CVE-2026-62475: Medium severity Oracle Oracle E-Business Suite - Oracle Shipping Execution vulnerability
Vulnerability in the Oracle Shipping Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Shipping Execution. Successful attacks of this vulnerability can result in takeover of Oracle Shipping Execution. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Shipping Execution (Oracle E-Business Suite) - Internal Operationsto a version that resolves this vulnerability.Fixed in 12.2.3-12.2.15
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Organizations running Oracle Shipping Execution as part of Oracle E-Business Suite versions 12.2.3 through 12.2.15 are affected. Exploitation targets the Internal Operations component over HTTP.
What access does an attacker need to exploit it?
An attacker needs network access via HTTP and high privileges. No user interaction is required, but exploitation is rated difficult.
What is the potential impact of a successful attack?
A successful attack can result in takeover of Oracle Shipping Execution, with high confidentiality, integrity, and availability impact.