Executive brief
A vulnerability exists in the Internal Operations component of Oracle Production Scheduling, a tool used within the Oracle E-Business Suite to manage manufacturing timelines. An attacker could potentially gain unauthorized access to sensitive business data or all accessible scheduling information. For an attack to be successful, a legitimate user must perform a specific action, and the exploit is considered difficult to execute.
Technical details
This vulnerability affects the Internal Operations component of Oracle Production Scheduling (versions 12.2.3 through 12.2.15). It is characterized by a high attack complexity, requiring an unauthenticated attacker to have network access via HTTP and necessitating interaction from a legitimate user (UI:R). If successfully exploited, the attacker can achieve unauthorized access to critical data or complete access to all data accessible by the Production Scheduling component. The vulnerability has a CVSS 3.1 base score of 5.3, primarily impacting confidentiality. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Production Scheduling 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory