Executive brief
A vulnerability exists in Oracle Project Portfolio Analysis, a tool used by businesses to manage and evaluate investment projects within the E-Business Suite. An attacker with basic user credentials can exploit this flaw over the network to modify, create, or delete critical project data. This could lead to significant data integrity issues or a partial disruption of the service, impacting business operations and financial reporting.
Technical details
This vulnerability affects the Internal Operations component of Oracle Project Portfolio Analysis within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can achieve unauthorized creation, deletion, or modification of all accessible data within the product. Additionally, the exploit can cause a partial denial of service (DoS), impacting the availability of the application. The vulnerability has a CVSS 3.1 base score of 7.1, primarily impacting integrity and availability.
Affected products
- Oracle Project Portfolio Analysis 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.
- 2026-07-21: disclosed