No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspusep2026.html |
|
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Remote Code Execution in Oracle One-to-One Fulfillment via HTTP | |
| Weaknesses | CWE-502 |
Thu, 17 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 | |
| Metrics |
ssvc
|
Thu, 17 Sep 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Remote Code Execution in Oracle One-to-One Fulfillment via HTTP | |
| Weaknesses | CWE-502 |
Tue, 15 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Java Server Issues). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks of this vulnerability can result in takeover of Oracle One-to-One Fulfillment. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle one-to-one Fulfillment |
|
| CPEs | cpe:2.3:a:oracle:one-to-one_fulfillment:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle one-to-one Fulfillment |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-09-17T13:10:43.185Z
Reserved: 2026-08-31T15:40:57.344Z
Link: CVE-2026-83169
Updated: 2026-09-17T13:02:04.932Z
Status : Deferred
Published: 2026-09-15T20:18:27.887
Modified: 2026-09-17T14:17:34.937
Link: CVE-2026-83169
No data.
OpenCVE Enrichment
Updated: 2026-09-20T09:15:17Z