Description
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Contracts Integration accessible data as well as unauthorized access to critical data or complete access to all Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability, identified as CWE-284 (Authorization Bypass), permits a low‑privileged attacker who can reach the Oracle Contracts Integration service over HTTP to bypass authorization controls in the Internal Operations component, allowing creation, deletion, or modification of critical data. This results in a high impact on confidentiality and integrity, reflected in the CVSS 3.1 score of 8.1.

Affected Systems

Oracle Contracts Integration, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected. The flaw resides in the Internal Operations module and is accessible via the product’s HTTP interface.

Risk and Exploitability

Exploitation requires only the ability to send crafted HTTP requests; the low attack complexity and network‑scope vector make the vulnerability easy to exploit. The high CVSS score indicates significant risk, while the EPSS score of less than 1 % suggests limited current exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on August 4, 2026 at 00:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle July 2026 CPU patch for Oracle Contracts Integration
  • Restrict HTTP access to the Contracts Integration service to trusted internal IP ranges
  • Disable unused API endpoints and enforce strict authentication on remaining endpoints
  • Regularly review audit logs for anomalous data modification activity

Generated by OpenCVE AI on August 4, 2026 at 00:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Oracle Contracts Integration Enabling Unauthorized Data Modification

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Oracle Contracts Integration Enabling Unauthorized Data Modification

Tue, 28 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Remote API Access Bypass Allowing Unauthorized Data Modification in Oracle Contracts Integration

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Remote API Access Bypass Allowing Unauthorized Data Modification in Oracle Contracts Integration

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Contracts Integration accessible data as well as unauthorized access to critical data or complete access to all Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle contracts Integration
CPEs cpe:2.3:a:oracle:contracts_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle contracts Integration
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Contracts Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T17:39:09.138Z

Reserved: 2026-07-08T15:52:20.748Z

Link: CVE-2026-61338

cve-icon Vulnrichment

Updated: 2026-07-22T17:39:03.522Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:00:05Z

Weaknesses