Executive brief
A vulnerability exists in the Project Definition component of Oracle Project Foundation, a module within the Oracle E-Business Suite used for managing project lifecycles and financials. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete certain project data. This could lead to unauthorized changes in project records or a partial disruption of the service, potentially impacting business operations and data integrity.
Technical details
A vulnerability in the Project Definition component of Oracle Project Foundation (part of Oracle E-Business Suite) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables an attacker to read, update, insert, or delete a subset of data accessible to the Project Foundation module. Additionally, the vulnerability can be used to cause a partial denial of service (DoS). The issue affects versions 12.2.3 through 12.2.15 and was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Project Foundation 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update (CPU) published