Executive brief
A vulnerability exists in the Internal Operations component of Oracle Property Manager, a tool used within the Oracle E-Business Suite to manage real estate portfolios and lease agreements. A user with low-level access to the system can exploit this flaw over the network to view, modify, or delete certain property-related data. This could lead to unauthorized changes in financial records or the exposure of sensitive leasing information.
Technical details
This vulnerability affects the Internal Operations component of Oracle Property Manager within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network reachability via HTTP. An attacker can successfully exploit this to gain unauthorized read access to a subset of data and perform unauthorized updates, insertions, or deletions of accessible data. The vulnerability does not impact system availability or result in a full takeover, but it compromises data integrity and confidentiality. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.
Affected products
- Oracle Property Manager 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial publication of the CVE record.
- 2026-07-21: advisory: Oracle released the July 2026 Critical Patch Update.