CVE-2026-46837: High severity Oracle Oracle Flow Manufacturing vulnerability
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Security). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in takeover of Oracle Flow Manufacturing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Flow Manufacturing (Oracle E-Business Suite) - Securityto a version that resolves this vulnerability.Fixed in 12.2.9-12.2.15
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46837?
The severity of CVE-2026-46837 is rated high with a CVSS score of 8.8.
How do I fix CVE-2026-46837?
To fix CVE-2026-46837, apply the latest security patches provided by Oracle for the affected versions of Oracle Flow Manufacturing.
Who is affected by CVE-2026-46837?
CVE-2026-46837 affects users of Oracle Flow Manufacturing in versions 12.2.9 to 12.2.15.
What type of attack is enabled by CVE-2026-46837?
CVE-2026-46837 allows a low privileged attacker with network access to exploit SQL vulnerabilities and potentially compromise Oracle Flow Manufacturing.
Is CVE-2026-46837 easily exploitable?
Yes, CVE-2026-46837 is considered easily exploitable due to its low privilege and network access requirements.