Description
Vulnerability in the Oracle Process Manufacturing Process Execution product of Oracle E-Business Suite (component: Internal Operations). The supported version that is affected is 12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Process Execution. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Process Execution. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Process Manufacturing Process Execution allows a low‑privileged attacker with network access to the system’s HTTP interface to compromise the application’s confidentiality, integrity, and availability. Successful exploitation can result in full takeover of the Oracle Process Manufacturing Process Execution component. The impact was measured with a CVSS 3.1 base score of 7.5, reflecting high impacts on confidentiality, integrity, and availability.

Affected Systems

Oracle Process Manufacturing Process Execution version 12.2.15 is affected. No other versions or products were listed as impacted in the CNA data.

Risk and Exploitability

The CVSS score of 7.5 indicates a medium‑to‑high severity. The EPSS score of less than 1 % suggests exploited instances are expected to be scarce at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over the public or internal network via HTTP, and an attacker with low privileges can exploit the flaw to execute code or achieve privilege escalation within the application.

Generated by OpenCVE AI on August 5, 2026 at 01:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch or upgrade to a version that fixes the vulnerability as outlined in Oracle’s July 2026 CPU advisory
  • Restrict HTTP access to the internal operations endpoint so that only trusted networks or hosts can reach it
  • Configure a web application firewall or equivalent defensive layer to detect and block malformed or malicious requests targeting the vulnerable interface

Generated by OpenCVE AI on August 5, 2026 at 01:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Allows Full Takeover of Oracle Process Manufacturing Process Execution
Weaknesses CWE-284

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Oracle Process Manufacturing Process Execution Remote Code Execution Vulnerability
Weaknesses CWE-20
CWE-94

Thu, 30 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Oracle Process Manufacturing Process Execution Remote Code Execution Vulnerability
Weaknesses CWE-20
CWE-94

Tue, 28 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle Process Manufacturing Process Execution via HTTP
Weaknesses CWE-119
CWE-77

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle Process Manufacturing Process Execution via HTTP
Weaknesses CWE-119
CWE-77

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Process Manufacturing Process Execution product of Oracle E-Business Suite (component: Internal Operations). The supported version that is affected is 12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Process Execution. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Process Execution. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle process Manufacturing Process Execution
CPEs cpe:2.3:a:oracle:process_manufacturing_process_execution:12.2.15:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle process Manufacturing Process Execution
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Process Manufacturing Process Execution
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:28:25.028Z

Reserved: 2026-07-14T14:54:48.736Z

Link: CVE-2026-62495

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:15:03Z

Weaknesses