These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A critical vulnerability exists in Oracle Application Testing Suite version 13.3.0.1. A low-privileged attacker with network access via HTTP can compromise the suite, potentially impacting additional products. Successful attacks can result in unauthorized access to critical data, update, insert or delete access to some data, and partial denial of service.
A vulnerability in Siebel CRM End User product of Oracle Siebel CRM (component: Open UI) has been identified. The vulnerability is difficult to exploit, allowing a low-privileged attacker with network access via HTTP to compromise Siebel CRM End User. Successful attacks require human interaction and can result in unauthorized creation, deletion, or modification access to critical data or all Siebel CRM En [truncated]
A vulnerability in Siebel Apps - Customer Order Management of Oracle Siebel CRM allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks require human interaction and can result in unauthorized creation, deletion, or modification access to critical data or all Siebel Apps - Customer Order Management accessible data, as well as unauthorized access to criti [truncated]
A vulnerability in Siebel Apps - Customer Order Management of Oracle Siebel CRM allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks require human interaction and can result in unauthorized creation, deletion, or modification access to critical data or all Siebel Apps - Customer Order Management accessible data, as well as unauthorized access to criti [truncated]
A vulnerability in Siebel Apps - Life Sciences of Oracle Siebel CRM (component: eDetailing) allows an unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Life Sciences. Successful attacks require human interaction and can result in unauthorized creation, deletion, or modification access to critical data or all Siebel Apps - Life Sciences accessible data as well as unauthorize [truncated]
A vulnerability in Oracle Sales Online, part of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks require human interaction and can result in unauthorized access to critical data or complete access to all Oracle Sales Online accessible data, as well as unauthorized update, insert, or delete access to some data.
A high-severity vulnerability exists in Oracle Order Management, a component of Oracle E-Business Suite. The vulnerability, tracked as CVE-2026-83116, is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Order Management accessible data.
The CVE-2026-83115 vulnerability affects Oracle Applications Manager, a component of Oracle E-Business Suite. This high-severity vulnerability, classified as easily exploitable, allows unauthenticated attackers with network access via HTTP to compromise the manager. Successful attacks can result in unauthorized access to critical data. Defenders should prioritize verifying exposure, especially in instance [truncated]
A vulnerability in Oracle Quality, a component of Oracle E-Business Suite, allows a low-privileged attacker with network access via HTTP to compromise the product. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle Quality accessible data, as well as unauthorized update, insert, or delete access to some of Oracle Quality accessible data.
CVE-2026-83085 is a high-severity vulnerability in Oracle Siebel CRM Cloud Applications, a low-privileged attacker with access to the physical communication segment can compromise the application. Defenders should assess exposure, prioritize remediation, and verify compensating controls to prevent unauthorized access, data manipulation, and partial DOS. The vulnerability allows attackers to potentially im [truncated]
CVE-2026-83078 is a high-severity vulnerability in Oracle Siebel CRM Cloud Applications, specifically in the Siebel Cloud Manager component. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise Siebel CRM Cloud Applications, potentially leading to unauthorized access to critical data and update, insert, or delete access to some data.
A vulnerability in Siebel CRM Cloud Applications' Siebel Cloud Manager component allows low-privileged attackers with network access via HTTP to compromise the application, potentially impacting additional products. Successful attacks can result in unauthorized data access and modifications. The vulnerability has a medium severity and affects versions 22.3-26.7. Administrators and security teams should as [truncated]
CVE-2026-83075 debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:17.137Z and has not been modified since then. The vulnerability affects Siebel CRM Cloud Applications, specifically versions 22.3-26.7, and allows unauthenticated attackers to access critical data. Defenders should prioritize verifying exposure and implementing compensating controls. The Siebel Clo [truncated]
CVE-2026-83074 is a high-severity vulnerability in Oracle Siebel CRM Cloud Applications' Siebel Cloud Manager component. The vulnerability allows unauthenticated attackers with network access via SSH to compromise Siebel CRM Cloud Applications, potentially impacting additional products. Successful attacks can result in unauthorized access to critical data or complete access to all Siebel CRM Cloud Applica [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:14.563Z and has not been modified since then. The vulnerability in Oracle Internet Directory (component: OID LDAP Server) allows unauthenticated attackers with network access via LDAP to compromise Oracle Internet Directory. Affected versions include 12.2.1.4.0 and 14.1.2.1.0. Successful at [truncated]
A high-severity vulnerability exists in Oracle WebCenter Portal, affecting versions 12.2.1.4.0 and 14.1.2.0.0. An attacker with high privileges and network access via HTTP can exploit this vulnerability, potentially impacting additional products. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data, as well as unauthorized [truncated]
CVE-2026-83051 debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:13.657Z and was last modified on 2026-09-21T18:06:53.050Z. The NVD entry is currently Analyzed. Defenders responsible for Oracle WebCenter Portal instances, especially those with unauthenticated network access via HTTP, should assess exposure and prioritize verification and potential remediation. T [truncated]
The CVE-2026-83049 vulnerability affects Oracle WebCenter Portal, specifically versions 12.2.1.4.0 and 14.1.2.0.0, and allows low-privileged attackers with network access via HTTP to compromise the system. This vulnerability is classified as high-severity, with a CVSS score of 8.5, indicating significant impacts on confidentiality and integrity. The vulnerability may also impact additional products due to [truncated]
A vulnerability in Oracle WebCenter Portal's Runtime Tools component allows low-privileged attackers with network access via HTTP to compromise the product. This could impact additional products and allow unauthorized access to critical data. The vulnerability has a CVSS 3.1 Base Score of 7.7, indicating high severity. Administrators and security teams should assess exposure and apply patches to prevent p [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-15T20:18:13.203Z and has not been modified since then. The vulnerability in Oracle WebCenter Portal allows unauthenticated attackers with network access via HTTP to compromise the product, potentially leading to unauthorized access to critical data or updates to accessible data. Defenders should pri [truncated]
A vulnerability in Oracle WebCenter Portal allows low-privileged attackers with network access via HTTP to compromise the product, potentially leading to unauthorized access to critical data or partial denial of service. This high-severity issue, tracked as CVE-2026-83046, affects versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Portal. The vulnerability has a CVSS 3.1 Base Score of 7.1, indicating [truncated]
A vulnerability in Oracle WebCenter Portal allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products. Successful attacks can result in unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data, as well as unauthorized update, insert, or delete access to some data.
The CVE-2026-83043 vulnerability affects Oracle WebCenter Portal, specifically versions 12.2.1.4.0 and 14.1.2.0.0. This vulnerability, classified under the Composer component, allows unauthenticated attackers with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction and can lead to a takeover of Oracle WebCenter Portal, with potential impacts on addit [truncated]
A vulnerability in Oracle WebCenter Portal's Portlet Services allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products and allowing unauthorized access to critical data. This high-severity vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0, with a CVSS 3.1 Base Score of 7.7, indicating significant confidentiality impacts. Succe [truncated]
A critical vulnerability exists in Oracle WebCenter Portal, specifically in the Portlet Services component. This vulnerability, tracked as CVE-2026-83040, allows an unauthenticated attacker with network access via SOAP to compromise the portal. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the [truncated]
A critical vulnerability exists in Oracle WebCenter Portal, specifically in the Composer component of Oracle Fusion Middleware. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. It allows a low-privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal easily. Successful attacks can result in the takeover of Oracle WebCenter Portal, and impacts may extend to additio [truncated]
CVE-2026-83037 is a critical vulnerability in Oracle WebCenter Sites, with a CVSS score of 9.8. It allows unauthenticated attackers to compromise the site via HTTP, potentially leading to takeover and compromise of confidentiality, integrity, and availability. Defenders should assess exposure, prioritize remediation, and verify network access controls and HTTP security measures. The vulnerability affects [truncated]
A critical vulnerability exists in Oracle WebCenter Sites, a component of Oracle Fusion Middleware. This vulnerability, tracked as CVE-2026-83036, allows an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites, potentially leading to a complete takeover of the system. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0 and has a CVSS score of 9.8, indicating [truncated]
A critical vulnerability exists in Oracle WebCenter Sites, a component of Oracle Fusion Middleware. This vulnerability, tracked as CVE-2026-83035, allows an unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites, potentially leading to a complete takeover of the system. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0 of Oracle WebCenter Sites and has a CVSS [truncated]
CVE-2026-83034 is a high-severity vulnerability in Oracle WebCenter Sites, with a CVSS score of 7.5. It allows unauthenticated attackers to access critical data via HTTP. Defenders should assess exposure, prioritize remediation, and verify inventory. The vulnerability is in the WebCenter Sites component of Oracle Fusion Middleware. Successful attacks can result in unauthorized access to critical data or c [truncated]