{"cve":"CVE-2026-83200","enrichment":{"affected":[{"configurations":[{"platform":null,"status":"affected","versions":{"scheme":"semver","value":"[12.2.3,12.2.15]"}}],"enrichment":{"confidence":95.0,"confidence_source":"inferred","scores":[{"score":95.0,"source":"inferred"},{"score":100.0,"source":"matching"}]},"original":{"product":"Oracle Process Manufacturing Intelligence","source":"cna","vendor":"Oracle Corporation"},"product":"process_manufacturing_intelligence","vendor":"oracle"}],"created":"2026-09-16T16:45:17.728936+00:00","title":"Unauthorized Data Access via Weak Authorization in Oracle Process Manufacturing Intelligence","updated":"2026-09-20T09:15:17.433153+00:00","vendors":["oracle","oracle$PRODUCT$process_manufacturing_intelligence"]},"epss":{"score":0.0034},"mitre":{"cpes":["cpe:2.3:a:oracle:process_manufacturing_intelligence:*:*:*:*:*:*:*:*"],"created":"2026-09-15T20:04:19.096000+00:00","description":"Vulnerability in the Oracle Process Manufacturing Intelligence product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle Process Manufacturing Intelligence.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Process Manufacturing Intelligence accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":6.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"cvssV4_0":{}},"mitre_repo_path":"cves/2026/83xxx/CVE-2026-83200.json","references":["https://www.oracle.com/security-alerts/cspusep2026.html"],"title":null,"updated":"2026-09-17T15:14:49.964000+00:00","vendors":["oracle","oracle$PRODUCT$process_manufacturing_intelligence"],"weaknesses":[]},"nvd":{"cpes":[],"created":"2026-09-15T20:18:31.507000+00:00","description":"Vulnerability in the Oracle Process Manufacturing Intelligence product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle Process Manufacturing Intelligence.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Process Manufacturing Intelligence accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":6.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"cvssV4_0":{}},"nvd_repo_path":"2026/CVE-2026-83200.json","references":["https://www.oracle.com/security-alerts/cspusep2026.html"],"title":null,"updated":"2026-09-17T16:18:08.870000+00:00","vendors":[],"weaknesses":["CWE-284"]},"opencve":{"changes":[{"created":"2026-09-15T20:15:00+00:00","data":[{"details":{"new":"Vulnerability in the Oracle Process Manufacturing Intelligence product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle Process Manufacturing Intelligence.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Process Manufacturing Intelligence accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","old":null},"type":"description"},{"details":["oracle","oracle$PRODUCT$process_manufacturing_intelligence"],"type":"first_time"},{"details":{"added":["cpe:2.3:a:oracle:process_manufacturing_intelligence:*:*:*:*:*:*:*:*"],"removed":[]},"type":"cpes"},{"details":{"added":["oracle","oracle$PRODUCT$process_manufacturing_intelligence"],"removed":[]},"type":"vendors"},{"details":{"added":["https://www.oracle.com/security-alerts/cspusep2026.html"],"removed":[]},"type":"references"},{"details":{"added":{"cvssV3_1":{"score":6.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"f8c487fd-04a9-4fc9-b6a4-64ac1edea51e"},{"created":"2026-09-17T01:30:00+00:00","data":[{"details":{"new":"Low Privilege Oracle Process Manufacturing Intelligence Data Access Vulnerability","old":null},"type":"title"},{"details":{"added":["CWE-200","CWE-284"],"removed":[]},"type":"weaknesses"}],"id":"946138ac-0242-464f-b02f-8ac521dd4090"},{"created":"2026-09-17T16:30:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"9fe2f375-951e-407a-a332-2cc67fb8c3df"},{"created":"2026-09-18T21:30:00+00:00","data":[{"details":{"new":null,"old":"Low Privilege Oracle Process Manufacturing Intelligence Data Access Vulnerability"},"type":"title"},{"details":{"added":[],"removed":["CWE-200"]},"type":"weaknesses"}],"id":"4d08e87c-5ba9-48ac-8f71-1355af50da5e"},{"created":"2026-09-20T09:30:00+00:00","data":[{"details":{"new":"Unauthorized Data Access via Weak Authorization in Oracle Process Manufacturing Intelligence","old":null},"type":"title"}],"id":"932d161a-a8cb-4968-b7b3-d94d9f9bd3c0"}],"cpes":{"data":["cpe:2.3:a:oracle:process_manufacturing_intelligence:*:*:*:*:*:*:*:*"],"providers":["mitre"]},"created":{"data":"2026-09-15T20:04:19.096000+00:00","provider":"mitre"},"description":{"data":"Vulnerability in the Oracle Process Manufacturing Intelligence product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle Process Manufacturing Intelligence.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Process Manufacturing Intelligence accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":6.5,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.0034},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://www.oracle.com/security-alerts/cspusep2026.html"],"providers":["mitre","nvd"]},"title":{"data":"Unauthorized Data Access via Weak Authorization in Oracle Process Manufacturing Intelligence","provider":"enrichment"},"updated":{"data":"2026-09-20T09:15:17.433153+00:00","provider":"enrichment"},"vendors":{"data":["oracle","oracle$PRODUCT$process_manufacturing_intelligence"],"providers":["mitre","enrichment"]},"weaknesses":{"data":["CWE-284"],"providers":["nvd","vulnrichment"]}},"vulnrichment":{"cpes":[],"created":"2026-09-15T20:04:19.096000+00:00","description":"Vulnerability in the Oracle Process Manufacturing Intelligence product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle Process Manufacturing Intelligence.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Process Manufacturing Intelligence accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"no","Exploitation":"none","Technical Impact":"partial"},"version":"2.0.3"}},"references":[],"title":null,"updated":"2026-09-17T14:22:39.569000+00:00","vendors":[],"vulnrichment_repo_path":"2026/83xxx/CVE-2026-83200.json","weaknesses":["CWE-284"]}}