Description
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Contracts Integration accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Contracts Integration. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a cross‑site request forgery (CWE-352) that allows an unauthenticated attacker who can send HTTP traffic to Oracle Contracts Integration to perform state‑changing actions without the user’s consent. Exploitation can lead to unauthorized creation, deletion or modification of critical data and can also cause a partial denial of service. The CVSS score of 7.1 reflects a high impact on integrity and a moderate impact on availability, while the attack vector is over the network (HTTP).

Affected Systems

The affected product is Oracle Contracts Integration, part of Oracle E‑Business Suite, running in the Internal Operations component. Versions 12.2.3 through 12.2.15 are vulnerable.

Risk and Exploitability

The risk is moderate‑high, with a CVSS of 7.1, but the EPSS score of less than 1% indicates that the likely exploitation rate is ISA it has not yet been widely abused. Successful exploitation requires an unauthenticated attacker with network access to the Oracle Contracts Integration endpoint via HTTP and a separate human user who interacts with the system in a way that triggers thus network‑based and relies user to complete the transaction.

Generated by OpenCVE AI on August 4, 2026 at 00:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Contracts Integration as detailed in the Oracle security advisory for versions 12.2.3–12.2.15
  • Validate and enforce CSRF tokens on all state‑changing requests in Contracts Integration to prevent unauthorized requests
  • Limit HTTP access to the Contracts Integration interface to trusted logging of all modification actions

Generated by OpenCVE AI on August 4, 2026 at 00:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery Enables Unauthorized Data Modification in Oracle Contracts Integration

Thu, 30 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery Enables Unauthorized Data Modification in Oracle Contracts Integration

Tue, 28 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery Enables Unauthorized Data Modification in Oracle Contracts Integration

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery Enables Unauthorized Data Modification in Oracle Contracts Integration

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Contracts Integration accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Contracts Integration. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L).
First Time appeared Oracle
Oracle contracts Integration
CPEs cpe:2.3:a:oracle:contracts_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle contracts Integration
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L'}


Subscriptions

Oracle Contracts Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T17:39:59.652Z

Reserved: 2026-07-14T14:54:48.731Z

Link: CVE-2026-62443

cve-icon Vulnrichment

Updated: 2026-07-22T17:39:54.335Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:00:05Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)