Description
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in takeover of Oracle Scripting. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Scripting, a component of Oracle E‑Business Suite, is vulnerable to a difficult‑to‑exploit flaw that allows an attacker without authentication to gain full control of the system when interacting over HTTP. This flaw results in a total compromise of the affected product, delivering capability for a data breach as well as any integrity or availability attacks. The CVSS vector confirms that confidentiality, integrity, and availability are all severely impacted, with a base score of 8.1.

Affected Systems

The vulnerability affects Oracle Corporation’s Oracle Scripting product in the Oracle E‑Business Suite family, specifically the Internal Operations component. Supported versions that are impacted run from 12.2.3 through 12.2.15. Users running any of these releases should verify whether they are still within this range.

Risk and Exploitability

The attack vector is inferred to be a network‑based HTTP request that can be performed by an unauthenticated attacker, as the exploit requires no prior access or privileges. The high effort required for exploitation (denoted by the “High Complexity” score) is reflected in an EPSS score below 1%, indicating a low probability of active exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, but its high CVSS score and complete compromise potential warrant urgent attention.

Generated by OpenCVE AI on August 4, 2026 at 02:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle CPU patch for Oracle Scripting as published by Oracle’s security alerts
  • Restrict HTTP access to the Oracle Scripting component by implementing firewall rules or access control lists that allow only trusted IP addresses
  • Disable or isolate the Oracle Scripting service on systems that do not require it until a patch can be applied

Generated by OpenCVE AI on August 4, 2026 at 02:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP RCE in Oracle Scripting 12.2.x

Thu, 30 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP RCE in Oracle Scripting 12.2.x

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle Scripting

Sun, 26 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in Oracle Scripting
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in takeover of Oracle Scripting. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle scripting
CPEs cpe:2.3:a:oracle:scripting:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle scripting
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Scripting
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:20:36.942Z

Reserved: 2026-07-08T15:51:55.605Z

Link: CVE-2026-60979

cve-icon Vulnrichment

Updated: 2026-07-24T15:20:31.933Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:31.217

Modified: 2026-07-31T19:29:18.033

Link: CVE-2026-60979

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function