Impact
The Oracle Scripting component in Oracle E‑Business Suite is vulnerable to an easily exploitable flaw. A low‑privileged attacker with network access can leverage the HTTP interface to bypass normal authorization checks and gain full control of the scripting environment. The impact includes complete compromise of the Oracle Scripting service, resulting in confidentiality, integrity, and availability loss. The weakness maps to improper access control, allowing attackers to elevate privileges within the application.
Affected Systems
Oracle Corporation’s Oracle Scripting product, part of Oracle E‑Business Suite’s Internal Operations component, is affected. The vulnerability exists in versions 12.2.3 through 12.2.15. System administrators should verify whether these corresponding releases are in use.
Risk and Exploitability
The CVSS v3.1 score of 8.8 indicates a high‑severity vulnerability that can be exploited over the network with a low attack complexity and requiring only local privileges. Although the EPSS score is not available and the flaw is not listed in the CISA KEV catalog, the lack of mitigation steps in the affected environment makes exploitation likely if the HTTP interface remains reachable from untrusted networks. The attack path does not require user interaction and can be performed remotely, highlighting the need for immediate remediation.
OpenCVE Enrichment