Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. While the vulnerability is in Oracle Contracts Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Contracts Integration. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html |
|
History
Sat, 01 Aug 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low‑Privileged HTTP Attack Can Takeover Oracle Contracts Integration |
Mon, 27 Jul 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low‑Privilege Remote Takeover via HTTP in Oracle Contracts Integration |
Fri, 24 Jul 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low‑Privilege Remote Takeover via HTTP in Oracle Contracts Integration |
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
ssvc
|
Tue, 21 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. While the vulnerability is in Oracle Contracts Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Contracts Integration. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle contracts Integration |
|
| CPEs | cpe:2.3:a:oracle:contracts_integration:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle contracts Integration |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-07-21T21:33:08.894Z
Updated: 2026-07-23T17:07:10.232Z
Reserved: 2026-05-18T15:55:10.318Z
Link: CVE-2026-47033
Updated: 2026-07-23T16:16:06.387Z
Status : Analyzed
Published: 2026-07-21T22:17:08.823
Modified: 2026-07-27T17:44:32.203
Link: CVE-2026-47033
No data.