Executive brief
A vulnerability exists in the Internal Operations component of Oracle Work in Process, a module within the Oracle E-Business Suite used for managing manufacturing operations. A low-privileged attacker could exploit this flaw to gain unauthorized access to sensitive business data or modify existing records. Successful exploitation requires a legitimate user to perform an action, such as clicking a malicious link, and could potentially allow the attacker to impact other integrated Oracle products.
Technical details
This vulnerability affects the Internal Operations component of Oracle Work in Process versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. The attack requires human interaction (UI:R) from a person other than the attacker and involves a scope change (S:C), meaning the security impact can extend beyond the Work in Process module to other parts of the Oracle E-Business Suite. Successful exploitation can result in unauthorized read access to all accessible data (Confidentiality: High) and unauthorized update, insert, or delete access to some data (Integrity: Low). The vulnerability was addressed in the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle Work in Process 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released.