Oracle E-Business Suite: CVE-2026-46817 aktiv ausgenutzt
LONDON (IT BOLTWISE) – Ein kritisches Oracle-Problem in der E-Business-Suite wird laut Berichten bereits aktiv ausgenutzt: CVE-2026-46817 (CVSS 9,8) betrifft Oracle Payments und kann laut Datenbankbeschreibung zu einer Übernahme anfälliger …
IT Security Nachrichten it-boltwise.de 1 Min. LesezeitKEV ACTIVEEPSS 13% KRITIS / Energie Finanzwesen & Banking 0-CLICK
LONDON (IT BOLTWISE) – Ein kritisches Oracle-Problem in der E-Business-Suite wird laut Berichten bereits aktiv ausgenutzt: CVE-2026-46817 (CVSS 9,8) betrifft Oracle Payments und kann laut Datenbankbeschreibung zu einer Übernahme anfälliger Installationen führen. Betroffene Versionen reichen von 12.2.3 bis 12.2.15, Patches kamen als Teil des Critical Security Patch Update. Parallel zeigt der Kontext weiterer, ebenfalls schwerwiegender […]
Verschlüsselung im Ruhezustand & Unveränderbare SIEM-Logs
Geschützt (KMS Envelope Encryption)
Angreifer penetrieren Perimeter und WAF ungehindert. Schicht 3 (Micro-Segmentierung & Port-Drop) bildet die entscheidende Stop-Linie zur Schadenseindämmung.
Sofortige Quarantäne oder Notfall-Patching binnen weniger Stunden unumgänglich. Direkte Übernahme ohne Vorwarnung möglich.
NIS-2 / KRITIS Frühwarn- und Meldepflicht (24h-Frist gem. § 30 BSIG-E / EU-Richtlinie 2022/2555). Bei personenbezogenen Daten droht DSGVO-Haftung bis zu 10 Mio. € bzw. 2% des weltweiten Jahresumsatzes.
Advisory Radar
Hersteller-Sicherheitsmeldungen & Patch-Status
Offizielles Hersteller-Update verfügbar
Handlungsempfehlung für Administratoren
Hersteller hat ein verifiziertes Patch-Release herausgegeben. Sofortiges Rollout auf Test- und Produktivsystemen empfohlen.
Analyse für CVE-2026-46817 auf Basis von Live-CTI (ENISA EUVD): CVSS 0.0 · EPSS 0.0% · CISA KEV: ja. Handlungsableitung aus den verlinkten Hersteller-Quellen.
🛡️ Angriffsfläche & Exposure
Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.
1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Verwandte Schwachstellen (gleicher Hersteller)
CVE-2026-87230CVE-2026-87230 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful
CVSS 10.0
CVE-2026-83099CVE-2026-83099 | Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode). Supported versions that are affected are 12.2.1.19.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms. While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability
CVSS 10.0
CVE-2026-83059CVE-2026-83059 | Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory. While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change). Successful attack
CVSS 10.0
Synthetische RAG-Antwort
HAND-OFF
Auf Smartphone übergeben (CVE-2026-46817)
Scannen Sie den QR-Code mit der Smartphone-Kamera für sofortigen mobilen Zugriff: