Description
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Contracts Integration accessible data as well as unauthorized read access to a subset of Oracle Contracts Integration accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Contracts Integration. CVSS 3.1 Base Score 5.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Contracts Integration, part of Oracle E‑Business Suite, contains an access‑control weakness that permits an unauthenticated attacker with HTTP network access to modify, insert, or delete data, read a subset of data, and trigger a partial denial of service. The flaw, classified as CWE‑284 and CWE‑640, undermines the confidentiality, integrity, and availability of the application’s data.

Affected Systems

All releases of Oracle Contracts Integration from version 12.2.3 through 12.2.15 are vulnerable. The product is delivered by Oracle Corporation as part of the Internal Operations component of Oracle E‑Business Suite.

Risk and Exploitability

The CVSS 3.1 base score of 5.0 indicates a medium level of risk. The attack vector is network (HTTP) and requires no authentication, but an additional human interaction from a third party is necessary, reducing the likelihood of exploitation. The EPSS score of less than 1% signals a very low current exploitation probability, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Consequently, the overall threat remains moderate, with a realistic chance of exploitation only under specific circumstances.

Generated by OpenCVE AI on August 4, 2026 at 00:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle security patch for CVE‑2026‑62486 to all affected releases (12.2.3‑12.2.15) to address the access‑control and object‑level authorization weaknesses.
  • Configure Oracle Contracts Integration to enforce strict role‑based access control, limiting update, insert, delete, and read operations to authorized personnel only.
  • Restrict exposure of the Contracts Integration service by applying firewall rules or VPN segmentation so that only trusted internal hosts can reach the HTTP endpoint.

Generated by OpenCVE AI on August 4, 2026 at 00:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification and Partial DoS in Oracle Contracts Integration

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Modification and Partial Denial of Service in Oracle Contracts Integration

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Data Modification and Partial Denial of Service in Oracle Contracts Integration

Wed, 22 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-640
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Contracts Integration accessible data as well as unauthorized read access to a subset of Oracle Contracts Integration accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Contracts Integration. CVSS 3.1 Base Score 5.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle contracts Integration
CPEs cpe:2.3:a:oracle:contracts_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle contracts Integration
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Contracts Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T16:05:18.192Z

Reserved: 2026-07-14T14:54:48.735Z

Link: CVE-2026-62486

cve-icon Vulnrichment

Updated: 2026-07-22T16:05:13.951Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:45:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password