CVE-2026-62489: Medium severity Oracle Oracle Contracts Integration vulnerability
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Contracts Integration accessible data as well as unauthorized read access to a subset of Oracle Contracts Integration accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62489?
The severity of CVE-2026-62489 is medium with a CVSS score of 4.2.
How do I fix CVE-2026-62489?
To fix CVE-2026-62489, update your Oracle E-Business Suite to a version that is not affected.
What systems are affected by CVE-2026-62489?
CVE-2026-62489 affects Oracle Contracts Integration within the Oracle E-Business Suite, specifically versions 12.2.3 to 12.2.15.
What type of attack does CVE-2026-62489 allow?
CVE-2026-62489 allows a low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration.
Is CVE-2026-62489 easy to exploit?
CVE-2026-62489 is considered difficult to exploit due to its requirements.