Description
Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Wage Determination Online). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contract Lifecycle Management for Public Sector. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Contract Lifecycle Management for Public Sector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Contract Lifecycle Management for Public Sector accessible data as well as unauthorized read access to a subset of Oracle Contract Lifecycle Management for Public Sector accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-09-15
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Modification/Read
Action: Patch Now
AI Analysis

Impact

An insufficient access control flaw in Oracle Contract Lifecycle Management for Public Sector lets unauthenticated web users modify or read restricted data over HTTP. The weakness, categorized as CWE-284, permits unauthorized updates, inserts, or deletions, as well as read access to subsets of the system’s data. This can compromise the integrity and confidentiality of the application’s information.

Affected Systems

The vulnerability impacts Oracle’s Contract Lifecycle Management for Public Sector product, specifically the Wage Determination Online component, across versions 12.2.3 to 12.2.15. Users of these releases are exposed to potential data tampering or unauthorized data disclosure.

Risk and Exploitability

The CVSS v3.1 base score of 6.1 scores moderate risk for confidentiality and integrity. The exploit probability according to the EPSS is below 1 %, and the flaw is not listed in the CISA KEV catalog. It is exploitable by a network-remote attacker over HTTP, but requires human interaction to activate the malicious actions. The attack vector is therefore a network-based one, and while the flaw resides in the Contract Lifecycle Management product, the impact may extend to other Oracle E-Business Suite components.

Generated by OpenCVE AI on September 18, 2026 at 17:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Oracle Contract Lifecycle Management for Public Sector that addresses the insufficient access control flaw.
  • Limit HTTP access to the application by configuring firewall rules or IP whitelisting to restrict exposure to trusted networks.
  • Enforce strong authentication, including multi-factor authentication where possible, for all users accessing the Contract Lifecycle Management system to prevent unauthenticated access.

Generated by OpenCVE AI on September 18, 2026 at 17:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification in Oracle Contract Lifecycle Management
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Unauthorized Data Modification in Oracle Contract Lifecycle Management
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Wage Determination Online). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contract Lifecycle Management for Public Sector. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Contract Lifecycle Management for Public Sector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Contract Lifecycle Management for Public Sector accessible data as well as unauthorized read access to a subset of Oracle Contract Lifecycle Management for Public Sector accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle contract Lifecycle Management For Public Sector
CPEs cpe:2.3:a:oracle:contract_lifecycle_management_for_public_sector:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle contract Lifecycle Management For Public Sector
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Contract Lifecycle Management For Public Sector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:11:41.463Z

Reserved: 2026-09-08T21:49:12.400Z

Link: CVE-2026-87169

cve-icon Vulnrichment

Updated: 2026-09-18T18:11:36.389Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:19:04.630

Modified: 2026-09-18T18:17:21.277

Link: CVE-2026-87169

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T17:15:11Z

Weaknesses