Executive brief
A vulnerability exists in the Internal Operations component of Oracle Project Portfolio Analysis, a tool used by businesses to manage and evaluate project investments. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive project data. This could allow them to delete or modify critical business information, potentially disrupting operations and compromising the integrity of financial or strategic planning data.
Technical details
This vulnerability affects the Internal Operations component of Oracle Project Portfolio Analysis within the Oracle E-Business Suite. It is classified as easily exploitable, requiring only low-privileged user authentication and network access via HTTP. An attacker can achieve unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to a subset of the application's data. The vulnerability has been addressed in the Oracle Critical Patch Update for July 2026. Affected versions include 12.2.3 through 12.2.15.
Affected products
- Oracle Corporation Oracle Project Portfolio Analysis 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.
- 2026-07-21: disclosed