Junglewise Threat Intelligence

CVE-2026-62489: Oracle E-Business Suite data manipulation in Oracle Contracts Integration

CVE-2026-62489 · Severity: medium · CVSS 4.2 · Published 2026-07-21

Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Contracts Integration, a tool used by businesses to manage and integrate contract data within the Oracle E-Business Suite. An attacker with low-level access to the network could potentially view, modify, or delete certain contract-related information. While the attack is considered difficult to execute, it could lead to unauthorized changes to business records or the exposure of sensitive data.

Technical details

This vulnerability affects the Internal Operations component of Oracle Contracts Integration within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a difficult-to-exploit flaw that requires the attacker to have low-privileged credentials and network access via HTTP. Successful exploitation allows an attacker to perform unauthorized read, update, insert, or delete operations on a subset of the data accessible to the Oracle Contracts Integration product. The vulnerability has a CVSS 3.1 base score of 4.2, reflecting impacts on confidentiality and integrity but not availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation E-Business Suite (Oracle Contracts Integration) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update and NVD publication.

References