{"cve":"CVE-2026-83128","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[12.2.3,12.2.15]"}}],"enrichment":{"confidence":95.0,"confidence_source":"inferred","scores":[{"score":95.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"original":{"product":"Oracle Sales Offline","source":"cna","vendor":"Oracle Corporation"},"product":"sales_offline","vendor":"oracle"}],"created":"2026-09-16T02:30:07.502925+00:00","title":"Unauthenticated HTTP Access Allows Confidential Data Exposure in Oracle Sales Offline","updated":"2026-09-20T11:00:09.914973+00:00","vendors":["oracle","oracle$PRODUCT$sales_offline"]},"epss":{"score":0.00377},"mitre":{"cpes":["cpe:2.3:a:oracle:sales_offline:*:*:*:*:*:*:*:*"],"created":"2026-09-15T20:03:31.079000+00:00","description":"Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Sales Offline accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":7.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/83xxx/CVE-2026-83128.json","references":["https://www.oracle.com/security-alerts/cspusep2026.html"],"title":null,"updated":"2026-09-16T17:57:29.604000+00:00","vendors":["oracle","oracle$PRODUCT$sales_offline"],"weaknesses":[]},"nvd":{"cpes":[],"created":"2026-09-15T20:18:23.337000+00:00","description":"Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Sales Offline accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":7.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-83128.json","references":["https://www.oracle.com/security-alerts/cspusep2026.html"],"title":null,"updated":"2026-09-16T19:40:00.317000+00:00","vendors":[],"weaknesses":["CWE-284"]},"opencve":{"changes":[{"created":"2026-09-15T20:15:00+00:00","data":[{"details":{"new":"Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Sales Offline accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","old":null},"type":"description"},{"details":["oracle","oracle$PRODUCT$sales_offline"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:oracle:sales_offline:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["oracle","oracle$PRODUCT$sales_offline"],"removed":[]},"type":"vendors"},{"details":{"added":["https://www.oracle.com/security-alerts/cspusep2026.html"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":7.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"45061301-208e-42f3-8291-bdca8688905d"},{"created":"2026-09-16T18:30:00+00:00","data":[{"details":{"added":["CWE-284"],"removed":[]},"type":"weaknesses"}],"id":"783a6474-49a5-42ad-930c-36b9c1f657cd"},{"created":"2026-09-16T19:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"d9fbeb68-247b-4f72-8f44-436302a10015"},{"created":"2026-09-17T02:15:00+00:00","data":[{"details":{"new":"Unauthenticated HTTP Data Exposure in Oracle Sales Offline","old":null},"type":"title"},{"details":{"added":["CWE-306"],"removed":[]},"type":"weaknesses"}],"id":"afe1a9ca-70c4-44e5-ba0e-dd91548ca517"},{"created":"2026-09-18T21:30:00+00:00","data":[{"details":{"new":null,"old":"Unauthenticated HTTP Data Exposure in Oracle Sales Offline"},"type":"title"},{"details":{"added":[],"removed":["CWE-306"]},"type":"weaknesses"}],"id":"fa696d14-e2f3-4fdf-bb83-7837d2876278"},{"created":"2026-09-20T11:15:00+00:00","data":[{"details":{"new":"Unauthenticated HTTP Access Allows Confidential Data Exposure in Oracle Sales Offline","old":null},"type":"title"}],"id":"6a32d10f-1e95-48f8-9d24-b37b386394da"}],"cpes":{"data":["cpe:2.3:a:oracle:sales_offline:*:*:*:*:*:*:*:*"],"providers":["mitre"]},"created":{"data":"2026-09-15T20:03:31.079000+00:00","provider":"mitre"},"description":{"data":"Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Sales Offline accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":7.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.00377},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://www.oracle.com/security-alerts/cspusep2026.html"],"providers":["mitre","nvd"]},"title":{"data":"Unauthenticated HTTP Access Allows Confidential Data Exposure in Oracle Sales Offline","provider":"enrichment"},"updated":{"data":"2026-09-20T11:00:09.914973+00:00","provider":"enrichment"},"vendors":{"data":["oracle","oracle$PRODUCT$sales_offline"],"providers":["mitre","enrichment"]},"weaknesses":{"data":["CWE-284"],"providers":["nvd","vulnrichment"]}},"vulnrichment":{"cpes":[],"created":"2026-09-15T20:03:31.079000+00:00","description":"Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Sales Offline accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":null,"updated":"2026-09-16T17:52:18.960000+00:00","vendors":[],"vulnrichment_repo_path":"2026/83xxx/CVE-2026-83128.json","weaknesses":["CWE-284"]}}