Impact
A vulnerability in the Internal Operations component of Oracle Process Manufacturing Systems enables a high‑privileged attacker with network access via HTTP to take full control of the application. The flaw directly affects confidentiality, integrity, and availability, giving the attacker the ability to perform unauthorized actions and effectively seize the system. The weakness is identified as CWE‑306 (Missing Authentication for Critical Function).
Affected Systems
Oracle Corporation’s Oracle Process Manufacturing Systems, specifically versions 12.2.11 through 12.2.15, are impacted. The vulnerability is present in the internal operations area of the platform, affecting all installations that have not applied the July 2026 Oracle CPU update.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, while the EPSS score of less than 1 % suggests a low likelihood of exploitation at this time. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires an attacker to already possess high‑level privileges and network access to the system’s HTTP interface. If the attacker succeeds, they can take full control of the system, potentially leading to data breach, sabotage, or other malicious activities.
OpenCVE Enrichment