PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60984 Oracle CVE debrief

CVE-2026-60984 is a vulnerability in Oracle Project Portfolio Analysis, a component of Oracle E-Business Suite. The vulnerability has a CVSS score of 7.1 and can be exploited by low-privileged attackers with network access via HTTP, potentially leading to unauthorized data modifications or access. Organizations should review their deployments and apply patches from Oracle. The CVE record was published on 2026-07-21T22:18:31.440Z and has not been modified since then. Affected versions are 12.2.3-12.2.15.

Vendor
Oracle
Product
Project Portfolio Analysis
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-31
Advisory published
2026-07-21
Advisory updated
2026-07-31

Who should care

Organizations using Oracle Project Portfolio Analysis versions 12.2.3-12.2.15 should prioritize patching to prevent potential data breaches. This includes reviewing current deployments, restricting network access to trusted users only, and monitoring for unauthorized data modifications or access attempts. Security teams should verify if patches have been applied and ensure that compensating controls are in place for exposed systems while remediation is scheduled and verified. Vulnerability management processes should be updated to include checks for this CVE. Asset inventory should be reviewed to identify potentially affected systems. Change management windows should be planned for patch deployment. Source tracking should be implemented to monitor for potential exploitation attempts. Monitoring and detection capabilities should be reviewed to ensure they can identify potential exploitation attempts. Rollback plans should be in place in case patching is not immediately feasible. These actions should be coordinated with IT operations and security teams to ensure timely and effective mitigation of the vulnerability. Patching should be prioritized based on the CVSS score of 7.1, indicating high severity. The vulnerability affects low-privileged attackers with network access via HTTP, which may require additional compensating controls. The vulnerability allows unauthorized data modifications or access, which may require additional monitoring and detection capabilities. The CVE record was published on 2026-07-21T22:18:31.440Z and has not been modified since then. Affected versions are 12.2.3-12.2.15. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N). CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). The vulnerability is easily exploitable. The CVE-2026-60984 vulnerability affects Oracle Project Portfolio Analysis versions 12.2.3-12.2.15, with a CVSS score of 7.1, indicating high severity. Exploitation allows low-privileged attackers with network access via HTTP to compromise data integrity and confidentiality. The vulnerability has not been modified since its publication on 2026-07-21T22:18:31.440Z. The CVE record provides details on the CVSS

Technical summary

CVE-2026-60984 is a vulnerability in Oracle Project Portfolio Analysis, a component of Oracle E-Business Suite. The vulnerability has a CVSS score of 7.1 and can be exploited by low-privileged attackers with network access via HTTP, potentially leading to unauthorized data modifications or access. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data as well as unauthorized read access to a subset of Oracle Project Portfolio Analysis accessible data.

Defensive priority

Oracle Project Portfolio Analysis vulnerability allows low-privileged attackers to compromise data integrity and confidentiality; prioritize patching for affected versions 12.2.3-12.2.15.

Recommended defensive actions

  • Verify if Oracle Project Portfolio Analysis versions 12.2.3-12.2.15 are in use and apply patches from Oracle.
  • Restrict network access to Oracle Project Portfolio Analysis to trusted users only.
  • Monitor Oracle Project Portfolio Analysis for unauthorized data modifications or access attempts.
  • Review current deployments and assign an owner for follow-up.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE-2026-60984 vulnerability affects Oracle Project Portfolio Analysis versions 12.2.3-12.2.15, with a CVSS score of 7.1, indicating high severity. Exploitation allows low-privileged attackers with network access via HTTP to compromise data integrity and confidentiality.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:31.440Z and has not been modified since then.