Description
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Production Scheduling accessible data as well as unauthorized read access to a subset of Oracle Production Scheduling accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Production Scheduling. CVSS 3.1 Base Score 4.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Production Scheduling allows a high‑privileged attacker with network access via HTTP to update, insert, or delete data, read a subset of data, and cause a partial denial of service. The weakness involves improper access control, enabling the attacker to compromise confidentiality, integrity, and availability of the application in a limited way. The vulnerability is exploitable in supported versions 12.2.3 through 12.2.15.

Affected Systems

Oracle Corporation's Oracle Production Scheduling component of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15.

Risk and Exploitability

The CVSS 3.1 Base Score is 4.7, indicating a medium impact. The EPSS score is below 1 %, suggesting a low probability of widespread exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an authenticated attacker with elevated privileges operating over the network using HTTP, who can directly manipulate application data and partially disrupt availability.

Generated by OpenCVE AI on August 4, 2026 at 02:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Production Scheduling patch released in the July 2026 CPU advisory
  • Configure network access controls to allow only trusted IP addresses to reach the Production Scheduling service
  • Enforce strict role‑based access controls within the application to prevent unauthorized data modification and access

Generated by OpenCVE AI on August 4, 2026 at 02:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service in Oracle Production Scheduling

Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Oracle Production Scheduling Access Control Vulnerability with Partial Denial of Service

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Oracle Production Scheduling Access Control Vulnerability with Partial Denial of Service
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Production Scheduling accessible data as well as unauthorized read access to a subset of Oracle Production Scheduling accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Production Scheduling. CVSS 3.1 Base Score 4.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle production Scheduling
CPEs cpe:2.3:a:oracle:production_scheduling:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle production Scheduling
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Production Scheduling
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:34:57.681Z

Reserved: 2026-07-08T15:51:55.609Z

Link: CVE-2026-61044

cve-icon Vulnrichment

Updated: 2026-07-24T14:34:51.531Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses