Impact
A flaw in the Internal Operations component of Oracle Project Portfolio Analysis permits an attacker with low privileges who can reach the system via HTTP to bypass normal access controls. The vulnerability allows the attacker to create, delete, or modify critical portfolio data and to read data that should be protected. The weakness is a missing authentication and authorization control (CWE‑284). The CVSS score of 7.1 indicates moderate-to-high impact on confidentiality and integrity.
Affected Systems
Oracle Project Portfolio Analysis from Oracle Corporation, versions 12.2.3 through 12.2.15 of the Oracle E‑Business Suite, are affected. The issue resides in the Internal Operations component used to manage portfolio information.
Risk and Exploitability
The CVSS score signals substantial risk, yet the EPSS score of less than 1 % indicates a low likelihood of active exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog, further suggesting it is not widely exploited. However, because the flaw can be triggered by a simple HTTP request from a low‑privileged user, the potential for data compromise remains significant.
OpenCVE Enrichment