Executive brief
A vulnerability exists in the Oracle Product Workbench, a component of the Oracle E-Business Suite used for managing product lifecycles and internal operations. An attacker with basic user access to the network can exploit this flaw to view, modify, or delete sensitive business data. This could lead to a significant breach of corporate information or unauthorized changes to critical product records.
Technical details
This vulnerability affects the Internal Operations component of Oracle Product Workbench within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged user credentials and network access via HTTP. An attacker can leverage this vulnerability to achieve unauthorized creation, deletion, or modification of all data accessible to the Product Workbench, as well as full read access to that data. The vulnerability has a CVSS 3.1 base score of 8.1, reflecting high impacts on confidentiality and integrity, though it does not directly impact service availability.
Affected products
- Oracle Corporation Product Workbench (Oracle E-Business Suite) 12.2.3 - 12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this advisory.
- 2026-07-21: disclosed: CVE-2026-61333 was published to the NVD.