Description
Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data as well as unauthorized read access to a subset of Oracle Project Portfolio Analysis accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Internal Operations component of Oracle Project Portfolio Analysis permits an attacker with low privileges who can reach the system via HTTP to bypass normal access controls. The vulnerability allows the attacker to create, delete, or modify critical portfolio data and to read data that should be protected. The weakness is a missing authentication and authorization control (CWE‑284). The CVSS score of 7.1 indicates moderate-to-high impact on confidentiality and integrity.

Affected Systems

Oracle Project Portfolio Analysis from Oracle Corporation, versions 12.2.3 through 12.2.15 of the Oracle E‑Business Suite, are affected. The issue resides in the Internal Operations component used to manage portfolio information.

Risk and Exploitability

The CVSS score signals substantial risk, yet the EPSS score of less than 1 % indicates a low likelihood of active exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog, further suggesting it is not widely exploited. However, because the flaw can be triggered by a simple HTTP request from a low‑privileged user, the potential for data compromise remains significant.

Generated by OpenCVE AI on August 4, 2026 at 02:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch for Project Portfolio Analysis versions 12.2.3‑12.2.15, as published in the Oracle security advisory
  • Limit inbound HTTP access to the Project Portfolio Analysis service by configuring firewall or access‑control rules to allow only trusted hosts or IP ranges
  • Enforce strong authentication and role‑based access controls, ensuring that only privileged accounts can use the Internal Operations component and disabling any unused low‑privileged accounts

Generated by OpenCVE AI on August 4, 2026 at 02:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title HTTP‑Based Unauthorized Access and Data Modifications in Oracle Project Portfolio Analysis

Thu, 30 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title HTTP‑Based Unauthorized Access and Data Modifications in Oracle Project Portfolio Analysis

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Oracle Project Portfolio Analysis Vulnerability Allows Unauthorized Data Access and Modification via HTTP
Weaknesses CWE-20
CWE-285

Sat, 25 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Oracle Project Portfolio Analysis Vulnerability Allows Unauthorized Data Access and Modification via HTTP
Weaknesses CWE-20
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data as well as unauthorized read access to a subset of Oracle Project Portfolio Analysis accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).
First Time appeared Oracle
Oracle project Portfolio Analysis
CPEs cpe:2.3:a:oracle:project_portfolio_analysis:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle project Portfolio Analysis
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

Oracle Project Portfolio Analysis
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:17:45.072Z

Reserved: 2026-07-08T15:51:55.606Z

Link: CVE-2026-60984

cve-icon Vulnrichment

Updated: 2026-07-24T15:17:37.557Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:31.440

Modified: 2026-07-31T19:23:54.273

Link: CVE-2026-60984

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses