Description
Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Regulatory Management. While the vulnerability is in Oracle Process Manufacturing Regulatory Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Process Manufacturing Regulatory Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Process Manufacturing Regulatory Management accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-07-21
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Process Manufacturing Regulatory Management’s internal operations component allows an attacker with low privileges and network access over HTTP to read, insert or delete data that the application normally protects, enabling unauthorized access to critical information and potential data alteration. The listed CVSS vector shows high confidentiality impact, low integrity impact, and no availability impact, meaning the main danger is to data privacy and accuracy rather than service disruption.

Affected Systems

The vulnerability affects Oracle Process Manufacturing Regulatory Management versions 12.2.3 through 12.2.15. It is noted that the flaw is tied to the internal operations code and a scope change indicates that other Oracle E‑Business Suite products that share this code might also be impacted.

Risk and Exploitability

With a CVSS base score of 8.5 the issue is high severity. The EPSS score of less than 1% suggests that while exploitation has not been widely observed, the vulnerability remains exploitable if an attacker can reach the HTTP interface. The flaw is not yet listed in CISA’s KEV catalog, but the combination of remote, low‑privilege access, and significant confidentiality impact makes prompt remediation prudent.

Generated by OpenCVE AI on August 4, 2026 at 00:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU for July 2026, which contains the patch for this access‑control flaw.
  • Limit exposure of the product’s HTTP interfaces by enforcing firewall rules or VPN connectivity, allowing only trusted hosts access to the affected system.
  • Strengthen role‑based access controls within the application to ensure that only users with explicit authorization can view or modify sensitive data, directly addressing the CWE‑284 weakness.

Generated by OpenCVE AI on August 4, 2026 at 00:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title HTTP Low‑Privilege Access Enables Unauthorized Data Modification in Oracle Process Manufacturing Regulatory Management

Sun, 02 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Oracle Process Manufacturing Regulatory Management Access Control Vulnerability

Thu, 30 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Oracle Process Manufacturing Regulatory Management Access Control Vulnerability

Tue, 28 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access Vulnerability in Oracle Process Manufacturing Regulatory Management via HTTP

Sun, 26 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access Vulnerability in Oracle Process Manufacturing Regulatory Management via HTTP

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Regulatory Management. While the vulnerability is in Oracle Process Manufacturing Regulatory Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Process Manufacturing Regulatory Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Process Manufacturing Regulatory Management accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle process Manufacturing Regulatory Management
CPEs cpe:2.3:a:oracle:process_manufacturing_regulatory_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle process Manufacturing Regulatory Management
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Process Manufacturing Regulatory Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:24:40.424Z

Reserved: 2026-07-14T14:54:48.737Z

Link: CVE-2026-62513

cve-icon Vulnrichment

Updated: 2026-07-22T15:24:36.667Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:45:03Z

Weaknesses