Executive brief
A vulnerability exists in Oracle Project Portfolio Analysis, a component of the Oracle E-Business Suite used by organizations to manage and analyze project investments. An attacker with low-level user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the unauthorized viewing, modification, or deletion of critical project and financial information, potentially disrupting business operations and compromising data integrity.
Technical details
This vulnerability affects the Internal Operations component of Oracle Project Portfolio Analysis (versions 12.2.3 through 12.2.15). It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. The vulnerability allows an attacker to bypass intended access controls to achieve high confidentiality and integrity impacts. Successful exploitation enables the attacker to perform unauthorized CRUD (Create, Read, Update, Delete) operations on critical data or all data accessible to the affected component. The CVSS 3.1 base score is 8.1, reflecting high impact on confidentiality and integrity with no impact on availability.
Affected products
- Oracle Corporation Oracle Project Portfolio Analysis 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the security alert as part of the July 2026 CPU.
- 2026-07-21: disclosed