CVE-2026-62484: Medium severity Oracle Oracle E-Business Suite - Oracle Contracts Integration vulnerability
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62484?
The severity of CVE-2026-62484 is rated medium with a score of 5.9.
How do I fix CVE-2026-62484?
To fix CVE-2026-62484, apply the latest security patches provided by Oracle for affected versions 12.2.3-12.2.15.
What are the affected products for CVE-2026-62484?
CVE-2026-62484 affects the Oracle Contracts Integration component of Oracle E-Business Suite versions 12.2.3 to 12.2.15.
Who can exploit CVE-2026-62484?
CVE-2026-62484 can be exploited by an unauthenticated attacker with network access via HTTP.
What impact does CVE-2026-62484 have on Oracle E-Business Suite?
The impact of CVE-2026-62484 includes the potential compromise of Oracle Contracts Integration functionality.