Description
Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MES for Process Manufacturing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle MES for Process Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle MES for Process Manufacturing accessible data as well as unauthorized update, insert or delete access to some of Oracle MES for Process Manufacturing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
Published: 2026-07-21
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability exposes Oracle MES for Process Manufacturing to unauthenticated HTTP requests that can read and modify critical manufacturing data. The flaw allows an attacker to obtain confidential information with high confidentiality impact and to alter or delete data, resulting in integrity compromise. The CVSS 3.1 base score of 8.2 reflects these high impacts, while the attack maintains low complexity and requires no prior credentials.

Affected Systems

Oracle MES for Process Manufacturing, part of the Oracle E‑Business Suite, is affected in the 12.2.3 through 12.2.15 release line. The vulnerability resides in the Internal Operations component and applies to all installations that expose the MES web interface over HTTP.

Risk and Exploitability

Although the EPSS score is below 1 % indicating a low likelihood of exploitation at this time, the high CVSS score and lack of a KEV listing mean the risk should be taken seriously. The exploit requires an unauthenticated attacker to send crafted HTTP traffic, and an additional human interaction from a user other than the attacker is necessary to trigger the action. Successful attacks can result in unauthorized reads and writes to MES data and, due to the scope change, could also affect linked Oracle products.

Generated by OpenCVE AI on August 4, 2026 at 01:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Critical Patch Update released in July 2026 for Oracle MES 12.2.3‑12.2.15
  • Restrict HTTP access to the MES application by allowing only trusted IP ranges or VPN endpoints
  • Enforce multi‑factor authentication and explicit user authorization for any data modification operations
  • Configure logging and monitoring to detect unusual unauthenticated HTTP activity

Generated by OpenCVE AI on August 4, 2026 at 01:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Compromise in Oracle MES

Sat, 01 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Compromise in Oracle MES

Tue, 28 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Leading to Unauthorized Data Access in Oracle MES for Process Manufacturing

Fri, 24 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Leading to Unauthorized Data Access in Oracle MES for Process Manufacturing

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-352
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MES for Process Manufacturing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle MES for Process Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle MES for Process Manufacturing accessible data as well as unauthorized update, insert or delete access to some of Oracle MES for Process Manufacturing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle mes For Process Manufacturing
CPEs cpe:2.3:a:oracle:mes_for_process_manufacturing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle mes For Process Manufacturing
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle E-business Suite Mes For Process Manufacturing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:27:07.578Z

Reserved: 2026-07-08T15:51:55.613Z

Link: CVE-2026-61101

cve-icon Vulnrichment

Updated: 2026-07-23T19:27:02.828Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:41.247

Modified: 2026-08-06T15:06:12.767

Link: CVE-2026-61101

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-352

    Cross-Site Request Forgery (CSRF)