Junglewise Threat Intelligence

CVE-2026-83443: Oracle Assets information disclosure in Oracle E-Business Suite

CVE-2026-83443 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Vendors: Oracle.

Executive brief

Oracle Assets is a financial management module within Oracle E-Business Suite used to track and manage fixed assets. This vulnerability allows a low-privileged network user to access sensitive financial asset data without authorization, potentially exposing critical business information about company equipment, depreciation, and asset valuations.

Technical details

The vulnerability is an information disclosure flaw in the Oracle Assets component (Internal Operations) of Oracle E-Business Suite. It is easily exploitable via HTTP by an attacker with low-level network privileges and requires no user interaction. The attack vector is network-based with low complexity. Successful exploitation allows unauthorized access to confidential asset data. Affected versions include 12.2.3 through 12.2.15. Patches are available from Oracle's security updates.

Affected products

  • Oracle E-Business Suite Assets 12.2.3 to 12.2.15

Timeline

  • 2026-09-15: disclosed

References