Executive brief
A vulnerability exists in the Internal Operations component of Oracle Process Manufacturing Logistics, a tool used by businesses to manage manufacturing supply chains and logistics within the Oracle E-Business Suite. A successful exploit could allow a highly privileged attacker to take complete control of the logistics system, potentially disrupting manufacturing operations and impacting integrated business systems. While the attack is difficult to execute and requires existing high-level access, it poses a significant risk to the confidentiality and integrity of corporate data.
Technical details
This vulnerability affects the Internal Operations component of Oracle Process Manufacturing Logistics within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a high-severity issue (CVSS 8.0) that allows a high-privileged attacker with network access via HTTP to compromise the system. The exploit is characterized as difficult to execute (High Attack Complexity) but results in a Scope change, meaning the impact can extend beyond the immediate component to other parts of the E-Business Suite environment. Successful exploitation can lead to a total loss of confidentiality, integrity, and availability (takeover) of the affected product. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Corporation Oracle Process Manufacturing Logistics 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Initial publication of the vulnerability by Oracle and NVD.