Impact
The vulnerability in Oracle Contracts Integration allows an unauthenticated network attacker to gain unauthorized update, insert or delete capabilities and read access to a subset of data when contacting the application over HTTP. Interacting with the system requires a person other than the attacker, which increases the risk of social engineering. The flaw is a classic example of improper access control, leading to confidentiality and integrity loss for the exposed data.
Affected Systems
Oracle Contracts Integration for Oracle E‑Business Suite, version range 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS 3.1 score of 6.1 indicates moderate severity, but the EPSS score of less than 1% points to a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is HTTP network traffic, which may be limited by network segmentation or firewall rules. Successful exploitation would elevate an attacker’s privileges within Contracts Integration and could potentially affect related products due to the scope change noted in the advisory.
OpenCVE Enrichment