Description
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Work in Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Work in Process accessible data as well as unauthorized read access to a subset of Oracle Work in Process accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in Oracle Work in Process, part of Oracle E‑Business Suite. The flaw allows an attacker with low privileges and network access via HTTP to perform unauthorized updates, inserts, or deletions, as well as read restricted data. The attacker must interact with a user other than themselves, implying that successful exploitation requires some level of social engineering or user cooperation. Because the vulnerability can change the scope of the affected system, its impacted integrity and confidentiality can extend beyond the immediate product. This results in the loss or corruption of data that is normally protected by the application’s access controls.

Affected Systems

The product affected is Oracle Work in Process within Oracle E‑Business Suite. Versions 12.2.5 through 12.2.15 are vulnerable. These versions include the internal operations component, which handles critical business data and processes.

Risk and Exploitability

The CVSS v3.1 base score is 5.4, indicating a moderate level of risk. The EPSS score is less than 1%, showing a low probability of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network via HTTP and requires the attacker to have low privileges and to obtain user interaction. While the risk is moderate, the potential to change the scope of the impact means it can affect other Oracle products if the attacker gains broader access.

Generated by OpenCVE AI on August 4, 2026 at 00:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 patch for Oracle Work in Process (versions 12.2.5‑12.2.15).
  • After applying the patch, limit HTTP access to the internal‑operations interface by firewall rules or network segmentation, ensuring only authorized users can reach the vulnerable endpoints.
  • Enable or enforce multi‑factor authentication for all users with read/write privileges to Oracle Work in Process.
  • Monitor database logs for unexpected changes or reads and investigate any anomalies promptly.

Generated by OpenCVE AI on August 4, 2026 at 00:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Vulnerability Enabling Unauthorized Data Modification in Oracle Work in Process

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Vulnerability Enabling Unauthorized Data Modification in Oracle Work in Process

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Update and Disclosure via HTTP in Oracle Work in Process

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Update and Disclosure via HTTP in Oracle Work in Process

Wed, 22 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-352
CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Work in Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Work in Process accessible data as well as unauthorized read access to a subset of Oracle Work in Process accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle work In Process
CPEs cpe:2.3:a:oracle:work_in_process:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle work In Process
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Work In Process
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T13:12:14.180Z

Reserved: 2026-07-14T14:54:48.741Z

Link: CVE-2026-62563

cve-icon Vulnrichment

Updated: 2026-07-22T13:12:07.960Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:30:18Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')