Executive brief
A vulnerability exists in Oracle Process Manufacturing Regulatory Management, a component of the Oracle E-Business Suite used by manufacturers to manage regulatory compliance and safety data. A low-privileged user could exploit this flaw to gain unauthorized access to sensitive regulatory information or modify critical data. Because this component integrates with other business systems, a successful attack could potentially impact the security and integrity of broader corporate operations.
Technical details
This vulnerability affects the Internal Operations component of Oracle Process Manufacturing Regulatory Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTP. The flaw is notable for a scope change (CVSS S:C), meaning an exploit can impact security beyond the immediate component. Successful exploitation allows for the unauthorized high-impact retrieval of data and low-impact modification (update, insert, or delete) of records. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Corporation Oracle Process Manufacturing Regulatory Management 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update.
- 2026-07-21: disclosed: CVE-2026-62513 was published to the NVD.