Description
Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Systems. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Internal Operations component of Oracle Process Manufacturing Systems enables a high‑privileged attacker with network access via HTTP to take full control of the application. The flaw directly affects confidentiality, integrity, and availability, giving the attacker the ability to perform unauthorized actions and effectively seize the system. The weakness is identified as CWE‑306 (Missing Authentication for Critical Function).

Affected Systems

Oracle Corporation’s Oracle Process Manufacturing Systems, specifically versions 12.2.11 through 12.2.15, are impacted. The vulnerability is present in the internal operations area of the platform, affecting all installations that have not applied the July 2026 Oracle CPU update.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity, while the EPSS score of less than 1 % suggests a low likelihood of exploitation at this time. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires an attacker to already possess high‑level privileges and network access to the system’s HTTP interface. If the attacker succeeds, they can take full control of the system, potentially leading to data breach, sabotage, or other malicious activities.

Generated by OpenCVE AI on August 4, 2026 at 01:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the Oracle CPU July 2026 patch for Process Manufacturing Systems, which addresses the missing authentication flaw.
  • If a patch cannot be applied immediately, limit HTTP access to the system to trusted internal networks or a strict set of IP addresses through firewall rules.
  • Finally, monitor logs for anomalous HTTP activity against the Internal Operations interface and enforce strict account‑based authentication so that only authorized users can reach the application.

Generated by OpenCVE AI on August 4, 2026 at 01:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Missing Authentication Enables System Compromise in Oracle Process Manufacturing Systems

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Missing Authentication Enables System Compromise in Oracle Process Manufacturing Systems

Mon, 27 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title High Privileged HTTP Attack Compromises Oracle Process Manufacturing Systems

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title High Privileged HTTP Attack Compromises Oracle Process Manufacturing Systems

Wed, 22 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Systems. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle process Manufacturing Systems
CPEs cpe:2.3:a:oracle:process_manufacturing_systems:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle process Manufacturing Systems
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Process Manufacturing Systems
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T14:39:17.214Z

Reserved: 2026-07-08T15:52:20.745Z

Link: CVE-2026-61285

cve-icon Vulnrichment

Updated: 2026-07-22T14:38:46.495Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function