Description
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Work in Process as well as unauthorized update, insert or delete access to some of Oracle Work in Process accessible data. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Work in Process, a component of Oracle E‑Business Suite, contains an easily exploitable flaw that can be triggered over HTTP by a low‑privileged attacker. When successfully exploited, it allows the attacker to update, insert, or delete data stored in Work in Process and to cause the application to hang or repeatedly crash, resulting in both integrity and availability compromises.

Affected Systems

The vulnerability affects the Oracle Work in Process product, specifically its Internal Operations component, across all supported E‑Business Suite releases from 12.2.3 through 12.2.15. Users running any of these versions with the Work in Process component exposed to HTTP are at risk.

Risk and Exploitability

The flaw carries a CVSS 3.1 base score of 7.1, indicating moderate severity. Attackers only need network access to the Work in Process HTTP interface and, due to the low privilege requirement, can exploit the issue even from a compromised device within the trusted network. The EPSS score is less than 1%, suggesting a low probability of current exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the potential for repeated crashes and unauthorized data modification makes it a significant threat for exposed systems.

Generated by OpenCVE AI on August 21, 2026 at 12:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch or upgrade Oracle Work in Process to a version beyond 12.2.15 as recommended by Oracle.
  • Restrict HTTP access to the Work in Process interface to trusted networks or enforce strong authentication to limit low‑privileged attackers.
  • Disable or limit internal operations features that expose critical data until a patch is applied, and enable logging to monitor for unauthorized update attempts.

Generated by OpenCVE AI on August 21, 2026 at 12:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Oracle Work in Process Internal Operations Exploit Enables Data Modification and Denial of Service
Weaknesses CWE-284
CWE-770

Fri, 21 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Denial of Service via HTTP in Oracle Work in Process
Weaknesses CWE-285

Wed, 19 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Denial of Service via HTTP in Oracle Work in Process
Weaknesses CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Work in Process as well as unauthorized update, insert or delete access to some of Oracle Work in Process accessible data. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H).
First Time appeared Oracle
Oracle work In Process
CPEs cpe:2.3:a:oracle:work_in_process:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle work In Process
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Oracle Work In Process
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T15:28:51.973Z

Reserved: 2026-07-14T14:54:48.732Z

Link: CVE-2026-62458

cve-icon Vulnrichment

Updated: 2026-08-26T13:45:07.392Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:02.337

Modified: 2026-08-31T13:44:11.527

Link: CVE-2026-62458

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:15:05Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-770

    Allocation of Resources Without Limits or Throttling