Impact
A flaw in the Oracle Process Manufacturing Regulatory Management component of Oracle E‑Business Suite allows an attacker with low system privileges and network access over HTTP to fully compromise the application. The vulnerability can be triggered simply by sending a crafted request, giving the attacker the ability to manipulate the system with confidentiality, integrity, and availability impact. Successful exploitation results in a complete takeover of the product and potentially the underlying database or infrastructure.
Affected Systems
Oracle Process Manufacturing Regulatory Management within Oracle E‑Business Suite is affected. Versions from 12.2.3 up to 12.2.15 are vulnerable. Only these releases receive the relevant fix in the July 2026 CPU.
Risk and Exploitability
The CVSS 3.1 base score is 8.8, indicating a high severity. EPSS theory shows a probability of exploitation of less than 1%, suggesting that while the vulnerability exists, real‑world exploitation may be rare. The vulnerability is not listed in CISA’s KEV catalog. Attackers with basic network access and low privileges can trigger the flaw, and no additional authentication or elevated permissions are required beyond standard HTTP leverage. Because the impact covers all core asset fidelity properties, organizations must treat this as a critical risk.
OpenCVE Enrichment