Impact
Oracle Scripting, a component of Oracle E‑Business Suite, is vulnerable to a difficult‑to‑exploit flaw that allows an attacker without authentication to gain full control of the system when interacting over HTTP. This flaw results in a total compromise of the affected product, delivering capability for a data breach as well as any integrity or availability attacks. The CVSS vector confirms that confidentiality, integrity, and availability are all severely impacted, with a base score of 8.1.
Affected Systems
The vulnerability affects Oracle Corporation’s Oracle Scripting product in the Oracle E‑Business Suite family, specifically the Internal Operations component. Supported versions that are impacted run from 12.2.3 through 12.2.15. Users running any of these releases should verify whether they are still within this range.
Risk and Exploitability
The attack vector is inferred to be a network‑based HTTP request that can be performed by an unauthenticated attacker, as the exploit requires no prior access or privileges. The high effort required for exploitation (denoted by the “High Complexity” score) is reflected in an EPSS score below 1%, indicating a low probability of active exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, but its high CVSS score and complete compromise potential warrant urgent attention.
OpenCVE Enrichment