Executive brief
A vulnerability exists in Oracle Property Manager, a component of the Oracle E-Business Suite used for managing real estate portfolios and lease agreements. A high-privileged attacker could exploit this flaw to gain full control over the application, potentially leading to the theft of sensitive financial data or disruption of property management operations. Organizations using affected versions should apply the latest security updates from Oracle to mitigate this risk.
Technical details
This vulnerability affects the Internal Operations component of Oracle Property Manager within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires high privileges (PR:H) but no user interaction. An attacker can exploit this over the network via HTTP to achieve a complete compromise of the product, impacting confidentiality, integrity, and availability (C:H/I:H/A:H). While the specific CWE is not provided in the advisory, the impact is described as a full 'takeover' of the affected component. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Corporation Property Manager 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published