Executive brief
A critical vulnerability exists in the Internal Operations component of Oracle Process Manufacturing Product Development, a tool used by manufacturers to manage product recipes and development cycles. A low-privileged user can exploit this flaw over the network to gain full control of the application. This could lead to the theft of proprietary manufacturing formulas, unauthorized changes to production processes, or a complete shutdown of the development environment.
Technical details
This vulnerability is classified as an Improper Access Control issue (CWE-284) within the Internal Operations component of Oracle Process Manufacturing Product Development. It is easily exploitable by a low-privileged attacker with network access via HTTP. The flaw is particularly severe because it involves a 'scope change' (CVSS S:C), meaning a successful exploit allows the attacker to move beyond the affected component to impact other parts of the Oracle E-Business Suite environment. Successful exploitation results in a complete takeover of the product, compromising confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15.
Affected products
- Oracle Process Manufacturing Product Development 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published