Impact
A defect in Oracle Contracts permits an attacker who already possesses high‑privileged network credentials to bypass established authorization checks and assume full control of the application. The issue results in complete compromise of confidentiality, integrity, and availability and is identified as an elevation of privilege (CWE‑269). Successful exploitation enables the attacker to conduct unrestricted operations within Oracle Contracts, effectively taking over the system.
Affected Systems
Oracle Corporation’s Oracle Contracts product, part of Oracle E‑Business Suite, is affected for versions 12.2.14 through 12.2.15. Clients interacting over HTTP are exposed to the vulnerability.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 indicates high severity. With an EPSS score below 1 %, widespread exploitation is currently unlikely, and the vulnerability is not catalogued in the CISA KEV directory. The attack vector assumes network access via HTTP, where an attacker sends crafted requests on behalf of a user who possesses high‑privileged credentials, to trigger the authorization bypass and gain takeover.
OpenCVE Enrichment