Impact
The vulnerability in Oracle's Contracts Integration service permits a low‑privileged attacker with network access over HTTP to perform unauthorized write operations and read restricted data. As a result, an attacker can update, insert, or delete data that the application exposes while also gaining read access to portions of that data. The weakness is a missing authorization check and is categorized as CWE‑284, leading to confidentiality and integrity impacts as noted in the CVSS vector.
Affected Systems
Oracle Contracts Integration, part of Oracle E‑Business Suite, is affected from version 12.2.3 through 12.2.15. The product is listed under the vendor Oracle Corporation and the specific component is Internal Operations.
Risk and Exploitability
The vulnerability has a CVSS base score of 4.2, indicating moderate impact on confidentiality and integrity. The EPSS score indicates less than a 1% likelihood of exploitation. It is not listed in the CISA KEV catalog. Successful attacks require a low‑privilege attacker with network access over HTTP to the Contracts Integration service. Based on the description, the attack vector is network access via HTTP. It is inferred that the attack could be reached from outside the enterprise network if firewall rules expose the interface. Because the vulnerability arises from a missing authorization check (CWE‑284), an adversary can perform unauthorized updates, inserts, deletes, and read restricted data.
OpenCVE Enrichment