Executive brief
A vulnerability exists in the Internal Operations component of Oracle Process Manufacturing Systems, a tool used by businesses to manage complex manufacturing workflows and production data. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive manufacturing data. This could lead to the theft of proprietary information or the unauthorized modification and deletion of critical production records, potentially disrupting business operations.
Technical details
This vulnerability affects the Internal Operations component of Oracle Process Manufacturing Systems within the Oracle E-Business Suite. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can achieve high confidentiality and integrity impacts, allowing for the unauthorized creation, deletion, or modification of all accessible data within the manufacturing system. The vulnerability does not impact system availability. Affected versions range from 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Oracle Process Manufacturing Systems 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory