Description
Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Logistics. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Process Manufacturing Logistics accessible data as well as unauthorized update, insert or delete access to some of Oracle Process Manufacturing Logistics accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Oracle Process Manufacturing Logistics internal operations component allows an attacker who can reach the application over HTTP to bypass normal access controls and obtain confidential information. If successfully exploited, the attacker can read sensitive data or perform update, insert, or delete operations on that data, compromising both confidentiality and integrity. The weakness is an improper access control flaw (CWE‑284).

Affected Systems

Oracle Corporation’s Oracle Process Manufacturing Logistics component of Oracle E‑Business Suite is vulnerable in all supported releases from 12.2.3 through 12.2.15. The vulnerability affects the internal operations module that is exposed over HTTP.

Risk and Exploitability

The CVSS v3.1 base score of 7.1 reflects the severity of the confidentiality impact and limited integrity impact. The EPSS score of less than 1 % suggests that while exploitation is possible, it is unlikely to be automated or widespread at present. The vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploitation. The likely attack vector is a remote web request—an attacker with network access can send HTTP requests to the affected component without needing elevated privileges.

Generated by OpenCVE AI on August 4, 2026 at 01:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑Suite 12.2.3 and newer versions from the linked Oracle security advisory
  • Restrict HTTP access to the internal operations interface and enforce least privilege for all users who interact with the Oracle Process Manufacturing Logistics module
  • Implement strict access‑control checks and regularly audit logs for unauthorized access or changes to the data

Generated by OpenCVE AI on August 4, 2026 at 01:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Data Modification via Low-Privilege HTTP in Oracle Process Manufacturing Logistics

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Data Modification via Low-Privilege HTTP in Oracle Process Manufacturing Logistics

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via HTTP in Oracle Process Manufacturing Logistics

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via HTTP in Oracle Process Manufacturing Logistics

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Process Manufacturing Logistics product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Logistics. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Process Manufacturing Logistics accessible data as well as unauthorized update, insert or delete access to some of Oracle Process Manufacturing Logistics accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle process Manufacturing Logistics
CPEs cpe:2.3:a:oracle:process_manufacturing_logistics:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle process Manufacturing Logistics
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Process Manufacturing Logistics
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:09:00.487Z

Reserved: 2026-07-08T15:52:20.746Z

Link: CVE-2026-61299

cve-icon Vulnrichment

Updated: 2026-07-22T18:08:54.059Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses