Impact
Vulnerability in Oracle Scripting arises from insufficient access control and improper authorization checking, allowing a high‑privileged attacker with network access over HTTP to create, delete or modify critical data. The flaw bypasses normal access controls, enabling unauthorized creation, deletion or alteration of information exposed by Oracle Scripting. This results in loss of confidentiality and integrity of all data accessible through the application.
Affected Systems
Oracle Corporation’s Oracle Scripting component of Oracle E‑Business Suite is affected, specifically supported releases from version 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 % suggests a low probability of exploitation. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based HTTP requests from a host that already holds high privileges in the Oracle environment, enabling the attacker to modify or delete data beyond normal role permissions.
OpenCVE Enrichment