Executive brief
A vulnerability exists in the Internal Operations component of Oracle Process Manufacturing Systems, a tool used by manufacturers to manage production and supply chain processes. A high-privileged user could exploit this flaw over the network to gain full control of the system. This could lead to a complete loss of data confidentiality, unauthorized changes to manufacturing records, and disruption of business operations.
Technical details
This vulnerability affects the Internal Operations component of Oracle Process Manufacturing Systems within Oracle E-Business Suite versions 12.2.11 through 12.2.15. It is classified as an easily exploitable flaw that allows a high-privileged attacker with network access via HTTP to fully compromise the application. Successful exploitation results in a complete takeover of the system, impacting confidentiality, integrity, and availability (CIA triad). The attack requires high privileges but no user interaction. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Corporation Oracle Process Manufacturing Systems (Oracle E-Business Suite) 12.2.11-12.2.15
Timeline
- 2026-07-21: advisory: Initial publication by Oracle and NVD