Oracle Work in Process: data tampering via Internal Operations
Medium5.4CVE-2026-62563 · Published Jul 21, 2026 · updated Aug 6, 2026
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Work in Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Work in Process accessible data as well as unauthorized read access to a subset of Oracle Work in Process accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Oracle Work in Process Product | >= 12.2.5, <= 12.2.15 | No fix yet |
Details and references
More Oracle advisories
All Oracle| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 21 | Oracle HRMS (US): takeover via Internal Operations | High7.8 | No fix yet |
| Jul 21 | Oracle HRMS (US): data exposure via Internal Operations | Medium6.5 | No fix yet |
| Jul 21 | Oracle HRMS (US): data tampering via US Payroll Year End | High7.1 | No fix yet |
| Jul 21 | Oracle HRMS (UK): data exposure via UK Payroll | High7.7 | No fix yet |
| Jul 21 | Oracle Java SE: takeover via Install | High7.8 | No fix yet |
| Jul 21 | Oracle Advanced Benefits: data tampering via Self Service Benefits | Medium6.3 | No fix yet |