Description
Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Financials. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Financials accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Financials accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an access control flaw that allows a low‑privileged attacker with network access via HTTP to bypass internal controls in Oracle Process Manufacturing Financials. This flaw can enable the attacker to create, delete, or modify critical data and read any data stored by the application. The weakness is classified as CWE‑284, leading to high confidentiality and integrity impacts while availability is not affected.

Affected Systems

Oracle Process Manufacturing Financials, part of Oracle E‑Business Suite, affects versions 12.2.3 through 12.2.15. Other versions are not known to be impacted by this issue.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 indicates a high‑severity vulnerability that can be exploited over the network without user interaction. The EPSS score of less than 1% suggests that exploitation is currently uncommon, and the vulnerability is not listed in the CISA KEV catalog. However, the flaw is easily exploitable by an attacker with low privileges and network access to the Internal Operations component, and it can result in unauthorized data creation, deletion, modification, and read access to all data stored in the system.

Generated by OpenCVE AI on August 4, 2026 at 01:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s latest patch or update released for the affected 12.2.3‑12.2.15 releases.
  • Restrict HTTP access to the Internal Operations component by limiting connections to trusted IP addresses or by requiring VPN authentication.
  • Enforce strict role‑based access controls so that low‑privileged users cannot perform data modification or read sensitive data.
  • Implement continuous monitoring of audit logs for unexpected data creation, deletion, or modification activities and investigate anomalies promptly.

Generated by OpenCVE AI on August 4, 2026 at 01:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title HTTP Access Control Bypass in Oracle Process Manufacturing Financials 12.2.x

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title HTTP Access Control Bypass in Oracle Process Manufacturing Financials 12.2.x

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation and Data Access Control Bypass in Oracle Process Manufacturing Financials

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation and Data Access Control Bypass in Oracle Process Manufacturing Financials

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Financials. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Process Manufacturing Financials accessible data as well as unauthorized access to critical data or complete access to all Oracle Process Manufacturing Financials accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle process Manufacturing Financials
CPEs cpe:2.3:a:oracle:process_manufacturing_financials:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle process Manufacturing Financials
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Process Manufacturing Financials
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:08:24.150Z

Reserved: 2026-07-08T15:52:20.746Z

Link: CVE-2026-61301

cve-icon Vulnrichment

Updated: 2026-07-22T18:08:14.866Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses