Executive brief
Oracle Contract Lifecycle Management for Public Sector is an enterprise application that manages government and public sector contracts within Oracle E-Business Suite. A vulnerability in the ECC For Award and IDV component allows a low-privileged network attacker to gain complete control of the system, compromising confidentiality, integrity, and availability of all contract data and operations.
Technical details
This is a privilege escalation vulnerability in the ECC For Award and IDV component of Oracle Contract Lifecycle Management for Public Sector. The vulnerability is easily exploitable via HTTP and requires only low privilege network access and no user interaction. An authenticated attacker with low privileges can exploit this flaw to achieve full system compromise with high confidentiality, integrity, and availability impact. The vulnerability affects version 16 of the product, and patches should be available from Oracle.
Affected products
- Oracle Contract Lifecycle Management for Public Sector V16
Timeline
- 2026-09-15: disclosed