Executive brief
Oracle Property Manager, a component of the Oracle E-Business Suite used for managing real estate portfolios and lease agreements, contains a security vulnerability in its Internal Operations component. An attacker who already has high-level administrative access to the underlying server infrastructure could potentially view a limited amount of sensitive data within the application. This is considered a low-risk issue because it requires significant existing access and is difficult to execute.
Technical details
This vulnerability affects the Internal Operations component of Oracle Property Manager within Oracle E-Business Suite. It is classified as an information disclosure bug that allows a high-privileged attacker with local logon access to the underlying infrastructure to compromise the application's confidentiality. The attack complexity is rated as high, suggesting that specific timing or environmental conditions are required for successful exploitation. Successful exploitation results in unauthorized read access to a subset of data accessible by the Property Manager. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Corporation Property Manager 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed