CVE-2026-61083: Medium severity Oracle Oracle E-Business Suite (Performance Management) vulnerability
Vulnerability in the Oracle Performance Management product of Oracle E-Business Suite (component: Appraisals). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Performance Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Performance Management accessible data as well as unauthorized read access to a subset of Oracle Performance Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Performance Management (Oracle E-Business Suite) - Appraisalsto a version that resolves this vulnerability.Fixed in 12.2.3-12.2.15
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61083?
The severity of CVE-2026-61083 is medium with a CVSS score of 5.4.
How do I fix CVE-2026-61083?
To mitigate CVE-2026-61083, apply the latest patch provided by Oracle for affected versions of the Oracle E-Business Suite.
Who can exploit CVE-2026-61083?
CVE-2026-61083 can be exploited by low privileged attackers with network access via HTTP.
Which versions of Oracle E-Business Suite are affected by CVE-2026-61083?
Affected versions of Oracle E-Business Suite are 12.2.3 through 12.2.15.
What component is impacted by CVE-2026-61083?
CVE-2026-61083 impacts the Appraisals component of the Oracle Performance Management product in Oracle E-Business Suite.