CVE-2026-46956: Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful attacks of this vulnerability can result in takeover of Oracle Property Manager. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 7.2
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An unspecified vulnerability in the Internal Operations component of Oracle Property Manager (part of Oracle E-Business Suite, versions 12.2.3 through 12.2.15) allows a remote, authenticated attacker with administrative privileges to compromise the application over HTTP. No victim interaction is required, and exploitation is straightforward once the attacker holds a high-privileged account. Successful exploitation gives the attacker full control over Oracle Property Manager, affecting confidentiality, integrity, and availability. HarborGuard is tracking this advisory and will make a patched-image rebuild available the moment Oracle publishes a fix.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Oracle E-Business Suite components. Any image carrying an affected version of Oracle Property Manager (12.2.3 through 12.2.15) is flagged automatically.
AvailableHarborGuard scores this finding at CVSS 7.2 (High) using the published v3.1 vector and weights it further against each environment's compliance policy to determine routing priority. Findings are dispatched to the appropriate team inbox within each customer organization based on asset ownership rules configured in the platform.
AvailableBecause Oracle has not yet published a fix version, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment upstream releases one. For customers with auto-remediation enabled, the rebuild, regression run, and PR against affected workloads will be initiated without manual intervention once a fix is available.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the Oracle Property Manager service over a network connection via HTTP; there is no purely local exploitation path.
- AuthenticationRequired
A high-privileged (administrative) account is required; the attacker cannot exploit this without first obtaining or compromising such credentials.
- Victim interactionNot required
No action from any other user or victim is needed to trigger the vulnerability.
- Attack complexityDetail
Attack complexity is Low, meaning the exploit is reliable and does not depend on race conditions, specific memory layout, or other hard-to-control environmental factors.
Blast Radius
- A successful attacker reads all data accessible to Oracle Property Manager, including lease records, property details, and any stored credentials or session tokens.
- The attacker can modify or delete persisted property management records, financial data, and configuration within the application.
- The attacker can crash or render the Oracle Property Manager service unavailable, disrupting business operations that depend on it.
- Combined confidentiality, integrity, and availability impact effectively constitutes a full application takeover.
How HarborGuard Handles This
Available on HarborGuard: because no fix version has been published by Oracle, the platform monitors this advisory on every ingest cycle and will trigger a patched-image rebuild automatically the moment an upstream fix is released. In the interim, customers should consider compensating controls such as network-policy isolation that restricts HTTP access to Oracle Property Manager to trusted, internal IP ranges only; egress filtering to limit outbound connections from the affected service; and tightening administrative account provisioning to reduce the pool of credentials that could be leveraged for exploitation. Where auto-remediation is enabled, the rebuild, regression test run, and PR against affected workloads will be initiated without manual steps as soon as Oracle ships a patch.
- Oracle Corporation / Oracle Property Manager≤ 12.2.15
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H