Executive brief
A vulnerability exists in the Internal Operations component of Oracle Project Contracts, a tool used by businesses to manage complex project-based agreements within the Oracle E-Business Suite. An attacker with basic user credentials could potentially gain unauthorized access to sensitive project data. While the risk of data exposure is present, the attack is considered difficult to execute and requires existing access to the network.
Technical details
This vulnerability affects the Internal Operations component of Oracle Project Contracts within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a confidentiality-impacting bug that allows a low-privileged attacker with network access via HTTP to compromise the system. The attack complexity is rated as high, suggesting that specific conditions or significant effort are required for a successful exploit. If successful, an attacker can achieve unauthorized read access to a subset of data managed by the Project Contracts module. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Project Contracts 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory