CVE-2026-62517: Medium severity Oracle Oracle Production Scheduling vulnerability
Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Production Scheduling accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle E-Business Suite - Oracle Production Scheduling (Internal Operations)to a version that resolves this vulnerability.Fixed in 12.2.3-12.2.15
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62517?
CVE-2026-62517 has a medium severity rating of 5.3.
What are the affected software versions for CVE-2026-62517?
The affected software versions for CVE-2026-62517 are Oracle E-Business Suite versions 12.2.3 to 12.2.15.
How can an attacker exploit CVE-2026-62517?
CVE-2026-62517 can be exploited by an unauthenticated attacker with network access via HTTP.
What impact does CVE-2026-62517 have on Oracle Production Scheduling?
CVE-2026-62517 allows an attacker to compromise Oracle Production Scheduling without authentication.
What mitigations are available for CVE-2026-62517?
Mitigating CVE-2026-62517 involves applying relevant patches and updates from Oracle for the affected software.