Executive brief
Oracle Process Manufacturing Intelligence is a component of Oracle E-Business Suite used for manufacturing operations analytics and reporting. A low-privilege authenticated attacker with network access can exploit a vulnerability in the Internal Operations component to gain unauthorized access to sensitive manufacturing data. This could result in exposure of critical operational data, production schedules, and business-sensitive information.
Technical details
This vulnerability in Oracle Process Manufacturing Intelligence's Internal Operations component allows a low-privileged authenticated attacker to escalate their data access privileges via Oracle Net protocol. The attack requires network connectivity and valid credentials (low privilege user), but does not require user interaction or complex attack prerequisites. Successful exploitation results in unauthorized read access to confidential data within the Process Manufacturing Intelligence application. The CVSS 3.1 vector reflects high confidentiality impact with no integrity or availability consequences. Patch information has not been made available in accessible advisory sources.
Affected products
- Oracle Process Manufacturing Intelligence 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed