Description
Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Project Contracts accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A confidentiality flaw in Oracle Project Contracts, identified as CWE‑200, allows an attacker with low privileges and network access over HTTP to read a limited set of contract data that should otherwise be protected. While exploitation is difficult, a successful attack yields only a partial leak of sensitive information.

Affected Systems

Oracle Corporation’s Oracle Project Contracts component of Oracle E‑Business Suite is impacted, with vulnerable versions ranging from 12.2.3 through 12.2.15.

Risk and Exploitability

The vulnerability carries a CVSS base score of 3.1 and an EPSS score less than 1 %, indicating a very low likelihood of exploitation. It is not listed in the CISA KEV catalog. Attacks would need network reachability to the application via HTTP and an existing low‑privilege account, making it a low‑severity issue in most environments.

Generated by OpenCVE AI on August 4, 2026 at 02:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Project Contracts patch available through the Oracle CPU for E‑Business Suite.
  • Configure firewall or routing rules to restrict HTTP access to the application to trusted source IP ranges only.
  • Enforce role‑based access controls and ensure that only users with explicit contract‑view permissions can retrieve contractual data.

Generated by OpenCVE AI on August 4, 2026 at 02:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Unrestricted Read Access in Oracle Project Contracts

Sat, 01 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unrestricted Read Access in Oracle Project Contracts

Mon, 27 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Disclosure in Oracle Project Contracts via Low‑Privilege HTTP Access
Weaknesses CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Disclosure in Oracle Project Contracts via Low‑Privilege HTTP Access
Weaknesses CWE-200
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Project Contracts accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle project Contracts
CPEs cpe:2.3:a:oracle:project_contracts:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle project Contracts
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Project Contracts
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:44:40.419Z

Reserved: 2026-07-08T15:51:55.603Z

Link: CVE-2026-60939

cve-icon Vulnrichment

Updated: 2026-07-24T16:44:33.437Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:28.660

Modified: 2026-07-31T13:04:40.330

Link: CVE-2026-60939

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:30:02Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor