Description
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Property Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Property Manager accessible data as well as unauthorized read access to a subset of Oracle Property Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Easily exploitable via HTTP when a low privileged user is present. The flaw allows an attacker to perform unauthorized insert, update, or delete operations, as well as read protected data, thereby impacting data integrity and confidentiality. The vulnerability requires human interaction by a person other than the attacker to complete the attack, so the full exploitation depends on user cooperation.

Affected Systems

Oracle Property Manager, part of Oracle E‑Business Suite internal operations, affected versions 12.2.3 through 12.2.15 are listed by Oracle as vulnerable. Only these releases have the flaw according to the CNA information.

Risk and Exploitability

With a CVSS 3.1 score of 5.4 the risk is moderate, the EPSS score of less than 1% indicates a very low probability of widespread exploitation, and the vulnerability is not presently listed in CISA KEV. The likely attack vector is an HTTP endpoint that permits low‑privileged users to submit requests that bypass authorization checks, requiring another user’s interaction to trigger the action.

Generated by OpenCVE AI on August 2, 2026 at 20:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Property Manager to the latest supported version that contains the vendor patch for CVE‑2026‑60911.
  • Restrict HTTP access to the Property Manager server to authenticated users only, and ensure that the application enforces proper session and permission checks.
  • Implement thorough auditing and monitoring of data modification and read requests; investigate any anomalous activity that could indicate exploitation.

Generated by OpenCVE AI on August 2, 2026 at 20:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Property Manager via HTTP

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Data Modification and Read in Oracle Property Manager via HTTP
Weaknesses CWE-284
CWE-862

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-352
CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Data Modification and Read in Oracle Property Manager via HTTP
Weaknesses CWE-284
CWE-862

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Property Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Property Manager accessible data as well as unauthorized read access to a subset of Oracle Property Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle property Manager
CPEs cpe:2.3:a:oracle:property_manager:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle property Manager
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Property Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:17:42.955Z

Reserved: 2026-07-08T15:51:55.601Z

Link: CVE-2026-60911

cve-icon Vulnrichment

Updated: 2026-07-24T17:17:35.355Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:45:05Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')