Executive brief
A vulnerability exists in Oracle Flow Manufacturing, a component of the Oracle E-Business Suite used for managing production processes. An attacker with low-level user credentials can exploit this flaw over the network to gain unauthorized access to sensitive manufacturing data. This could lead to the theft of proprietary information or the unauthorized modification and deletion of critical business records, potentially disrupting operations and compromising data integrity.
Technical details
This vulnerability affects the Internal Operations component of Oracle Flow Manufacturing within Oracle E-Business Suite versions 12.2.13 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and is reachable via the HTTP protocol. An attacker can achieve high confidentiality and integrity impacts, allowing for the full viewing or manipulation of data managed by the Flow Manufacturing module. The vulnerability does not impact system availability (A:N) or cross security boundaries (S:U). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Oracle Flow Manufacturing 12.2.13 - 12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
- 2026-07-21: disclosed