Junglewise Threat Intelligence

CVE-2026-62488: Oracle E-Business Suite data integrity vulnerability in Contracts Integration

CVE-2026-62488 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle Contracts Integration. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Oracle Contracts Integration component of Oracle E-Business Suite, which is used by organizations to manage and integrate business contracts. An attacker with basic user credentials can exploit this flaw over the network to modify, create, or delete critical contract data. This could lead to unauthorized changes in business agreements or the loss of important legal and operational records.

Technical details

This vulnerability affects the Internal Operations component of Oracle Contracts Integration within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an integrity-impacting flaw that is easily exploitable via HTTP. An attacker requires low-level privileges (authenticated user) and network access to trigger the vulnerability. Successful exploitation allows the attacker to create, delete, or modify critical data or all data accessible to the Oracle Contracts Integration module. The vulnerability does not impact confidentiality or availability according to the CVSS vector. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Oracle Contracts Integration (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats