Successful attacks require human interaction and can result in unauthorized creation, deletion, or modification access to critical data or all Siebel Apps - Life Sciences accessible data as well as unauthorize [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83126

A vulnerability in Oracle Sales Online, part of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks require human interaction and can result in unauthorized access to critical data or complete access to all Oracle Sales Online accessible data, as well as unauthorized update, insert, or delete access to some data.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83116

A high-severity vulnerability exists in Oracle Order Management, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-83116, is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83115

The CVE-2026-83115 vulnerability affects Oracle Applications Manager, a component of Oracle E-Business Suite. This high-severity vulnerability, classified as easily exploitable, allows unauthenticated attackers with network access via HTTP to compromise the manager. Successful attacks can result in unauthorized access to critical data. Defenders should prioritize verifying exposure, especially in instance [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83113

A vulnerability in Oracle Quality, a component of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Quality accessible data, as well as unauthorized update, insert, or delete access to some of Oracle Quality accessible data.

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83085

CVE-2026-83085 is a high-severity vulnerability in Oracle Siebel CRM Cloud Applications, a low-privileged attacker with access to the physical communication segment can compromise the application. Defenders should assess exposure, prioritize remediation, and verify compensating controls to prevent unauthorized access, data manipulation, and partial DOS. The vulnerability allows attackers to potentially im [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83078

CVE-2026-83078 is a high-severity vulnerability in Oracle Siebel CRM Cloud Applications, specifically in the Siebel Cloud Manager component. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise Siebel CRM Cloud Applications, potentially leading to unauthorized access to critical data and update, insert, or delete access to some data.

MEDIUM Oracle Corporation CVE published 2026-09-15

CVE-2026-83077

A vulnerability in Siebel CRM Cloud Applications' Siebel Cloud Manager component allows low-privileged attackers with network access via HTTP to compromise the application, potentially impacting additional products. Successful attacks can result in unauthorized data access and modifications. The vulnerability has a medium severity and affects versions 22.3-26.7. Administrators and security teams should as [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83075

CVE-2026-83075 debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:17.137Z and has not been modified since then. The vulnerability affects Siebel CRM Cloud Applications, specifically versions 22.3-26.7, and allows unauthenticated attackers to access critical data. Defenders should prioritize verifying exposure and implementing compensating controls. The Siebel Clo [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83074

CVE-2026-83074 is a high-severity vulnerability in Oracle Siebel CRM Cloud Applications' Siebel Cloud Manager component. The vulnerability allows unauthenticated attackers with network access via SSH to compromise Siebel CRM Cloud Applications, potentially impacting additional products. Successful attacks can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applica [truncated]

CRITICAL Oracle Corporation CVE published 2026-09-15

CVE-2026-83059

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:14.563Z and has not been modified since then. The vulnerability in Oracle Internet Directory (component: OID LDAP Server) allows unauthenticated attackers with network access via LDAP to compromise Oracle Internet Directory. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. Successful at [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83052

A high-severity vulnerability exists in Oracle WebCenter Portal, affecting versions 12.2.1.4.0 and 14.1.2.0.0. An attacker with high privileges and network access via HTTP can exploit this vulnerability, potentially impacting additional products. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data, as well as unauthorized [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83051

CVE-2026-83051 debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:13.657Z and was last modified on 2026-09-21T18:06:53.050Z. The NVD entry is currently Analyzed. Defenders responsible for Oracle WebCenter Portal instances, especially those with unauthenticated network access via HTTP, should assess exposure and prioritize verification and potential remediation. T [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83049

The CVE-2026-83049 vulnerability affects Oracle WebCenter Portal, specifically versions 12.2.1.4.0 and 14.1.2.0.0, and allows low-privileged attackers with network access via HTTP to compromise the system. This vulnerability is classified as high-severity, with a CVSS score of 8.5, indicating significant impacts on confidentiality and integrity. The vulnerability may also impact additional products due to [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83048

A vulnerability in Oracle WebCenter Portal's Runtime Tools component allows low-privileged attackers with network access via HTTP to compromise the product. This could impact additional products and allow unauthorized access to critical data. The vulnerability has a CVSS 3.1 Base Score of 7.7, indicating high severity. Administrators and security teams should assess exposure and apply patches to prevent p [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83047

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:13.203Z and has not been modified since then. The vulnerability in Oracle WebCenter Portal allows unauthenticated attackers with network access via HTTP to compromise the product, potentially leading to unauthorized access to critical data or updates to accessible data. Defenders should pri [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83046

A vulnerability in Oracle WebCenter Portal allows low-privileged attackers with network access via HTTP to compromise the product, potentially leading to unauthorized access to critical data or partial denial of service. This high-severity issue, tracked as CVE-2026-83046, affects versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Portal. The vulnerability has a CVSS 3.1 Base Score of 7.1, indicating [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83045

A vulnerability in Oracle WebCenter Portal allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data, as well as unauthorized update, insert, or delete access to some data.

CRITICAL Oracle Corporation CVE published 2026-09-15

CVE-2026-83043

The CVE-2026-83043 vulnerability affects Oracle WebCenter Portal, specifically versions 12.2.1.4.0 and 14.1.2.0.0. This vulnerability, classified under the Composer component, allows unauthenticated attackers with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction and can lead to a takeover of Oracle WebCenter Portal, with potential impacts on addit [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83041

A vulnerability in Oracle WebCenter Portal's Portlet Services allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products and allowing unauthorized access to critical data. This high-severity vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0, with a CVSS 3.1 Base Score of 7.7, indicating significant confidentiality impacts. Succe [truncated]

CRITICAL Oracle Corporation CVE published 2026-09-15

CVE-2026-83040

A critical vulnerability exists in Oracle WebCenter Portal, specifically in the Portlet Services component. This vulnerability, tracked as CVE-2026-83040, allows an unauthenticated attacker with network access via SOAP to compromise the portal. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the [truncated]

CRITICAL Oracle Corporation CVE published 2026-09-15

CVE-2026-83039

A critical vulnerability exists in Oracle WebCenter Portal, specifically in the Composer component of Oracle Fusion Middleware. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. It allows a low-privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal easily. Successful attacks can result in the takeover of Oracle WebCenter Portal, and impacts may extend to additio [truncated]

CRITICAL Oracle Corporation CVE published 2026-09-15

CVE-2026-83037

CVE-2026-83037 is a critical vulnerability in Oracle WebCenter Sites, with a CVSS score of 9.8. It allows unauthenticated attackers to compromise the site via HTTP, potentially leading to takeover and compromise of confidentiality, integrity, and availability. Defenders should assess exposure, prioritize remediation, and verify network access controls and HTTP security measures. The vulnerability affects [truncated]

CRITICAL Oracle Corporation CVE published 2026-09-15

CVE-2026-83036

A critical vulnerability exists in Oracle WebCenter Sites, a component of Oracle Fusion Middleware. This vulnerability, tracked as CVE-2026-83036, allows an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites, potentially leading to a complete takeover of the system. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0 and has a CVSS score of 9.8, indicating [truncated]

CRITICAL Oracle Corporation CVE published 2026-09-15

CVE-2026-83035

A critical vulnerability exists in Oracle WebCenter Sites, a component of Oracle Fusion Middleware. This vulnerability, tracked as CVE-2026-83035, allows an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites, potentially leading to a complete takeover of the system. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Sites and has a CVSS [truncated]

HIGH Oracle Corporation CVE published 2026-09-15

CVE-2026-83034

CVE-2026-83034 is a high-severity vulnerability in Oracle WebCenter Sites, with a CVSS score of 7.5. It allows unauthenticated attackers to access critical data via HTTP. Defenders should assess exposure, prioritize remediation, and verify inventory. The vulnerability is in the WebCenter Sites component of Oracle Fusion Middleware. Successful attacks can result in unauthorized access to critical data or c [truncated]