Executive brief
A vulnerability in the Internal Operations component of Oracle E-Business Suite's manufacturing module allows an authorized user with low-level permissions to gain full control over the system. This module is used by businesses to manage outsourced manufacturing processes; a successful exploit could lead to the theft of sensitive production data, disruption of manufacturing operations, or unauthorized modification of business records. The flaw is easily exploitable over the network via HTTP.
Technical details
This vulnerability exists in the Internal Operations component of Oracle Outsourced Mfg for Discrete Industries (part of Oracle E-Business Suite). It is classified under CWE-269 (Improper Privilege Management), CWE-287 (Improper Authentication), and CWE-306 (Missing Authentication for Critical Function). An attacker with low-privileged access and network connectivity via HTTP can exploit this flaw to achieve a total compromise of the component. The vulnerability has a CVSS 3.1 base score of 8.8, reflecting high impacts on confidentiality, integrity, and availability. Affected versions include 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for June 2026 for remediation.
Affected products
- Oracle Outsourced Mfg for Discrete Industries 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory