Impact
A flaw in the Internal Operations component of Oracle Contracts Integration allows an unauthenticated attacker to reach the application over HTTP and gain unauthorized rights to update, delete, or read contract data, causing both confidentiality and integrity impacts.
Affected Systems
Oracle Contracts Integration, part of the Oracle E‑Business Suite, with affected releases 12.2.3 through 12.2.15, is vulnerable. Only this product is listed in the CVE record; other Oracle products are not directly impacted but could be affected through scope changes.
Risk and Exploitability
The CVSS 3.1 base score of 6.1 points to a moderate severity while the EPSS score of less than 1% indicates a very low chance of exploitation in the near term. The vulnerability is not catalogued in CISA KEV. Attackers need no credentials but must be able to send HTTP requests to the service, and an additional user must interact with the system to complete the exploit chain. The scope alteration allows the attacker to potentially affect other components of the suite beyond Contracts Integration.
OpenCVE Enrichment