Description
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in Oracle Production Scheduling allows unauthenticated attackers with network access over HTTP to potentially compromise the system. The attack requires human interaction from a user other than the attacker and would result in unauthorized access to critical data or complete control over all data accessible by the Scheduling application. The flaw is rated moderate with a CVSS base score of 5.3, indicating effect.

Affected Systems

Affected instances include Oracle Corporation's Oracle Production Scheduling component of the Oracle E-Business Suite, specifically versions 12.2.3 through 12.2.15. This product uses the Internal Operations module, and only the stated versions are known to be vulnerable.

Risk and Exploitability

The risk of exploitation is considered moderate. The CVSS score reflects moderate severity, while the EPSS score of less than 1% suggests a low probability of real-world exploitation. With the vulnerability not listed in the CISA KEV database, it has no known widespread exploitation. Attackers would need HTTP access to the exposed service and a victim to interact with the application; the lack of authentication lowers the barrier, but the requirement of human interaction limits immediate exploitation potential.

Generated by OpenCVE AI on August 5, 2026 at 01:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Review Oracle security updates for Oracle Production Scheduling and apply any available patches or fixes when released.
  • Configure the application to validate and whitelist redirect URLs to eliminate the open redirect flaw (CWE-601).
  • Sanitize and validate all external data inputs used by the system to mitigate privilege escalation or data leakage (CWE-640).
  • Restrict external access control lists to limit unauthenticated HTTP access to the application.

Generated by OpenCVE AI on August 5, 2026 at 01:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Access in Oracle Production Scheduling

Sun, 02 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Access in Oracle Production Scheduling

Mon, 27 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Access Vulnerability in Oracle Production Scheduling

Sun, 26 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Access Vulnerability in Oracle Production Scheduling

Wed, 22 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-345
CWE-601
CWE-640
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle production Scheduling
CPEs cpe:2.3:a:oracle:production_scheduling:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle production Scheduling
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Production Scheduling
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T14:06:09.753Z

Reserved: 2026-07-14T14:54:48.738Z

Link: CVE-2026-62517

cve-icon Vulnrichment

Updated: 2026-07-22T14:06:05.745Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:15:03Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')

  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password