Executive brief
A vulnerability exists in Oracle Production Scheduling, a component of the Oracle E-Business Suite used by organizations to manage manufacturing and supply chain operations. An attacker with basic user credentials can exploit this flaw over the network to modify or delete critical production data and disrupt scheduling services. This could lead to significant operational delays, loss of data integrity, and partial service outages.
Technical details
This vulnerability affects the Internal Operations component of Oracle Production Scheduling within the Oracle E-Business Suite, versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and is reachable via HTTP over the network. Successful exploitation allows an attacker to gain unauthorized creation, deletion, or modification access to critical application data, as well as limited read access. Additionally, the vulnerability can be used to trigger a partial denial of service (DoS) affecting the availability of the scheduling system. The issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Production Scheduling 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed: CVE record published to the NVD.