Executive brief
A vulnerability exists in Oracle Property Manager, a component of the Oracle E-Business Suite used for managing real estate portfolios and lease agreements. A high-privileged user could exploit this flaw to gain full control over the Property Manager module. This could lead to the unauthorized viewing or modification of sensitive financial and lease data, potentially disrupting business operations and financial reporting.
Technical details
An improper access control vulnerability (CWE-284) exists in the Internal Operations component of Oracle Property Manager within Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw is easily exploitable by a high-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to compromise the component, leading to a complete loss of confidentiality, integrity, and availability (takeover) of the Oracle Property Manager module. The vulnerability is addressed in the Oracle Critical Patch Update for June 2026.
Affected products
- Oracle Property Manager 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle June 2026 Critical Patch Update released