Impact
Oracle Scripting in Oracle E‑Business Suite contains an access control flaw (CWE‑284) that permits attackers with low privileges to use HTTP requests to alter, insert or delete data and to read portions of data that should be restricted. The vulnerability leverages the Scripting Admin component and can be exploited by an attacker who can reach the application over the network. Successful exploitation compromises the confidentiality and integrity of the affected data but does not affect availability.
Affected Systems
The flaw affects Oracle Scripting versions from 12.2.3 through 12.2.15. Systems running these Oracle E‑Business Suite releases with the Scripting component exposed to HTTP traffic are vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 5.4 indicates moderate risk, primarily for confidentiality and integrity. The EPSS score of less than 1 % denotes a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is network‑based HTTP access to the Scripting Admin endpoint by a low‑privileged attacker, which can execute the exploit without additional privileges or user interaction.
OpenCVE Enrichment