Executive brief
A vulnerability exists in the Quality Management component of Oracle's manufacturing software, which is used by businesses to manage product specifications and development. A person with basic user access to the system can exploit this flaw over the network to gain full control of the application. This could lead to the unauthorized modification of product quality data, theft of proprietary manufacturing specifications, or a total disruption of the product development process.
Technical details
This vulnerability in Oracle E-Business Suite's Process Manufacturing Product Development module is categorized under improper access control and privilege management (CWE-269, CWE-284). It resides in the Quality Management Specs component and is easily exploitable by an authenticated attacker with low-level privileges via HTTP. Successful exploitation allows for a complete takeover of the affected component, impacting confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for June 2026 for remediation.
Affected products
- Oracle E-Business Suite (Oracle Process Manufacturing Product Development) 12.2.3 - 12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory