Junglewise Threat Intelligence

CVE-2026-60962: Oracle E-Business Suite Flow Manufacturing data manipulation in Internal Operations

CVE-2026-60962 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Flow Manufacturing, a module within the Oracle E-Business Suite used for production management. A low-privileged user could potentially view, modify, or delete certain manufacturing data if they can trick an authorized user into performing a specific action. This could lead to unauthorized changes in production records or the exposure of sensitive operational information.

Technical details

This vulnerability affects the Internal Operations component of Oracle Flow Manufacturing in Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a Cross-Site Scripting (XSS) or similar UI-based injection flaw, as indicated by the CVSS vector requiring human interaction (UI:R) and resulting in a scope change (S:C). An attacker with low-level privileges can exploit this over the network via HTTP to gain unauthorized read, update, or delete access to a subset of the application's data. The exploit requires a victim other than the attacker to interact with a malicious element, which then allows the attacker to impact the manufacturing data or potentially other integrated products.

Affected products

  • Oracle E-Business Suite (Oracle Flow Manufacturing) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References