Impact
Oracle Contracts Integration, part of Oracle E‑Business Suite, contains an access‑control weakness that permits an unauthenticated attacker with HTTP network access to modify, insert, or delete data, read a subset of data, and trigger a partial denial of service. The flaw, classified as CWE‑284 and CWE‑640, undermines the confidentiality, integrity, and availability of the application’s data.
Affected Systems
All releases of Oracle Contracts Integration from version 12.2.3 through 12.2.15 are vulnerable. The product is delivered by Oracle Corporation as part of the Internal Operations component of Oracle E‑Business Suite.
Risk and Exploitability
The CVSS 3.1 base score of 5.0 indicates a medium level of risk. The attack vector is network (HTTP) and requires no authentication, but an additional human interaction from a third party is necessary, reducing the likelihood of exploitation. The EPSS score of less than 1% signals a very low current exploitation probability, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Consequently, the overall threat remains moderate, with a realistic chance of exploitation only under specific circumstances.
OpenCVE Enrichment