Junglewise Threat Intelligence

CVE-2026-62563: Oracle Work in Process unauthorized data access in Internal Operations

CVE-2026-62563 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Oracle Work in Process. Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Work in Process, a module within the Oracle E-Business Suite used for managing manufacturing floor activities. An attacker with low-level access could potentially view, modify, or delete manufacturing data if they can trick a legitimate user into performing a specific action. This could lead to unauthorized changes in production records or the exposure of sensitive operational information.

Technical details

This vulnerability affects the Internal Operations component of Oracle Work in Process within Oracle E-Business Suite versions 12.2.5 through 12.2.15. It is classified as an easily exploitable flaw that requires a low-privileged attacker to have network access via HTTP. The exploit requires human interaction from a user other than the attacker (UI:R) and involves a scope change (S:C), suggesting it may be a Cross-Site Scripting (XSS) or similar injection vulnerability that allows the attacker to impact other products or components. Successful exploitation grants the attacker unauthorized read, update, insert, or delete access to a subset of the application's data. The vulnerability was addressed in the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle Work in Process (Oracle E-Business Suite) 12.2.5-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed: CVE-2026-62563 was published to the NVD.

References

Related threats