Description
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Flow Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Flow Manufacturing accessible data as well as unauthorized read access to a subset of Oracle Flow Manufacturing accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Flow Manufacturing’s Internal Operations component allows a low‑privileged attacker who can access the system over HTTP to carry out unauthorized update, insert, or delete operations, and read a subset of data. The flaw is caused by insufficient access control (CWE‑284) and a cross‑site request forgery vulnerability (CWE‑352). Successful exploitation results in confidentiality and integrity compromise of application data and requires human interaction from a user other than the attacker, making the attack not fully automated.

Affected Systems

Oracle Flow Manufacturing, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected.

Risk and Exploitability

The CVSS 3.1 base score of 5.4 signals moderate severity. The EPSS score of less than 1% indicates a very low probability of real‑world exploitation, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires network access over HTTP, low authentication and privilege, and depends on user interaction, which limits automated attacks. Because the flaw includes a scope change, an exploit could enable unauthorized data operations within Flow Manufacturing and potentially impact other Oracle products that integrate with the platform.

Generated by OpenCVE AI on August 2, 2026 at 20:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch that addresses CVE‑2026‑60962.
  • Restrict external HTTP access to Oracle Flow Manufacturing by limiting connections to trusted IP ranges or employing a web application firewall to block unauthorized requests.
  • Enforce strict least‑privilege rules on application accounts, review and tighten ACLs, and implement request‑validation checks to prevent cross‑site request forgery and improper access control.

Generated by OpenCVE AI on August 2, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Unauthorized Data Modification via HTTP in Oracle Flow Manufacturing

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unprivileged Network Attack Enables Unauthorized Data Access in Oracle Flow Manufacturing
Weaknesses CWE-640

Sat, 25 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unprivileged Network Attack Enables Unauthorized Data Access in Oracle Flow Manufacturing
Weaknesses CWE-284
CWE-640

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Flow Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Flow Manufacturing accessible data as well as unauthorized read access to a subset of Oracle Flow Manufacturing accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle flow Manufacturing
CPEs cpe:2.3:a:oracle:flow_manufacturing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle flow Manufacturing
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Flow Manufacturing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:27:24.477Z

Reserved: 2026-07-08T15:51:55.604Z

Link: CVE-2026-60962

cve-icon Vulnrichment

Updated: 2026-07-24T15:27:18.293Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-07-21T22:18:30.337

Modified: 2026-07-24T16:16:45.707

Link: CVE-2026-60962

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:30:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-352

    Cross-Site Request Forgery (CSRF)