Description
Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Systems accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Systems accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability, found in the Internal Operations component of Oracle Process Manufacturing Systems, is an easily exploitable improper access control flaw (CWE‑284). A low‑privileged attacker with network access via HTTP can compromise the system, achieving unauthorized creation, deletion or modification of critical data and gaining full read access to all data available in the system.

Affected Systems

Oracle Process Manufacturing Systems, part of Oracle E‑Business Suite, is affected. Versions 12.2.3 through 12.2.15 contain the flaw, while newer releases are not listed as vulnerable.

Risk and Exploitability

With a CVSS v3.1 base score of 8.1, the vulnerability carries high severity, inflicting major confidentiality and integrity damage while availability is not affected. The EPSS score is less than 1 %, indicating a low but non‑zero likelihood of exploitation in the wild, and the flaw is not currently listed in the CISA known‑exploited vulnerabilities catalog. Attackers likely pivot through the HTTP interface exposed by the Internal Operations component and require only low privilege credentials, making the vulnerability readily actionable for threats that already have network reach into the affected environment.

Generated by OpenCVE AI on August 4, 2026 at 16:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied security patch.
  • Review Oracle’s security advisory at https://www.oracle.com/security-alerts/cpujul2026.html to obtain patch details.
  • Limit HTTP access to the Internal Operations endpoint to authorized users only, using firewall rules, VPN or network segmentation.
  • Conduct a review of user accounts and enforce least‑privilege privileges, ensuring no account has unnecessary permissions to modify or read critical data.

Generated by OpenCVE AI on August 4, 2026 at 16:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Process Manufacturing Systems Allows Unauthorized Data Manipulation

Sun, 02 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Process Manufacturing Systems Allows Unauthorized Data Manipulation

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Low Privilege Data Manipulation via HTTP in Oracle Process Manufacturing Systems

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Data Manipulation via HTTP in Oracle Process Manufacturing Systems

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Systems accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Systems accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle process Manufacturing Systems
CPEs cpe:2.3:a:oracle:process_manufacturing_systems:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle process Manufacturing Systems
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Process Manufacturing Systems
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:11:51.472Z

Reserved: 2026-07-08T15:52:20.745Z

Link: CVE-2026-61287

cve-icon Vulnrichment

Updated: 2026-07-22T18:11:48.195Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:15:03Z

Weaknesses