Executive brief
A vulnerability exists in the Internal Operations component of Oracle Production Scheduling, a tool used by manufacturers to optimize supply chain and shop floor operations. An attacker with access to the same local network as the system could potentially take full control of the application. This attack is difficult to perform as it requires a legitimate user to interact with the system during the exploit, but a successful breach could lead to a total loss of data confidentiality and operational integrity.
Technical details
This vulnerability affects the Internal Operations component of Oracle Production Scheduling versions 12.2.3 through 12.2.15. It is classified as difficult to exploit (AC:H) and requires an unauthenticated attacker to be positioned on the same physical or logical network segment (AV:A) as the target hardware. The exploit also requires human interaction (UI:R) from a legitimate user to succeed. If successful, the attacker can achieve a complete takeover of the Oracle Production Scheduling instance, impacting confidentiality, integrity, and availability. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Production Scheduling (Oracle E-Business Suite) 12.2.3 - 12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory