Executive brief
Oracle E-Business Suite Contracts is a component used to manage contract operations and data within Oracle's enterprise business systems. A vulnerability in this component allows a low-privileged attacker to gain complete administrative control over the Contracts application through network access, potentially exposing or manipulating sensitive contract and business data.
Technical details
This is a privilege escalation vulnerability in the Internal Operations component of Oracle Contracts within E-Business Suite. The flaw is easily exploitable and requires only network access (HTTP) and low-privilege credentials—no special user interaction is needed. An attacker can leverage this to escalate privileges and achieve full compromise of the application, including unauthorized access to confidential data and the ability to modify or delete critical contract information. The vulnerability affects versions 12.2.14 through 12.2.15. Oracle has published a security advisory addressing this issue.
Affected products
- Oracle E-Business Suite Contracts 12.2.14-12.2.15
Timeline
- 2026-09-15: disclosed