Executive brief
A vulnerability exists in the Internal Operations component of Oracle's Work in Process software, which is used by manufacturing organizations to manage production cycles. An attacker with existing low-level access to the system could potentially view sensitive manufacturing data or cause parts of the application to become unavailable. While the impact is limited and the attack is difficult to perform, it could disrupt operations or lead to minor data exposure.
Technical details
This vulnerability affects the Internal Operations component of Oracle Work in Process within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a local attack requiring low privileges (PR:L) but is characterized by high attack complexity (AC:H), meaning specific timing or environmental conditions must be met for a successful exploit. An attacker with local infrastructure access can achieve unauthorized read access to a subset of data and cause a partial denial of service (DoS). The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle E-Business Suite Work in Process 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory