Description
Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability enables a low privileged attacker with network access via HTTP to create, delete or modify critical data in Oracle Project Portfolio Analysis, potentially compromising data integrity and causing a partial denial of service, as described by its CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).

Affected Systems

The affected product is Oracle Project Portfolio Analysis from Oracle Corporation, versions 12.2.3 through 12.2.15. No further subcomponents are listed as impacted.

Risk and Exploitability

The vulnerability has a CVSS 3.1 base score of 7.1, indicating moderate to high risk. The EPSS score of less than 1% indicates a low likelihood of exploitation, and it is not listed in the CISA KEV catalog. The attack vector is likely over the network via HTTP and requires only low privileges, making it relatively easy to target within a compromised network.

Generated by OpenCVE AI on August 4, 2026 at 02:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the CPU Jul 2026 update for Project Portfolio Analysis
  • Restrict HTTP access to the application to trusted internal networks or VPN connections to reduce exposure
  • Enforce least-privileged access controls on the application accounts to limit unauthorized data manipulation

Generated by OpenCVE AI on August 4, 2026 at 02:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via Low-Privilege HTTP Access in Oracle Project Portfolio Analysis

Sun, 02 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via Low-Privilege HTTP in Oracle Project Portfolio Analysis

Sat, 01 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via Low-Privilege HTTP in Oracle Project Portfolio Analysis

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Exploitable Unauthorized Data Modification and Partial Denial in Oracle Project Portfolio Analysis

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Exploitable Unauthorized Data Modification and Partial Denial in Oracle Project Portfolio Analysis
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).
First Time appeared Oracle
Oracle project Portfolio Analysis
CPEs cpe:2.3:a:oracle:project_portfolio_analysis:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle project Portfolio Analysis
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Oracle Project Portfolio Analysis
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:16:49.125Z

Reserved: 2026-07-08T15:51:55.606Z

Link: CVE-2026-60985

cve-icon Vulnrichment

Updated: 2026-07-24T15:16:44.452Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:31.547

Modified: 2026-07-31T19:20:48.740

Link: CVE-2026-60985

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses