Description
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper access control flaw in the Internal Operations component of Oracle Contracts Integration. An attacker who can authenticate with a low‑privilege account and has network reachability via HTTP can create, delete or modify critical data within the application. The flaw directly jeopardizes data integrity and can result in unauthorized changes to contracts and related records.

Affected Systems

the issue affects Oracle Corporation’s Contracts Integration product, part of the Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are vulnerable. These deployments are common in enterprise environments where the web interface is exposed to internal or external networks.

Risk and Exploitability

The CVSS 3.1 Base score of 6.5 indicates a moderate risk to integrity. The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of current exploitation. The attack vector is network over HTTP, requiring only that the attacker has a low‑privilege account and network access to the Contracts Integration subsystem. Proper restriction of HTTP exposure and enforcement of strict role-based access control are key to mitigating the threat.

Generated by OpenCVE AI on August 4, 2026 at 00:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Enforce strict role‑based access controls to eliminate improper privilege grants (CWE‑284) for the Internal Operations component.
  • Restrict HTTP access to the Contracts Integration subsystem to trusted hosts, VPN endpoints, or internal networks only.
  • Monitor authentication and activity logs for anomalous operations that might indicate exploitation of access‑control weaknesses.

Generated by OpenCVE AI on August 4, 2026 at 00:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control Allowing Low‑Privilege Data Modification in Oracle Contracts Integration

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control Allowing Low‑Privilege Data Modification in Oracle Contracts Integration

Tue, 28 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Low Privileged Network Attack Enabling Unauthorized Data Modification in Oracle Contracts Integration

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low Privileged Network Attack Enabling Unauthorized Data Modification in Oracle Contracts Integration

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).
First Time appeared Oracle
Oracle contracts Integration
CPEs cpe:2.3:a:oracle:contracts_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle contracts Integration
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Oracle Contracts Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:47:15.720Z

Reserved: 2026-07-14T14:54:48.735Z

Link: CVE-2026-62488

cve-icon Vulnrichment

Updated: 2026-07-22T15:47:11.006Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:45:03Z

Weaknesses