Description
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Contracts Integration accessible data as well as unauthorized read access to a subset of Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle's Contracts Integration service permits a low‑privileged attacker with network access over HTTP to perform unauthorized write operations and read restricted data. As a result, an attacker can update, insert, or delete data that the application exposes while also gaining read access to portions of that data. The weakness is a missing authorization check and is categorized as CWE‑284, leading to confidentiality and integrity impacts as noted in the CVSS vector.

Affected Systems

Oracle Contracts Integration, part of Oracle E‑Business Suite, is affected from version 12.2.3 through 12.2.15. The product is listed under the vendor Oracle Corporation and the specific component is Internal Operations.

Risk and Exploitability

The vulnerability has a CVSS base score of 4.2, indicating moderate impact on confidentiality and integrity. The EPSS score indicates less than a 1% likelihood of exploitation. It is not listed in the CISA KEV catalog. Successful attacks require a low‑privilege attacker with network access over HTTP to the Contracts Integration service. Based on the description, the attack vector is network access via HTTP. It is inferred that the attack could be reached from outside the enterprise network if firewall rules expose the interface. Because the vulnerability arises from a missing authorization check (CWE‑284), an adversary can perform unauthorized updates, inserts, deletes, and read restricted data.

Generated by OpenCVE AI on August 4, 2026 at 00:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 patch or upgrade to a version newer than 12.2.15 that includes the fix.
  • Restrict HTTP access to the Contracts Integration service to trusted users and tighten access controls so that low‑privileged accounts cannot perform write operations on Contracts Integration data.
  • Continuously monitor logs for unexpected write or read activities against the Contracts Integration service and respond to anomalies.

Generated by OpenCVE AI on August 4, 2026 at 00:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure in Oracle Contracts Integration

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure via Authorization Bypass in Oracle Contracts Integration

Mon, 27 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Disclosure via Authorization Bypass in Oracle Contracts Integration

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Contracts Integration accessible data as well as unauthorized read access to a subset of Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle contracts Integration
CPEs cpe:2.3:a:oracle:contracts_integration:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle contracts Integration
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Contracts Integration
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:48:00.444Z

Reserved: 2026-07-14T14:54:48.735Z

Link: CVE-2026-62489

cve-icon Vulnrichment

Updated: 2026-07-22T15:47:56.328Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:45:03Z

Weaknesses