Impact
Oracle Contracts Integration in Oracle E‑Business Suite contains an access‑control flaw (CWE‑284: Improper Access Control) in its Internal Operations component that lets an attacker with limited privileges and network access over HTTP create, delete, or modify critical data, or read all data exposed by the product. The vulnerability directly jeopardises confidentiality and integrity, as the CVSS 3.1 score of 8.1 reflects.
Affected Systems
The flaw affects Oracle Contracts Integration versions 12.2.3 through 12.2.15. No other products or vendors are listed in the provided data.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating that widespread exploitation has not yet been observed. However, the high CVSS base score and the simple network‑based attack vector mean that a low‑privileged attacker within the same network could compromise the product. The overall risk is therefore moderate to high for environments that expose Contracts Integration to external or internal network traffic or have weak internal access controls.
OpenCVE Enrichment