Impact
This vulnerability permits a low‑privileged attacker who can reach Oracle Property Manager over HTTP to perform unauthorized inserts, updates, and deletions, and to read sensitive data that the user should not have access to. The flaw arising from improper access control (CWE‑284), enabling data integrity and confidentiality breaches without requiring elevated privileges.
Affected Systems
Oracle Property Manager, part of the Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. Any environment running these releases that has not yet applied the latest CPU July 2026 patch is potentially vulnerable. The issue resides in the Internal Operations component and can be triggered from outside the organization via exposed HTTP interfaces.
Risk and Exploitability
The CVSS 3.1 base score of 5.4 indicates moderate risk, with low attack complexity and low privileges required. The EPSS score of less than 1 % suggests that active exploitation is currently low, and the vulnerability is not listed in CISA’s KEV catalog, but the attack surface remains present. It can be exploited over the network by any user who can reach the HTTP endpoint, and the flaw does not require authentication, making it accessible to remote threat actors.
OpenCVE Enrichment