Executive brief
Oracle Work in Process, a component of the Oracle E-Business Suite used for managing manufacturing operations, contains a security vulnerability in its Internal Operations component. A highly privileged attacker with existing access to the underlying server infrastructure could exploit this flaw to gain unauthorized read access to a limited amount of sensitive data. Because the attack requires high-level system access and faces significant technical hurdles, the overall risk to business operations is considered low.
Technical details
A vulnerability exists in the Internal Operations component of Oracle Work in Process (versions 12.2.3 through 12.2.15). The flaw is characterized by a high attack complexity, requiring a high-privileged attacker to have local logon access to the infrastructure where the software executes. Successful exploitation results in a low-impact breach of confidentiality, allowing unauthorized read access to a subset of data managed by the application. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Work in Process 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
- 2026-07-21: disclosed