Impact
This vulnerability is a cross‑site request forgery (CWE-352) that allows an unauthenticated attacker who can send HTTP traffic to Oracle Contracts Integration to perform state‑changing actions without the user’s consent. Exploitation can lead to unauthorized creation, deletion or modification of critical data and can also cause a partial denial of service. The CVSS score of 7.1 reflects a high impact on integrity and a moderate impact on availability, while the attack vector is over the network (HTTP).
Affected Systems
The affected product is Oracle Contracts Integration, part of Oracle E‑Business Suite, running in the Internal Operations component. Versions 12.2.3 through 12.2.15 are vulnerable.
Risk and Exploitability
The risk is moderate‑high, with a CVSS of 7.1, but the EPSS score of less than 1% indicates that the likely exploitation rate is ISA it has not yet been widely abused. Successful exploitation requires an unauthenticated attacker with network access to the Oracle Contracts Integration endpoint via HTTP and a separate human user who interacts with the system in a way that triggers thus network‑based and relies user to complete the transaction.
OpenCVE Enrichment