Description
Vulnerability in the Oracle Performance Management product of Oracle E-Business Suite (component: Appraisals). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Performance Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Performance Management accessible data as well as unauthorized read access to a subset of Oracle Performance Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Performance Management's Appraisals component contains a broken access control flaw that permits a low‑privileged attacker with network access over HTTP to perform unauthorized updates, inserts, deletions, and read operations against certain managed data. The vulnerability, identified as CWE‑284, does not require privileged credentials or local access. Successful exploitation can lead to alteration of appraisal records, tampering with performance metrics, or leakage of sensitive data, thereby impacting data integrity and confidentiality.

Affected Systems

Oracle Performance Management, part of Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. The Appraisals module is specifically impacted. Organizations using these versions should verify their installed software corresponds to the affected range.

Risk and Exploitability

The CVSS base score of 5.4 indicates a moderate impact with low confidentiality and integrity effects, and the attack vector is network through HTTP. The EPSS score below 1% suggests a very low current probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, an attacker who already has network reach to the application and a low‑privileged account can exploit the flaw with minimal effort to modify or read appraisal data, making the scenario realistic for organizations that do not enforce stringent role‑based access controls on the Performance Management module.

Generated by OpenCVE AI on August 4, 2026 at 04:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade Oracle Performance Management to a version newer than 12.2.15 to eliminate the vulnerability.
  • Restrict network access to the Oracle Performance Management Appraisals endpoint by firewall rules or placing it behind an application gateway, allowing only trusted administrative hosts.
  • Review and enforce strict role‑based access controls, ensuring that only authorized personnel have update or delete permissions on appraisal data.
  • Monitor application logs for unusual update, insert, or delete operations as a detection measure.

Generated by OpenCVE AI on August 4, 2026 at 04:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Modification and Leakage in Oracle Performance Management Appraisals due to Access Control Flaw

Thu, 30 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure via Low‑Privilege HTTP Access in Oracle Performance Management

Mon, 27 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure via Low‑Privilege HTTP Access in Oracle Performance Management

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Performance Management product of Oracle E-Business Suite (component: Appraisals). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Performance Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Performance Management accessible data as well as unauthorized read access to a subset of Oracle Performance Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle performance Management
CPEs cpe:2.3:a:oracle:performance_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle performance Management
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Performance Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:47:47.144Z

Reserved: 2026-07-08T15:51:40.529Z

Link: CVE-2026-60310

cve-icon Vulnrichment

Updated: 2026-07-23T17:47:32.987Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:30:04Z

Weaknesses