Description
Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Financials. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Financials accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Financials accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Internal Operations component of Oracle Process Manufacturing Financials. An attacker with network access via HTTP can exploit this flaw to create, delete, or modify critical data, or gain full access to all database content. The impact is a loss of confidentiality and integrity for the affected organization, enabling unauthorized data manipulation. The description does not specify whether this results in service interruption, so the effect on availability is unclear.

Affected Systems

Affected are Oracle Process Manufacturing Financials under Oracle E-Business Suite, specifically versions 12.2.3 through 12.2.15 from Oracle Corporation. These versions lack the patch referenced in the July 2026 CPU release.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 classifies this as a high‑severity issue, and the EPSS score of less than 1% indicates low current exploitation probability. It is not listed as a known exploited vulnerability. The attack surface requires a low‑privileged user with network connectivity to the HTTP interface; no elevated privileges or local access are required. In the absence of a patch, the risk remains high if the affected systems are reachable from untrusted networks.

Generated by OpenCVE AI on August 4, 2026 at 02:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Process Manufacturing Financials patch released in the July 2026 CPU.
  • Restrict HTTP access to the Oracle Process Manufacturing Financials environment to trusted internal networks or enforce VPN authentication.
  • Configure auditing on the database and application to detect and alert on unauthorized data modifications or access attempts.

Generated by OpenCVE AI on August 4, 2026 at 02:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP API Bypass in Oracle Process Manufacturing Financials

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Data Modification and Unauthorized Access Vulnerability in Oracle Process Manufacturing Financials

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Data Modification and Unauthorized Access Vulnerability in Oracle Process Manufacturing Financials
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Financials. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Financials accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Financials accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle process Manufacturing Financials
CPEs cpe:2.3:a:oracle:process_manufacturing_financials:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle process Manufacturing Financials
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle E-business Suite Process Manufacturing Financials
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:13:57.444Z

Reserved: 2026-07-08T15:51:55.580Z

Link: CVE-2026-60708

cve-icon Vulnrichment

Updated: 2026-07-24T19:13:53.553Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:11.210

Modified: 2026-08-07T21:12:03.593

Link: CVE-2026-60708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:00:02Z

Weaknesses