Description
Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Regulatory Management. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Regulatory Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Oracle Process Manufacturing Regulatory Management component of Oracle E‑Business Suite allows an attacker with low system privileges and network access over HTTP to fully compromise the application. The vulnerability can be triggered simply by sending a crafted request, giving the attacker the ability to manipulate the system with confidentiality, integrity, and availability impact. Successful exploitation results in a complete takeover of the product and potentially the underlying database or infrastructure.

Affected Systems

Oracle Process Manufacturing Regulatory Management within Oracle E‑Business Suite is affected. Versions from 12.2.3 up to 12.2.15 are vulnerable. Only these releases receive the relevant fix in the July 2026 CPU.

Risk and Exploitability

The CVSS 3.1 base score is 8.8, indicating a high severity. EPSS theory shows a probability of exploitation of less than 1%, suggesting that while the vulnerability exists, real‑world exploitation may be rare. The vulnerability is not listed in CISA’s KEV catalog. Attackers with basic network access and low privileges can trigger the flaw, and no additional authentication or elevated permissions are required beyond standard HTTP leverage. Because the impact covers all core asset fidelity properties, organizations must treat this as a critical risk.

Generated by OpenCVE AI on August 2, 2026 at 21:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and apply the July 2026 CPU for Oracle Process Manufacturing Regulatory Management from Oracle’s security site
  • Configure firewalls or network segmentation to restrict inbound HTTP access to the affected system
  • Ensure only the minimum set of privileges is granted to any accounts interacting via the web interface

Generated by OpenCVE AI on August 2, 2026 at 21:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title HTTP-Based Low-Privilege Takeover in Oracle Process Manufacturing Regulatory Management

Tue, 28 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Exploitable Low-Privilege HTTP Vulnerability in Oracle Process Manufacturing Regulatory Management
Weaknesses CWE-287
CWE-94

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Exploitable Low-Privilege HTTP Vulnerability in Oracle Process Manufacturing Regulatory Management
Weaknesses CWE-287
CWE-94

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Regulatory Management. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Regulatory Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle process Manufacturing Regulatory Management
CPEs cpe:2.3:a:oracle:process_manufacturing_regulatory_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle process Manufacturing Regulatory Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Process Manufacturing Regulatory Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:25:46.317Z

Reserved: 2026-07-08T15:51:55.578Z

Link: CVE-2026-60681

cve-icon Vulnrichment

Updated: 2026-07-24T15:04:56.422Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:30:04Z

Weaknesses