Description
Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Project Contracts accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).
Published: 2026-07-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Project Contracts enables an attacker who has low‑privileged credentials and can reach the application over HTTP to modify contractual data. By exploiting an improper access‑control check (CWE‑284), the attacker can update, insert, or delete records beyond their authorized scope, thereby undermining the integrity of Oracle Project Contracts data.

Affected Systems

Oracle Project Contracts, a component of Oracle E‑Business Suite’s Internal Operations, versions 12.2.3 through 12.2.15 are affected.

Risk and Exploitability

The CVSS 3.1 base score of 4.3 indicates a low threat focused on integrity. The EPSS score of less than 1 % reflects a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker with low‑privileged access and network connectivity via HTTP can trigger the flaw by sending a crafted request, leveraging the missing access‑control enforcement.

Generated by OpenCVE AI on August 5, 2026 at 01:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued update that resolves the access‑control flaw in Oracle Project Contracts.
  • Restrict HTTP access to the Oracle Project Contracts component to trusted IP ranges or networks.
  • Enforce least privilege by disabling or limiting low‑privileged user accounts from accessing the affected endpoints.

Generated by OpenCVE AI on August 5, 2026 at 01:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Project Contracts via Missing Access Control

Sun, 02 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Project Contracts via Missing Access Control

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Access Control Vulnerability Enables Unauthorized Data Modification in Oracle Project Contracts

Mon, 27 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Access Control Vulnerability Enables Unauthorized Data Modification in Oracle Project Contracts

Wed, 22 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Project Contracts accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).
First Time appeared Oracle
Oracle project Contracts
CPEs cpe:2.3:a:oracle:project_contracts:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle project Contracts
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Oracle Project Contracts
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T16:02:40.157Z

Reserved: 2026-07-14T14:54:48.735Z

Link: CVE-2026-62483

cve-icon Vulnrichment

Updated: 2026-07-22T16:01:07.691Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:15:03Z

Weaknesses