Description
Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Systems. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, the attack vector is HTTP. A vulnerability in the Internal Operations component of Oracle Process Manufacturing Systems allows a low privileged attacker who can reach the system over HTTP to compromise the application. Successful exploitation can lead to complete takeover of the system, exposing all data and control functions, and it has severe implications for confidentiality, integrity and availability. The weakness involves improper access control (CWE-284), as reflected in CVSS 3.1 scoring of 7.5, indicating that the issue is not trivial and can be fully leveraged once the attacker has network access.

Affected Systems

Oracle Process Manufacturing Systems versions 12.2.3 to 12.2.15 are affected. These are part of the Oracle E‑Business Suite and are deployed in manufacturing operations environments.

Risk and Exploitability

The vulnerability is accessed through a standard HTTP port, meaning it is exposed to anyone on the network who can reach the service. No known public exploit is listed, and the EPSS score of less than 1% indicates a very low probability of exploitation, but the CVSS Base Score of 7.5 demonstrates high potential impact if exploited. Because the attack requires only low privileges and network access, the risk to exposed systems remains significant. The vulnerability is not currently in the CISA KEV catalog, though its severity warrants immediate attention.

Generated by OpenCVE AI on August 24, 2026 at 23:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Process Manufacturing Systems patch or upgrade to a version newer than 12.2.15.
  • Restrict HTTP access to the system so that only trusted IP addresses or internal networks can reach the application.
  • Enforce strong authentication policies and review user privileges to ensure no unnecessary low‑privilege accounts exist.

Generated by OpenCVE AI on August 24, 2026 at 23:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Remote Takeover Vulnerability in Oracle Process Manufacturing Systems via HTTP
Weaknesses CWE-287
CWE-290

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Title Remote Takeover Vulnerability in Oracle Process Manufacturing Systems via HTTP
Weaknesses CWE-287
CWE-290

Fri, 21 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Remote System Takeover via Low Privileged HTTP Access in Oracle Process Manufacturing Systems
Weaknesses CWE-20
CWE-284

Wed, 19 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Remote System Takeover via Low Privileged HTTP Access in Oracle Process Manufacturing Systems
Weaknesses CWE-20
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Systems. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle process Manufacturing Systems
CPEs cpe:2.3:a:oracle:process_manufacturing_systems:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle process Manufacturing Systems
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Process Manufacturing Systems
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T15:21:26.693Z

Reserved: 2026-08-04T22:06:34.600Z

Link: CVE-2026-70829

cve-icon Vulnrichment

Updated: 2026-08-24T15:12:39.931Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:38.100

Modified: 2026-08-28T14:46:32.463

Link: CVE-2026-70829

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T23:30:17Z

Weaknesses