Description
Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Project Definition). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Foundation. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Project Foundation accessible data as well as unauthorized read access to a subset of Oracle Project Foundation accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Project Foundation. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Project Definition component of Oracle Project Foundation permits a low‑privileged attacker with network access via HTTP to modify, insert, or delete data, read restricted data, and induce a partial denial of service. This vulnerability has been rated as having moderate impact on confidentiality, integrity, and availability, as reflected in the CVSS 3.1 base score of 6.3.

Affected Systems

Oracle Project Foundation, part of Oracle E‑Business Suite, is affected. All supported builds from version 12.2.3 through 12.2.15 contain the vulnerability.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate risk while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based over HTTP and requires only low privileged access to the target system.

Generated by OpenCVE AI on August 4, 2026 at 17:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Project Foundation security patch released in the July 2026 CPU update.
  • Restrict HTTP access to the Project Definition component to trusted network segments to reduce exposure.
  • If patching is delayed, disable or restrict the Project Definition module or its exposed endpoints to prevent unauthorized operations.
  • Monitor application logs for abnormal database activity or denial‑of-service patterns to detect attempts or compromises early.

Generated by OpenCVE AI on August 4, 2026 at 17:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Oracle Project Foundation Unauthorized Data Modification and Partial Denial of Service via Low Privilege HTTP Attack

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Oracle Project Foundation Unauthorized Data Modification and Partial Denial of Service via Low Privilege HTTP Attack

Tue, 28 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low-Privilege HTTP Access in Oracle Project Foundation
Weaknesses CWE-639

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low-Privilege HTTP Access in Oracle Project Foundation
Weaknesses CWE-284
CWE-639

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Project Definition). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Foundation. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Project Foundation accessible data as well as unauthorized read access to a subset of Oracle Project Foundation accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Project Foundation. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle project Foundation
CPEs cpe:2.3:a:oracle:project_foundation:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle project Foundation
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Project Foundation
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T15:29:17.728Z

Reserved: 2026-07-08T15:51:40.546Z

Link: CVE-2026-60587

cve-icon Vulnrichment

Updated: 2026-07-27T15:29:01.280Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:03Z

Weaknesses