Impact
A flaw in Oracle Project Portfolio Analysis permits a low‑privileged attacker who can reach the application over HTTP to compromise the system, potentially taking full control of the application and exposing all data to breach. The CVSS vector (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates that the weakness is a remote access control issue, a conclusion inferred from the requirement of network access, high attack complexity, and low privileges. The result is a severe loss of confidentiality, integrity, and availability for affected users.
Affected Systems
Oracle Project Portfolio Analysis, part of Oracle E‑Business Suite, is vulnerable in supported releases 12.2.3 through 12.2.15. Users of these versions should apply the July 2026 critical security patch or otherwise ensure the service is updated to a fixed version.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 marks this vulnerability as high severity, while the EPSS score of less than 1 % suggests current exploitation is unlikely. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the weakness remotely over HTTP with no need for elevated privileges, making the vulnerability accessible to any network‑connected threat actor possessing a low‑privileged user account.
OpenCVE Enrichment