Executive brief
A vulnerability exists in the Internal Operations component of Oracle Production Scheduling, a tool used within the Oracle E-Business Suite to manage manufacturing timelines. A highly privileged attacker could exploit this flaw to modify or delete critical production data, potentially disrupting manufacturing operations. While the flaw is specific to the scheduling tool, an exploit could also impact other integrated business systems.
Technical details
This vulnerability affects the Internal Operations component of Oracle Production Scheduling within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as difficult to exploit, requiring a high-privileged attacker with network access via HTTP. A successful exploit results in a scope change (S:C), meaning the attacker can impact components beyond the immediate security scope of the scheduling product. Impact includes unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to a subset of data. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation guidance.
Affected products
- Oracle Production Scheduling 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory