Description
Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Systems accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Systems accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Process Manufacturing Systems allows an attacker with low privileges and simple network access over HTTP to create, delete, modify critical data and access all data handled by the system. The vulnerability is an improper access control flaw that leads to confidentiality and integrity violations. The impact allows full unauthorized control over system data.

Affected Systems

Oracle Process Manufacturing Systems versions 12.2.3 through 12.2.15 are affected. The flaw resides in the Internal Operations component of Oracle E‑Business Suite. Users running any of these releases should confirm their deployment version falls within the affected range.

Risk and Exploitability

The CVSS base score of 8.1 indicates high severity, with network access required, low attack complexity, and low privilege needed. The EPSS score is below 1 % indicating a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves a low‑privileged user sending specially crafted HTTP requests to the Internal Operations module, bypassing normal access controls to create, delete, or modify critical data.

Generated by OpenCVE AI on August 5, 2026 at 01:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch from Oracle’s CPU Jul 2026 advisory that addresses the access control flaw.
  • Restrict HTTP access to the Internal Operations component to trusted IP ranges or VPNs, and enforce firewall rules.
  • Strengthen role‑based access control, ensuring that only authorized privileged users can perform data modification actions, and enable detailed audit logging of all modification activities.

Generated by OpenCVE AI on August 5, 2026 at 01:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control Allowing Unauthorized Data Modification in Oracle Process Manufacturing Systems
Weaknesses CWE-284

Tue, 04 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Process Manufacturing Systems Internal Operations
Weaknesses CWE-284

Sat, 01 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Process Manufacturing Systems Internal Operations
Weaknesses CWE-284

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Process Manufacturing Systems via HTTP
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Process Manufacturing Systems via HTTP
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Systems accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Systems accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle process Manufacturing Systems
CPEs cpe:2.3:a:oracle:process_manufacturing_systems:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle process Manufacturing Systems
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Process Manufacturing Systems
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:10:14.827Z

Reserved: 2026-07-08T15:51:55.607Z

Link: CVE-2026-61000

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:30:17Z

Weaknesses