Vulnerability in Oracle E-Business Suite: Oracle Work in Process
CVE-2026-62563

5.4MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-62563?

This vulnerability exists in the Oracle Work in Process component of Oracle E-Business Suite, affecting versions 12.2.5 through 12.2.15. It allows a low privileged attacker with network access via HTTP to exploit the system, leading to unauthorized updates, insertions, deletions, or read access to sensitive data. The nature of the attack necessitates human interaction from an individual other than the attacker, which compounds the risk by potentially impacting other products interconnected within the Oracle ecosystem.

Affected Version(s)

Oracle Work in Process 12.2.5 <= 12.2.15

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.