Executive brief
A vulnerability exists in the Internal Operations component of Oracle Contracts Integration, a tool used within the Oracle E-Business Suite to manage business agreements. An unauthenticated attacker could trick a legitimate user into performing an action that allows the attacker to modify or delete critical contract data. This could lead to significant business disruption, loss of data integrity, and a partial shutdown of the contract management service.
Technical details
A vulnerability in the Internal Operations component of Oracle Contracts Integration (part of Oracle E-Business Suite) allows an unauthenticated attacker with network access via HTTP to compromise the system. The exploit requires human interaction from a person other than the attacker, suggesting a Cross-Site Request Forgery (CSRF) or similar client-side attack vector. Successful exploitation can lead to unauthorized creation, deletion, or modification of all accessible data within the component, as well as a partial denial of service. The vulnerability affects versions 12.2.3 through 12.2.15. Oracle addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle Contracts Integration 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Published as part of Oracle July 2026 CPU