Sceawere
Vulnerability Detail
CVE-2026-70829UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Process Manufacturing Takeover Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Process Manufacturing Systems
- Attack Type
- Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Systems.
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Process Manufacturing Systems product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Systems. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Systems. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-18T21:17:38.100Z",
"pubdate": "2026-08-18T21:17:38.100Z",
"executiveSummary": "A remotely exploitable security vulnerability affects the Oracle Process Manufacturing Systems component of Oracle E-Business Suite, specifically impacting supported versions 12.2.3 through 12.2.15. This high-severity flaw carries a CVSS 3.1 base score of 7.5, reflecting a vector of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H. The vulnerability is characterized as difficult to exploit under normal conditions, requiring network access via the HTTP protocol and low-privileged user credentials. Despite the high attack complexity, successful exploitation of this flaw grants an authenticated malicious actor the capability to achieve a complete system takeover of the affected Oracle Process Manufacturing Systems component. The realization of this risk results in a total compromise of confidentiality, integrity, and availability for the targeted application, potentially exposing sensitive manufacturing data, corrupting operational processes, and disrupting business continuity across the enterprise environment.",
"technicalDetails": "The vulnerability resides within the Internal Operations component of Oracle Process Manufacturing Systems in Oracle E-Business Suite versions 12.2.3 to 12.2.15. The flaw is exposed over the network via the HTTP protocol, allowing remote interaction with the application tier hosting the vulnerable module. Exploitation requires the attacker to possess low-privileged credentials within the application, lowering the initial barrier to entry while still depending on specific operational conditions due to the high attack complexity metric. The attack flow initiates when a malicious low-privileged user crafts and transmits a specialized HTTP request targeting the vulnerable Internal Operations functions within Oracle Process Manufacturing Systems. Because input validation or authorization checks within the affected component are insufficiently robust or improperly implemented, the crafted payload interacts with underlying backend logic or database interfaces in an unintended manner. This interaction bypasses intended security boundaries, allowing the adversary to escalate privileges or execute unauthorized administrative operations within the context of the application. The resulting payload behavior leads directly to the complete takeover of Oracle Process Manufacturing Systems, granting the attacker unrestricted control over application functions, data repositories, and associated workflows. Post-exploitation impact encompasses total loss of confidentiality through unauthorized data exfiltration, total loss of integrity via unauthorized modification of manufacturing configurations and records, and total loss of availability through operational disruption or denial of service within the affected enterprise module."
}