Description
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-08-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in Oracle Production Scheduling allows a low‑privileged attacker with network access to HTTP to gain unauthorized access to the application. Successful exploitation can expose critical scheduling data or provide complete access to all data stored in the system, resulting in a confidentiality breach.

Affected Systems

The affected product is Oracle Production Scheduling, a component of Oracle E‑Business Suite’s Internal Operations. Supported versions from 12.2.3 through 12.2.15 are impacted by this issue.

Risk and Exploitability

The CVSS 3.1 base score of 6.5 situates the vulnerability as moderate, with a significant confidentiality impact. The EPSS score of 0.00371 (roughly 0.4 %) indicates a very low probability of exploitation in the general population, yet the description notes it is easily exploitable and requires only network connectivity and low privilege. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widely known exploits are currently documented.

Generated by OpenCVE AI on August 21, 2026 at 09:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑supplied patch or upgrade to a non‑affected version of Oracle Production Scheduling
  • Restrict HTTP access to the Production Scheduling interface to trusted internal IP addresses or VPN tunnels to limit attacker reach
  • Implement monitoring and alerting for anomalous authentication attempts against the Production Scheduling application

Generated by OpenCVE AI on August 21, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Allows Unauthorized Access to Oracle Production Scheduling Data
Weaknesses CWE-284

Fri, 21 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via HTTP to Oracle Production Scheduling
Weaknesses CWE-287

Wed, 19 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via HTTP to Oracle Production Scheduling
Weaknesses CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle production Scheduling
CPEs cpe:2.3:a:oracle:production_scheduling:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle production Scheduling
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Production Scheduling
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:11:32.682Z

Reserved: 2026-08-04T22:06:34.592Z

Link: CVE-2026-70720

cve-icon Vulnrichment

Updated: 2026-08-25T15:00:33.155Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:24.437

Modified: 2026-08-31T15:05:47.200

Link: CVE-2026-70720

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T09:30:09Z

Weaknesses