Impact
The vulnerability exists in Oracle Contracts Integration, part of Oracle E‑Business Suite, where the Internal Operations component accepts HTTP requests that do not require authentication. Based on the description, it is inferred that an attacker who can reach the application over HTTP can send requests that create, delete, or alter critical data, resulting in a loss of data integrity. Confidentiality and availability are not directly affected by the flaw.
Affected Systems
Oracle Contracts Integration is affected for supported releases from version 12.2.3 through 12.2.15. The flaw resides in the Internal Operations module and can be exploited by any client that can reach the servers over the default HTTP port unless additional network controls are in place. Systems not running these versions or whose Interfaces are not exposed to public networks are not affected.
Risk and Exploitability
The CVSS 3.1 base score of 5.9 classifies the flaw as moderate severity focused on integrity. The EPSS score is less than 1 percent, indicating a low likelihood of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a simple unauthenticated HTTP request over the network; no credentials are required. An attacker with network access to the Contracts Integration servers can thereby exercise the flaw.
OpenCVE Enrichment