Description
Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in takeover of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Project Portfolio Analysis permits a low‑privileged attacker who can reach the application over HTTP to compromise the system, potentially taking full control of the application and exposing all data to breach. The CVSS vector (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates that the weakness is a remote access control issue, a conclusion inferred from the requirement of network access, high attack complexity, and low privileges. The result is a severe loss of confidentiality, integrity, and availability for affected users.

Affected Systems

Oracle Project Portfolio Analysis, part of Oracle E‑Business Suite, is vulnerable in supported releases 12.2.3 through 12.2.15. Users of these versions should apply the July 2026 critical security patch or otherwise ensure the service is updated to a fixed version.

Risk and Exploitability

The CVSS v3.1 base score of 7.5 marks this vulnerability as high severity, while the EPSS score of less than 1 % suggests current exploitation is unlikely. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the weakness remotely over HTTP with no need for elevated privileges, making the vulnerability accessible to any network‑connected threat actor possessing a low‑privileged user account.

Generated by OpenCVE AI on August 5, 2026 at 01:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the July 2026 Critical Patch Update for Oracle Project Portfolio Analysis.
  • Restrict HTTP access to the Project Portfolio Analysis service so that only trusted hosts or internal network segments can reach it, ensuring the application enforces proper authorization controls (CWE‑284).
  • Enforce least‑privilege for all user accounts interacting with the application and verify that the application validates permissions before granting access (CWE‑284).

Generated by OpenCVE AI on August 5, 2026 at 01:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enabling Remote Takeover of Oracle Project Portfolio Analysis
Weaknesses CWE-284

Tue, 04 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote Takeover via HTTP in Oracle Project Portfolio Analysis
Weaknesses CWE-284
CWE-285

Sat, 01 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote Takeover via HTTP in Oracle Project Portfolio Analysis
Weaknesses CWE-284
CWE-285

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Low‑privilege Remote Exploit Enables Full Compromise of Oracle Project Portfolio Analysis
Weaknesses CWE-284
CWE-285

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Low‑privilege Remote Exploit Enables Full Compromise of Oracle Project Portfolio Analysis
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in takeover of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle project Portfolio Analysis
CPEs cpe:2.3:a:oracle:project_portfolio_analysis:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle project Portfolio Analysis
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Project Portfolio Analysis
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:13:56.558Z

Reserved: 2026-07-08T15:51:55.606Z

Link: CVE-2026-60988

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:00:12Z

Weaknesses