Executive brief
A vulnerability in Oracle's manufacturing execution software could allow an unauthorized person to access or modify sensitive production data. This software is used to manage and track manufacturing processes, and a successful exploit could lead to the theft of proprietary information or unauthorized changes to operational records. The attack requires a legitimate user to perform a specific action, such as clicking a malicious link, while logged into the system.
Technical details
This vulnerability exists in the Internal Operations component of Oracle MES for Process Manufacturing (part of Oracle E-Business Suite). It is an unauthenticated, network-based attack via HTTP that requires human interaction (UI:R) from a legitimate user. The vulnerability is characterized by a 'scope change' (S:C), meaning an exploit can impact components beyond the immediate software. Successful exploitation can result in unauthorized read access to all accessible data and unauthorized update, insert, or delete access to a subset of data. Affected versions include 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation.
Affected products
- Oracle Corporation MES for Process Manufacturing 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.