Description
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Production Scheduling executes to compromise Oracle Production Scheduling. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 1.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).
Published: 2026-07-21
Score: 1.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An internal access control flaw in Oracle Production Scheduling allows a local attacker with high privileged logon to the host to perform unauthorized update, insert or delete operations against the application’s data. Because the flaw bypasses normal access checks, the attacker can modify production scheduling information and compromise the integrity of the data that drives the organization’s operations.

Affected Systems

The vulnerability affects Oracle Production Scheduling for Oracle E‑Business Suite, specifically the Internal Operations component. Versions ranging from 12.2.3 through 12.2.15 are vulnerable. Only systems running these affected versions on infrastructure where users have local high‑privileged access are at risk.

Risk and Exploitability

The CVSS 3.1 base score of 1.9 indicates a low severity effect limited to integrity. Exploitation is possible only if the attacker already has authenticated high‑privileged logon on the host where the application runs; the vector is local. EPSS is reported as less than 1 %, meaning exploit attempts are expected to be rare, and the vulnerability is not listed in the CISA KEV catalog. Consequently, the threat exists only where local administrative access is present and the application’s internal access controls are misconfigured.

Generated by OpenCVE AI on August 4, 2026 at 02:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle‑provided patch that addresses CVE‑2026‑61047 or upgrade to the latest Oracle Production Scheduling version that contains the fix.
  • Restrict local privileges on the servers hosting Oracle Production Scheduling to the minimum required for the service to function, removing unnecessary admin rights.
  • Enable auditing on all DML statements against the production scheduling tables and review logs regularly for abnormal changes.

Generated by OpenCVE AI on August 4, 2026 at 02:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Local Privileged Data Modification in Oracle Production Scheduling

Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Local Privileged Data Modification in Oracle Production Scheduling

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Local Privileged Data Modification in Oracle Production Scheduling

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Local Privileged Data Modification in Oracle Production Scheduling

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Production Scheduling executes to compromise Oracle Production Scheduling. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 1.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).
First Time appeared Oracle
Oracle production Scheduling
CPEs cpe:2.3:a:oracle:production_scheduling:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle production Scheduling
References
Metrics cvssV3_1

{'score': 1.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Oracle Production Scheduling
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:41:03.822Z

Reserved: 2026-07-08T15:51:55.610Z

Link: CVE-2026-61047

cve-icon Vulnrichment

Updated: 2026-07-24T14:40:28.261Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses