Impact
The vulnerability, identified as CWE-284 (Authorization Bypass), permits a low‑privileged attacker who can reach the Oracle Contracts Integration service over HTTP to bypass authorization controls in the Internal Operations component, allowing creation, deletion, or modification of critical data. This results in a high impact on confidentiality and integrity, reflected in the CVSS 3.1 score of 8.1.
Affected Systems
Oracle Contracts Integration, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected. The flaw resides in the Internal Operations module and is accessible via the product’s HTTP interface.
Risk and Exploitability
Exploitation requires only the ability to send crafted HTTP requests; the low attack complexity and network‑scope vector make the vulnerability easy to exploit. The high CVSS score indicates significant risk, while the EPSS score of less than 1 % suggests limited current exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment