Description
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in takeover of Oracle Work in Process. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows a low‑privileged attacker with network access via HTTP to exploit the Internal Operations component of Oracle Work in Process and gain full control of the application, compromising confidentiality, integrity, and availability through an easily exploitable path that requires no user interaction.

Affected Systems

Oracle Work in Process versions 12.2.3 through 12.2.15 of Oracle E‑Business Suite are affected; the flaw resides in the Internal Operations module of the Work in Process component.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 indicates a high‑severity impact on all core security properties. The EPSS score is less than 1% and the vulnerability is not listed in CISA KEV, suggesting limited publicly observed exploitation; nevertheless, the attack requires only low‑privilege network access to the HTTP endpoint, making the risk significant for exposed systems.

Generated by OpenCVE AI on August 27, 2026 at 01:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Work in Process security patch that addresses this vulnerability.
  • Restrict network access to the Work in Process HTTP interface until the patch is applied.
  • Enforce least‑privilege access controls on the Work in Process environment.
  • Monitor application logs and network traffic for signs of exploitation attempts.

Generated by OpenCVE AI on August 27, 2026 at 01:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Low-Privileged HTTP Exploit Enables Full Takeover in Oracle Work in Process

Thu, 27 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enables Full Takeover of Oracle Work in Process
Weaknesses CWE-287

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 21 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enables Full Takeover of Oracle Work in Process
Weaknesses CWE-287

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle Corporation
Oracle Corporation oracle Work In Process
Vendors & Products Oracle Corporation
Oracle Corporation oracle Work In Process

Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Title Remote Exploitation via HTTP Enables Low‑Privilege Takeover of Oracle Work in Process
Weaknesses CWE-284

Wed, 19 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Remote Exploitation via HTTP Enables Low‑Privilege Takeover of Oracle Work in Process
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in takeover of Oracle Work in Process. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle work In Process
CPEs cpe:2.3:a:oracle:work_in_process:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle work In Process
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Work In Process
Oracle Corporation Oracle Work In Process
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T15:28:32.828Z

Reserved: 2026-07-14T14:54:48.733Z

Link: CVE-2026-62462

cve-icon Vulnrichment

Updated: 2026-08-26T13:48:33.360Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:02.807

Modified: 2026-08-31T13:44:50.043

Link: CVE-2026-62462

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T02:00:14Z

Weaknesses