Description
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in takeover of Oracle Flow Manufacturing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Flow Manufacturing in Oracle E-Business Suite contains a weakness that allows an attacker with only low privileges and network access over HTTP to execute privileged operations inside the application’s internal operations component. The flaw results in a full takeover of the application, giving the attacker complete control over the system, its data, and any services it hosts. The vulnerability is an improper access control error that exposes sensitive functionality to unauthorized users.

Affected Systems

The affected product is Oracle Flow Manufacturing as part of Oracle E‑Business Suite. All installations from version 12.2.3 through 12.2.15 are impacted. The flaw exists in the internal operations component and applies regardless of deployment topology or environment configuration.

Risk and Exploitability

The CVSS base score is 8.8, indicating high severity with complete confidentiality, integrity, and availability impacts. The EPSS score is below 1%, suggesting a low but non‑zero chance of exploitation. The vulnerability is not listed in the CISA KEV catalog, so no confirmed exploitation is known. The likely attack vector is a direct HTTP connection from a remote host, requiring only low‑privilege access to the application. An attacker can exploit the flaw without elevated privileges or special preconditions beyond network reachability and the ability to interact with the HTTP interface.

Generated by OpenCVE AI on August 24, 2026 at 23:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch provided in Oracle’s August 2026 security alert to fix the unauthorized access flaw
  • Restrict HTTP access to the application by configuring firewall or IP‑based filtering to allow traffic only from trusted networks
  • Upgrade to a version later than 12.2.15 that contains the fix if an immediate patch is not available

Generated by OpenCVE AI on August 24, 2026 at 23:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Full Application Takeover via HTTP in Oracle Flow Manufacturing

Mon, 24 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title HTTP-based Remote Takeover Vulnerability in Oracle Flow Manufacturing
Weaknesses CWE-732

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Title HTTP-based Remote Takeover Vulnerability in Oracle Flow Manufacturing
Weaknesses CWE-732

Fri, 21 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote Takeover via HTTP in Oracle Flow Manufacturing
Weaknesses CWE-284

Wed, 19 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote Takeover via HTTP in Oracle Flow Manufacturing
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in takeover of Oracle Flow Manufacturing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle flow Manufacturing
CPEs cpe:2.3:a:oracle:flow_manufacturing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle flow Manufacturing
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Flow Manufacturing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T15:23:25.978Z

Reserved: 2026-07-14T14:54:48.732Z

Link: CVE-2026-62450

cve-icon Vulnrichment

Updated: 2026-08-24T15:13:01.738Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:01.720

Modified: 2026-08-31T15:40:49.350

Link: CVE-2026-62450

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T23:45:17Z

Weaknesses