Description
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Contracts Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Contracts Integration accessible data as well as unauthorized read access to a subset of Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Internal Operations component of Oracle Contracts Integration allows an unauthenticated attacker to reach the application over HTTP and gain unauthorized rights to update, delete, or read contract data, causing both confidentiality and integrity impacts.

Affected Systems

Oracle Contracts Integration, part of the Oracle E‑Business Suite, with affected releases 12.2.3 through 12.2.15, is vulnerable. Only this product is listed in the CVE record; other Oracle products are not directly impacted but could be affected through scope changes.

Risk and Exploitability

The CVSS 3.1 base score of 6.1 points to a moderate severity while the EPSS score of less than 1% indicates a very low chance of exploitation in the near term. The vulnerability is not catalogued in CISA KEV. Attackers need no credentials but must be able to send HTTP requests to the service, and an additional user must interact with the system to complete the exploit chain. The scope alteration allows the attacker to potentially affect other components of the suite beyond Contracts Integration.

Generated by OpenCVE AI on August 4, 2026 at 00:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Contracts Integration that addresses this vulnerability
  • Block or restrict inbound HTTP traffic to the Contracts Integration service, limiting access to trusted networks, VPNs, or firewalls
  • Enforce strict access‑control checks to prevent unauthorized updates or reads, ensuring only authenticated and authorized users can perform these operations

Generated by OpenCVE AI on August 4, 2026 at 00:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Provides Read/Write Control Over Oracle Contracts Integration Data

Thu, 30 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Provides Read/Write Control Over Oracle Contracts Integration Data

Mon, 27 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification in Oracle Contracts Integration

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Modification in Oracle Contracts Integration

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Contracts Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Contracts Integration accessible data as well as unauthorized read access to a subset of Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle contracts Integration
CPEs cpe:2.3:a:oracle:contracts_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle contracts Integration
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Contracts Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T17:43:10.245Z

Reserved: 2026-07-14T14:54:48.731Z

Link: CVE-2026-62444

cve-icon Vulnrichment

Updated: 2026-07-22T17:43:06.143Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:00:05Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')