Impact
The vulnerability exists in the Internal Operations component of Oracle Process Manufacturing Financials. An attacker with network access via HTTP can exploit this flaw to create, delete, or modify critical data, or gain full access to all database content. The impact is a loss of confidentiality and integrity for the affected organization, enabling unauthorized data manipulation. The description does not specify whether this results in service interruption, so the effect on availability is unclear.
Affected Systems
Affected are Oracle Process Manufacturing Financials under Oracle E-Business Suite, specifically versions 12.2.3 through 12.2.15 from Oracle Corporation. These versions lack the patch referenced in the July 2026 CPU release.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 classifies this as a high‑severity issue, and the EPSS score of less than 1% indicates low current exploitation probability. It is not listed as a known exploited vulnerability. The attack surface requires a low‑privileged user with network connectivity to the HTTP interface; no elevated privileges or local access are required. In the absence of a patch, the risk remains high if the affected systems are reachable from untrusted networks.
OpenCVE Enrichment