Description
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Production Scheduling executes to compromise Oracle Production Scheduling. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Production Scheduling. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker who can reach the physical communication segment of the hardware running Oracle Production Scheduling can exploit a missing authorization flaw in the Internal Operations component to take over the system. The vulnerability is considered difficult to exploit and is reflected in a CVSS 3.1 Base Score of 7.1, indicating high severity with full impact on confidentiality, integrity and availability. The weakness primarily stems from inadequate authentication controls over interfaces that can be accessed via the physical communication link. Based on the description, the missing authorization flaw is inferred from the stated lack of authenticated requirement and the need for physical access.

Affected Systems

The affected product is Oracle Production Scheduling, part of Oracle E‑Business Suite, with vulnerable releases spanning versions 12.2.3 through 12.2.15. All systems running these releases are exposed to the flaw, regardless of operating system or deployment environment.

Risk and Exploitability

The attack requires physical access to the communication segment and human interaction from a person not the attacker. Although the EPSS score is reported as < 1%, implying a low probability of exploitation on a broad scale, the CVSS score indicates that a successful exploit would result in a full system takeover. The vulnerability is not listed in CISA’s KEV catalog, and the vendor has not yet provided an official patch; however the risk to environments that allow such physical access remains significant.

Generated by OpenCVE AI on August 4, 2026 at 02:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict physical access to the hardware’s communication segment to authorized personnel only
  • Implement strict authentication and authorization controls for the physical communication interfaces
  • Monitor for unauthorized use or attempts on the physical communication interfaces
  • Consult vendor announcements for updates or mitigation recommendations

Generated by OpenCVE AI on August 4, 2026 at 02:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Physical Access vulnerability enabling takeover of Oracle Production Scheduling

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Physical Access vulnerability enabling takeover of Oracle Production Scheduling

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-287
CWE-640
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Production Scheduling executes to compromise Oracle Production Scheduling. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Production Scheduling. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle production Scheduling
CPEs cpe:2.3:a:oracle:production_scheduling:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle production Scheduling
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Production Scheduling
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:38:55.663Z

Reserved: 2026-07-08T15:51:55.610Z

Link: CVE-2026-61049

cve-icon Vulnrichment

Updated: 2026-07-24T14:38:49.113Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password