Description
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the User Interface component of Oracle Production Scheduling, allowing a low‑privileged attacker with network access over HTTP to exploit the system and gain unauthorized access to critical data or the entire database. The flaw enables confidentiality compromise without impacting integrity or availability. The weakness reflects an improper access control risk, enabling the attacker to bypass authentication restrictions.

Affected Systems

Oracle Production Scheduling versions 12.2.3 through 12.2.15 of Oracle E‑Business Suite are affected. These versions are delivered as part of Oracle's enterprise resource planning solution and are commonly deployed in manufacturing and production planning environments.

Risk and Exploitability

The CVSS 3.1 base score is 5.3, indicating moderate risk largely due to confidentiality impact. The EPSS score is below 1%, suggesting exploitation is currently rare or unobserved. The vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog. Attackers must initiate a network connection via HTTP and possess limited privileges; however, once compromised, they can access any data the affected user can see. Because the vector is remote and the exploit is considered difficult, precedence suggests monitoring for related activity but urgent patching is desirable if sensitive data is involved.

Generated by OpenCVE AI on August 2, 2026 at 20:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle's July 2026 patch from the CPU July 2026 flaw.
  • Restrict the Production Scheduling site by limiting it to trusted networks or VPN only, thereby reducing the attack surface for low‑privileged remote users.
  • Enforce strict role‑based only authorized personnel are granted permissions to view or modify production scheduling data, thereby limiting potential data exposure if an attacker gains access.

Generated by OpenCVE AI on August 2, 2026 at 20:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Vulnerable User Interface in Oracle Production Scheduling
Weaknesses CWE-284
CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Vulnerable User Interface in Oracle Production Scheduling
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle production Scheduling
CPEs cpe:2.3:a:oracle:production_scheduling:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle production Scheduling
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Production Scheduling
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:37:53.226Z

Reserved: 2026-07-08T15:51:55.610Z

Link: CVE-2026-61050

cve-icon Vulnrichment

Updated: 2026-07-24T14:37:43.382Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:15:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor