Executive brief
Oracle Contracts is a key component of Oracle E-Business Suite used to manage business contracts and agreements. A vulnerability in the internal operations module allows an authenticated high-privileged attacker to take over the entire Contracts system via network access, compromising the confidentiality, integrity, and availability of contract data and operations.
Technical details
The vulnerability is easily exploitable and affects the internal operations component of Oracle Contracts (versions 12.2.14–12.2.15). It requires high-level privileges and network access via HTTP; no user interaction is required. An authenticated attacker can achieve complete compromise of the Oracle Contracts system, resulting in full takeover. The vulnerability is unconfirmed for active exploitation in the wild. Patch availability and remediation details are available through Oracle's security advisory channels.
Affected products
- Oracle E-Business Suite Contracts 12.2.14–12.2.15
Timeline
- 2026-09-15: disclosed