Description
Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). The supported version that is affected is 12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Product Development. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Product Development. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Quality Management Specs component of the Oracle Process Manufacturing Product Development, where a low‑privileged attacker with network access over HTTP can exploit the flaw. This flaw allows the attacker to compromise the application, leading to a full takeover. The impact covers confidentiality, integrity and availability, as the CVSS vector shows high impacts on all three. The weakness is identified as CWE‑284, which indicates an issue with insufficient authorization.

Affected Systems

Oracle Process Manufacturing Product Development (Oracle E‑Business Suite) version 12.2.15 is affected. The product is specifically the Quality Management Specs component. No other versions are listed as vulnerable.

Risk and Exploitability

CVSS score 8.8 indicates high severity, but the EPSS score is < 1%, suggesting very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. An attacker would require only network access to the HTTP port and a low‑privileged account or guest access; no additional credentials are needed, making the attack relatively easy if the environment is exposed. Because the flaw is not yet widely exploited publicly, the risk is high but the likelihood remains low.

Generated by OpenCVE AI on August 4, 2026 at 01:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s security notifications for the latest patch for version 12.2.15 and apply it when available
  • Configure network firewalls or access controls to limit HTTP access on the affected servers to trusted IP ranges or privileged users
  • If the Quality Management Specs component is not required, disable or remove it from the environment to eliminate the attack surface

Generated by OpenCVE AI on August 4, 2026 at 01:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title HTTP Access Enables Full Takeover of Oracle Process Manufacturing Product Development

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title HTTP Access Enables Full Takeover of Oracle Process Manufacturing Product Development

Mon, 27 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Remote Compromise in Oracle Process Manufacturing Product Development

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Remote Compromise in Oracle Process Manufacturing Product Development

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). The supported version that is affected is 12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Product Development. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Product Development. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle process Manufacturing Product Development
CPEs cpe:2.3:a:oracle:process_manufacturing_product_development:12.2.15:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle process Manufacturing Product Development
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Process Manufacturing Product Development
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:11:14.862Z

Reserved: 2026-07-08T15:52:20.745Z

Link: CVE-2026-61289

cve-icon Vulnrichment

Updated: 2026-07-22T18:11:04.933Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses