Description
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Contracts Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Contracts Integration accessible data as well as unauthorized read access to a subset of Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Contracts Integration allows an unauthenticated network attacker to gain unauthorized update, insert or delete capabilities and read access to a subset of data when contacting the application over HTTP. Interacting with the system requires a person other than the attacker, which increases the risk of social engineering. The flaw is a classic example of improper access control, leading to confidentiality and integrity loss for the exposed data.

Affected Systems

Oracle Contracts Integration for Oracle E‑Business Suite, version range 12.2.3 through 12.2.15.

Risk and Exploitability

The CVSS 3.1 score of 6.1 indicates moderate severity, but the EPSS score of less than 1% points to a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is HTTP network traffic, which may be limited by network segmentation or firewall rules. Successful exploitation would elevate an attacker’s privileges within Contracts Integration and could potentially affect related products due to the scope change noted in the advisory.

Generated by OpenCVE AI on August 4, 2026 at 00:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the July 2026 CPU to update Contracts Integration to a version beyond 12.2.15
  • Limit HTTP access to the application to trusted internal networks and enforce strict segmentation or firewall rules
  • Implement monitoring for unusual data modification or read activity, and enforce role‑based access controls and MFA where possible

Generated by OpenCVE AI on August 4, 2026 at 00:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Cross‑site request forgery enables unauthorized update and read in Oracle Contracts Integration

Thu, 30 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Cross‑site request forgery enables unauthorized update and read in Oracle Contracts Integration

Tue, 28 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access Leading to Unauthorized Data Modification in Oracle Contracts Integration
Weaknesses CWE-284

Fri, 24 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access Leading to Unauthorized Data Modification in Oracle Contracts Integration
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Contracts Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Contracts Integration accessible data as well as unauthorized read access to a subset of Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle contracts Integration
CPEs cpe:2.3:a:oracle:contracts_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle contracts Integration
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Contracts Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:46:25.471Z

Reserved: 2026-07-14T14:54:48.735Z

Link: CVE-2026-62487

cve-icon Vulnrichment

Updated: 2026-07-22T15:46:08.188Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:45:03Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)