Executive brief
A vulnerability exists in the Oracle Contracts Integration component of the Oracle E-Business Suite, which manages business contract data and internal operations. An attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive contract information. This could lead to unauthorized data changes or the exposure of confidential business agreements.
Technical details
This vulnerability affects the Internal Operations component of Oracle Contracts Integration within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires network access via HTTP and human interaction (User Interaction: Required). The vulnerability involves a 'scope change' (Status: Changed), meaning an exploit can impact components beyond the immediate Oracle Contracts Integration environment. Attackers can achieve unauthorized read, update, insert, or delete access to a subset of the application's data. The CVSS vector (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) suggests a web-based attack such as Cross-Site Scripting (XSS) or a similar injection flaw.
Affected products
- Oracle Corporation Contracts Integration 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date