Junglewise Threat Intelligence

CVE-2026-83115: Oracle E-Business Suite Applications Manager unauthenticated data access in RapidClone

CVE-2026-83115 · Severity: high · CVSS 7.5 · Published 2026-09-15

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

A vulnerability in Oracle E-Business Suite's Applications Manager component (RapidClone utility) allows unauthenticated attackers to access sensitive data over the network without authentication. Successful exploitation exposes critical business data and system configuration information accessible through the Applications Manager, potentially compromising the entire E-Business Suite environment.

Technical details

An easily exploitable vulnerability in the Command Line component (RapidClone) of Oracle E-Business Suite's Applications Manager product allows unauthenticated attackers with network access via HTTP to read sensitive data. The vulnerability requires no authentication, no special user interaction, and no complex attack preconditions. Successful exploitation results in unauthorized access to critical data and potentially complete enumeration of all data accessible through the Applications Manager. The affected versions include 12.2.3 through 12.2.15. Patches are expected from Oracle's security bulletin.

Affected products

  • Oracle E-Business Suite 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats