Impact
The vulnerability is an improper access control flaw in the Internal Operations component of Oracle Contracts Integration. An attacker who can authenticate with a low‑privilege account and has network reachability via HTTP can create, delete or modify critical data within the application. The flaw directly jeopardizes data integrity and can result in unauthorized changes to contracts and related records.
Affected Systems
the issue affects Oracle Corporation’s Contracts Integration product, part of the Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are vulnerable. These deployments are common in enterprise environments where the web interface is exposed to internal or external networks.
Risk and Exploitability
The CVSS 3.1 Base score of 6.5 indicates a moderate risk to integrity. The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of current exploitation. The attack vector is network over HTTP, requiring only that the attacker has a low‑privilege account and network access to the Contracts Integration subsystem. Proper restriction of HTTP exposure and enforcement of strict role-based access control are key to mitigating the threat.
OpenCVE Enrichment