Description
Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Workbench accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Workbench accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Product Workbench allows a low‑privileged attacker with network access via HTTP to create, delete, modify, or otherwise manipulate critical data. The flaw grants unauthorized creation, deletion, or modification access to critical data, as well as the ability to access all data the product can reach, compromising both confidentiality and integrity of the system.

Affected Systems

Oracle Corporation’s Product Workbench component of Oracle E-Business Suite, specifically the Internal Operations module, is affected in versions 12.2.3 through 12.2.15.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity with substantial confidentiality and integrity impact. The EPSS score of <1% indicates a low probability of exploitation, yet it still represents a reported risk, and the vulnerability is not currently listed in CISA’s KEV catalog. The attack vector is network‑based, requiring only low‑privilege credentials and HTTP access to the product, making the vulnerability potentially easily exploitable by attackers who can reach the target system over the network.

Generated by OpenCVE AI on August 5, 2026 at 01:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Product Workbench patches to eliminate the vulnerability
  • Restrict product exposure by limiting HTTP access to trusted network segments or applying firewall rules to prevent unauthorized access to Product Workbench
  • Implement continuous monitoring of audit logs for suspicious data‑modification activity

Generated by OpenCVE AI on August 5, 2026 at 01:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Low Privilege Attack Enables Unauthorized Data Modification in Oracle Product Workbench

Thu, 30 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Attack Compromises Oracle Product Workbench

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Attack Compromises Oracle Product Workbench

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Workbench accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Workbench accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle product Workbench
CPEs cpe:2.3:a:oracle:product_workbench:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Workbench
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Product Workbench
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T17:49:52.273Z

Reserved: 2026-07-08T15:52:20.748Z

Link: CVE-2026-61333

cve-icon Vulnrichment

Updated: 2026-07-22T17:49:44.054Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:45:04Z

Weaknesses