Oracle Property Manager: data exposure via Internal Operations
Low1.9CVE-2026-60913 · Published Jul 21, 2026 · updated Aug 11, 2026
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Property Manager executes to compromise Oracle Property Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Property Manager accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Oracle Property Manager Product | >= 12.2.3, <= 12.2.15 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-200
More Oracle advisories
All Oracle| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 21 | Oracle HRMS (US): takeover via Internal Operations | High7.8 | No fix yet |
| Jul 21 | Oracle HRMS (US): data exposure via Internal Operations | Medium6.5 | No fix yet |
| Jul 21 | Oracle Work in Process: data tampering via Internal Operations | Medium5.4 | No fix yet |
| Jul 21 | Oracle HRMS (US): data tampering via US Payroll Year End | High7.1 | No fix yet |
| Jul 21 | Oracle HRMS (UK): data exposure via UK Payroll | High7.7 | No fix yet |
| Jul 21 | Oracle Java SE: takeover via Install | High7.8 | No fix yet |