Executive brief
Oracle Property Manager, a component of the Oracle E-Business Suite used for managing real estate portfolios and lease agreements, contains a security vulnerability. A low-privileged user could potentially view, modify, or delete certain property-related data if they can trick an authorized user into performing a specific action. This could lead to unauthorized changes in financial or property records and may impact other integrated Oracle business applications.
Technical details
A vulnerability exists in the Internal Operations component of Oracle Property Manager (versions 12.2.3 through 12.2.15). The flaw is categorized by a scope change (S:C), suggesting it may be a Cross-Site Scripting (XSS) or similar injection vulnerability that allows an attacker to impact other products beyond the initial component. An attacker with low privileges can exploit this over the network via HTTP, though success requires interaction from a victim (UI:R). If successful, the attacker can gain unauthorized read, update, insert, or delete access to a subset of data within the Property Manager. The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle Property Manager 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60911
- 2026-07-21: advisory: Included in Oracle July 2026 Critical Patch Update