Description
Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data as well as unauthorized read access to a subset of Oracle Project Portfolio Analysis accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper access control flaw (CWE‑284) that allows a low‑privileged attacker with network access to the HTTP interface of Oracle Project Portfolio Analysis to create, delete, or alter critical data, and to read protected data. Based on the description, it is inferred that the attacker likely needs a low‑privileged user account, but the requirement for authentication is not explicitly stated. The impact is a compromise of confidentiality and integrity of project information.

Affected Systems

Oracle Corporation's Oracle Project Portfolio Analysis, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15.

Risk and Exploitability

The CVSS base score of 7.1 indicates substantial impact. The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low current exploitation prevalence. Attackers need only network access to the HTTP service and a low‑privilege user account; it is inferred that no elevated rights are required, but the description does not explicitly state whether additional authentication is needed. Successful exploitation can lead to unauthorized modification or deletion of project data and unauthorized read access to sensitive data.

Generated by OpenCVE AI on August 4, 2026 at 16:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle's security patch for CVE‑2026‑60987, upgrading to a version newer than 12.2.15.
  • Restrict HTTP exposure of the Project Portfolio Analysis service to trusted networks or VPN‑only access, blocking unnecessary inbound traffic.
  • Enable comprehensive audit logging for data create, modify, and delete events, and monitor the logs for anomalous activity.

Generated by OpenCVE AI on August 4, 2026 at 16:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Exploit Allows Unauthorized Data Modification in Oracle Project Portfolio Analysis

Sat, 01 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Exploit Allows Unauthorized Data Modification in Oracle Project Portfolio Analysis

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Oracle Project Portfolio Analysis Authorization Bypass via HTTP

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Oracle Project Portfolio Analysis Authorization Bypass via HTTP
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data as well as unauthorized read access to a subset of Oracle Project Portfolio Analysis accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).
First Time appeared Oracle
Oracle project Portfolio Analysis
CPEs cpe:2.3:a:oracle:project_portfolio_analysis:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle project Portfolio Analysis
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

Oracle Project Portfolio Analysis
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:14:42.847Z

Reserved: 2026-07-08T15:51:55.606Z

Link: CVE-2026-60987

cve-icon Vulnrichment

Updated: 2026-07-24T15:14:35.398Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:45:04Z

Weaknesses