Description
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Contracts Integration accessible data as well as unauthorized access to critical data or complete access to all Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Contracts Integration in Oracle E‑Business Suite contains an access‑control flaw (CWE‑284: Improper Access Control) in its Internal Operations component that lets an attacker with limited privileges and network access over HTTP create, delete, or modify critical data, or read all data exposed by the product. The vulnerability directly jeopardises confidentiality and integrity, as the CVSS 3.1 score of 8.1 reflects.

Affected Systems

The flaw affects Oracle Contracts Integration versions 12.2.3 through 12.2.15. No other products or vendors are listed in the provided data.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating that widespread exploitation has not yet been observed. However, the high CVSS base score and the simple network‑based attack vector mean that a low‑privileged attacker within the same network could compromise the product. The overall risk is therefore moderate to high for environments that expose Contracts Integration to external or internal network traffic or have weak internal access controls.

Generated by OpenCVE AI on August 4, 2026 at 16:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 patch to remediate the access‑control flaw in Contracts Integration.
  • Configure firewall rules or network segmentation to restrict HTTP access to the Contracts Integration service.
  • Enforce least privilege by reviewing and tightening user permissions for the Internal Operations component and related ACLs.

Generated by OpenCVE AI on August 4, 2026 at 16:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Contracts Integration Enables Unauthorized Data Modification

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Contracts Integration Enables Unauthorized Data Modification

Thu, 30 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Access Control Flaw in Oracle Contracts Integration Allows Unauthorized Data Modification

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Access Control Flaw in Oracle Contracts Integration Allows Unauthorized Data Modification
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Contracts Integration accessible data as well as unauthorized access to critical data or complete access to all Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle contracts Integration
CPEs cpe:2.3:a:oracle:contracts_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle contracts Integration
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Contracts Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T18:18:14.083Z

Reserved: 2026-07-08T15:51:55.596Z

Link: CVE-2026-60857

cve-icon Vulnrichment

Updated: 2026-07-24T18:15:22.571Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:45:04Z

Weaknesses