Executive brief
A vulnerability exists in Oracle Production Scheduling, a component of the Oracle E-Business Suite used for supply chain and manufacturing planning. A low-privileged user with access to the underlying system could trick another user into performing an action that allows the attacker to modify or delete critical business data. This could lead to significant disruptions in production planning and unauthorized changes to sensitive operational records.
Technical details
This vulnerability affects the Internal Operations component of Oracle Production Scheduling (versions 12.2.3 through 12.2.15). It is classified as a local attack requiring low privileges and human interaction from a victim other than the attacker. The vulnerability involves a scope change (CVSS S:C), meaning an exploit can impact security properties of components outside the immediate Oracle Production Scheduling environment. Attackers can achieve unauthorized creation, deletion, or modification of all accessible data, as well as partial unauthorized read access. The issue was addressed in the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle Production Scheduling 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Initial publication by Oracle and NVD