Executive brief
A security vulnerability exists in Oracle Project Portfolio Analysis, a component of the Oracle E-Business Suite used by organizations to manage and evaluate business projects. An attacker with basic user access could exploit this flaw to gain full control over the application. This could lead to the unauthorized viewing of sensitive project data, modification of business records, or disruption of project management operations.
Technical details
A vulnerability in the Internal Operations component of Oracle Project Portfolio Analysis (Oracle E-Business Suite) allows for a complete compromise of the application. The flaw is accessible via HTTP and requires low-privileged authentication, though Oracle notes the exploit complexity is high. Successful exploitation results in high impacts to confidentiality, integrity, and availability, effectively allowing an attacker to take over the affected component. The vulnerability affects versions 12.2.3 through 12.2.15 and was addressed in the July 2026 Oracle Critical Patch Update.
Affected products
- Oracle Corporation Oracle Project Portfolio Analysis 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed: CVE record published to the NVD.