Description
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in takeover of Oracle Flow Manufacturing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Flow Manufacturing allows an attacker with limited privileges to bypass HTTP authentication, giving full control of the application. This vulnerability enables the attacker to compromise the system’s confidentiality, integrity, and availability by exploiting the authentication bypass in the Internal Operations component.

Affected Systems

Oracle Flow Manufacturing of Oracle E‑Business Suite, all supported versions from 12.2.7 to 12.2.15, is affected. The vulnerability lives in the Internal Operations module of the product.

Risk and Exploitability

The CVSS score of 8.8 indicates a high‑severity flaw, while the EPSS probability of less than 1 % suggests a low likelihood of widespread exploitation at present. The exploit requires network connectivity to the product’s HTTP interface and can be carried out with low‑privilege credentials; the primary attack vector therefore involves remote HTTP access to the affected system.

Generated by OpenCVE AI on August 4, 2026 at 00:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the security patch released in Oracle’s CPU July 2026 security alert for Oracle Flow Manufacturing
  • Restrict network exposure of the product’s HTTP interface to trusted IP ranges or isolate the environment
  • Enforce strict authentication and role‑based access controls according to vendor guidance
  • Monitor application and web server logs for anomalous authentication or configuration events

Generated by OpenCVE AI on August 4, 2026 at 00:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Authentication Bypass in Oracle Flow Manufacturing Allows Application Takeover

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Authentication Bypass in Oracle Flow Manufacturing Allows Application Takeover

Tue, 28 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Attack Enables Takeover of Oracle Flow Manufacturing

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Attack Enables Takeover of Oracle Flow Manufacturing

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in takeover of Oracle Flow Manufacturing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle flow Manufacturing
CPEs cpe:2.3:a:oracle:flow_manufacturing:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle flow Manufacturing
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Flow Manufacturing
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:36:45.833Z

Reserved: 2026-07-14T14:54:48.736Z

Link: CVE-2026-62498

cve-icon Vulnrichment

Updated: 2026-07-22T15:36:40.902Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function