Executive brief
A vulnerability exists in the Internal Operations component of Oracle Project Portfolio Analysis, a tool used by organizations to manage and evaluate business project investments. A high-privileged user could exploit this flaw to take full control of the application. This could lead to the unauthorized disclosure of sensitive project data, modification of financial records, or disruption of portfolio management operations.
Technical details
This vulnerability (CWE-284) is located in the Internal Operations component of Oracle Project Portfolio Analysis within the Oracle E-Business Suite. It is classified as an improper access control issue that is easily exploitable via HTTP. An attacker requires high privileges (PR:H) and network access to execute the exploit. Successful exploitation allows for a complete takeover of the affected component, impacting confidentiality, integrity, and availability. The vulnerability affects supported versions 12.2.3 through 12.2.15.
Affected products
- Oracle Project Portfolio Analysis 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published