Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Systems. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Wed, 19 Aug 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote System Takeover via Low Privileged HTTP Access in Oracle Process Manufacturing Systems | |
| Weaknesses | CWE-20 CWE-284 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Systems. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle process Manufacturing Systems |
|
| CPEs | cpe:2.3:a:oracle:process_manufacturing_systems:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle process Manufacturing Systems |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T21:02:02.624Z
Updated: 2026-08-18T21:02:02.624Z
Reserved: 2026-08-04T22:06:34.600Z
Link: CVE-2026-70829
No data.
Status : Awaiting Analysis
Published: 2026-08-18T21:17:38.100
Modified: 2026-08-20T13:07:28.683
Link: CVE-2026-70829
No data.