Impact
The vulnerability resides in Oracle Project Contracts, a component of Oracle E‑Business Suite, and allows an attacker who has network access to the HTTP interface and only low privileges to create, delete, or modify critical contract data. Based on the description, it is inferred that the flaw may stem from improper access control (CWE-284), enabling users to perform operations that should be limited to higher‑privileged accounts. This results in confidentiality and integrity compromise, as attackers can view, alter, or delete contractual records, potentially leading to financial loss or operational disruption.
Affected Systems
Customers running Oracle Project Contracts versions 12.2.3 through 12.2.15 are affected. These are the only versions identified in Oracle’s advisory, and no other releases were noted as impacted.
Risk and Exploitability
With a CVSS 3.1 base score of 8.1, the vulnerability is considered high severity, especially given its impact on confidentiality and integrity. The EPSS score of less than 1% indicates a low probability of exploitation at the time of the analysis, and the issue is not listed in CISA’s KEV catalog. It is inferred that attackers could exploit the flaw by sending crafted HTTP requests that bypass low‑level authorization checks, after which they could perform unauthorized operations on the contract data without needing administrative credentials.
OpenCVE Enrichment