Description
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Production Scheduling executes to compromise Oracle Production Scheduling. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Production Scheduling, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Production Scheduling accessible data as well as unauthorized read access to a subset of Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 6.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N).
Published: 2026-07-21
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the Oracle Production Scheduling product (Internal Operations component) allows a low‑privileged user with local logon to the infrastructure to create, delete, modify, or read Oracle Production Scheduling data. The exploit requires user interaction but grants unauthorized access to critical data, resulting in confidentiality compromise (low impact) and heightened integrity impact (high).

Affected Systems

Oracle Production Scheduling from Oracle Corporation, versions 12.2.3 through 12.2.15, is affected. The product runs within Oracle E‑Business Suite and may impact additional products if exploited.

Risk and Exploitability

The CVSS 3.1 base score of 6.7 indicates a moderate severity vulnerability. The EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers must have local low‑privilege access and rely on a user other than themselves to perform the exploitation, making the attack path more constrained but still potentially dangerous for environments where local access is granted to many users. Organizations should evaluate the likelihood of local access being available to untrusted personnel and the sensitivity of the protected data before determining remediation urgency.

Generated by OpenCVE AI on August 4, 2026 at 02:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle production scheduling patch or upgrade to the latest supported version (e.g., 12.2.16 or later).
  • Restrict local logon permissions for users who do not need direct access to the Production Scheduling system, and enforce least‑privilege principles.
  • Isolate the Production Scheduling database and application servers in a separate network segment with strict access controls to limit the spread of a successful compromise.

Generated by OpenCVE AI on August 4, 2026 at 02:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low-Privilege Local Access in Oracle Production Scheduling

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low-Privilege Local Access in Oracle Production Scheduling

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Production Scheduling executes to compromise Oracle Production Scheduling. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Production Scheduling, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Production Scheduling accessible data as well as unauthorized read access to a subset of Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 6.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N).
First Time appeared Oracle
Oracle production Scheduling
CPEs cpe:2.3:a:oracle:production_scheduling:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle production Scheduling
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N'}


Subscriptions

Oracle Production Scheduling
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:34:06.317Z

Reserved: 2026-07-08T15:51:55.609Z

Link: CVE-2026-61043

cve-icon Vulnrichment

Updated: 2026-07-24T14:33:52.465Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses