Oracle Advanced Benefits: takeover via Self-serv What-if Analysis
High8.0CVE-2026-83483 · Published Sep 15, 2026 · updated Sep 17, 2026
Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self-serv What-if Analysis). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits. While the vulnerability is in Oracle Advanced Benefits, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Advanced Benefits. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Oracle Advanced Benefits Product | >= 12.2.3, <= 12.2.15 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-269
More Oracle advisories
All Oracle| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 15 | Oracle GraalVM for JDK: takeover via Compiler | High8.1 | No fix yet |
| Sep 15 | Oracle GraalVM for JDK: data tampering via Compiler | High7.0 | No fix yet |
| Sep 15 | Oracle GraalVM for JDK: takeover via Compiler | High8.1 | No fix yet |
| Sep 15 | Oracle VM VirtualBox: flaw in Core | Low3.2 | No fix yet |
| Sep 15 | Oracle VM VirtualBox: denial of service via Core | Medium6.0 | No fix yet |
| Sep 15 | Oracle GraalVM: takeover via Compiler | High8.1 | No fix yet |