Executive brief
A critical vulnerability exists in the Internal Operations component of Oracle Work in Process, a key module within the Oracle E-Business Suite used for managing manufacturing operations. This flaw allows an unauthenticated attacker to remotely take full control of the application over the network. Successful exploitation could lead to a total loss of data confidentiality and integrity, potentially disrupting manufacturing processes and exposing sensitive business information.
Technical details
This vulnerability affects the Internal Operations component of Oracle Work in Process within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as easily exploitable, requiring no authentication or user interaction (CVSS 9.8). An attacker can exploit this flaw via HTTP over the network to achieve a complete takeover of the affected product, impacting confidentiality, integrity, and availability. While the specific CWE is not detailed in the advisory, the high CVSS score and 'takeover' description suggest a severe flaw such as an authentication bypass or remote code execution. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Work in Process (Oracle E-Business Suite) 12.2.3 - 12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update and NVD publication.