Executive brief
A vulnerability exists in the Internal Operations component of Oracle's manufacturing planning software, which is used by businesses to manage production schedules and resources. A user with low-level access to the system can exploit this flaw over the network to gain full control of the application. This could lead to the theft of sensitive manufacturing data, disruption of production operations, or unauthorized changes to business plans.
Technical details
This vulnerability in Oracle E-Business Suite's Process Manufacturing Process Planning (Internal Operations component) is characterized by improper access control or authentication (CWE-269, CWE-306). It is easily exploitable by a low-privileged attacker with network access via HTTP. The flaw does not require user interaction and has a high impact on confidentiality, integrity, and availability, potentially leading to a complete takeover of the affected component. Affected versions range from 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle Process Manufacturing Process Planning (Oracle E-Business Suite) 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: Oracle Security Alert published