Description
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Flow Manufacturing accessible data as well as unauthorized access to critical data or complete access to all Oracle Flow Manufacturing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper access control flaw in the Internal Operations component of Oracle Flow Manufacturing, classified as CWE‑284. It allows attackers with low‑privileged accounts and network access via HTTP to create, delete, or modify critical data and to read all data that they can reach through the web interface. This breach directly compromises both confidentiality and integrity of the application data.

Affected Systems

Affected are Oracle Corporation’s Oracle Flow Manufacturing product, versions 12.2.13 through 12.2.15 inclusive, which are part of Oracle E‑Business Suite.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 signals a high-impact vulnerability, while the EPSS score of less than 1% indicates that exploitation is currently rare. The vulnerability is not listed in CISA KEV, so no publicly documented exploits are known. Because an attacker only needs a low‑privilege user account and network connectivity via HTTP, the risk to exposed systems remains significant, especially if role‑based access controls are not properly enforced.

Generated by OpenCVE AI on August 4, 2026 at 15:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a vendor‑issued patch or upgrade Oracle Flow Manufacturing to a fixed version.
  • Limit HTTP access to the Oracle Flow Manufacturing instance, restricting connections to trusted networks or protecting the endpoint with a web application firewall.
  • Enforce strict role‑based access controls so that only authorized privileged users can create, delete, or modify critical data.

Generated by OpenCVE AI on August 4, 2026 at 15:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Access Control Vulnerability in Oracle Flow Manufacturing

Sun, 02 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Access Control Vulnerability in Oracle Flow Manufacturing

Tue, 28 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Flow Manufacturing Enables Data Manipulation

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Flow Manufacturing Enables Data Manipulation

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Flow Manufacturing accessible data as well as unauthorized access to critical data or complete access to all Oracle Flow Manufacturing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle flow Manufacturing
CPEs cpe:2.3:a:oracle:flow_manufacturing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle flow Manufacturing
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Flow Manufacturing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:35:16.840Z

Reserved: 2026-07-14T14:54:48.736Z

Link: CVE-2026-62497

cve-icon Vulnrichment

Updated: 2026-07-22T15:35:13.020Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:00:12Z

Weaknesses