Impact
A flaw in Oracle Project Contracts enables an attacker who has low‑privileged credentials and can reach the application over HTTP to modify contractual data. By exploiting an improper access‑control check (CWE‑284), the attacker can update, insert, or delete records beyond their authorized scope, thereby undermining the integrity of Oracle Project Contracts data.
Affected Systems
Oracle Project Contracts, a component of Oracle E‑Business Suite’s Internal Operations, versions 12.2.3 through 12.2.15 are affected.
Risk and Exploitability
The CVSS 3.1 base score of 4.3 indicates a low threat focused on integrity. The EPSS score of less than 1 % reflects a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker with low‑privileged access and network connectivity via HTTP can trigger the flaw by sending a crafted request, leveraging the missing access‑control enforcement.
OpenCVE Enrichment