CVE-2026-47033: High severity Oracle Oracle E-Business Suite - Oracle Contracts Integration vulnerability
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. While the vulnerability is in Oracle Contracts Integration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Contracts Integration. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Oracle E-Business Suite deployments using Oracle Contracts Integration versions 12.2.3 through 12.2.15 are affected. Exploitation requires network access to the service over HTTP.
What level of access does an attacker need?
An attacker must already have low-privileged access. No user interaction is required, but exploitation is rated difficult due to high attack complexity.
What could a successful attack impact beyond the vulnerable component?
A successful attack can result in takeover of Oracle Contracts Integration, with high confidentiality, integrity, and availability impact. The scope change indicates that additional products may also be significantly affected.