Impact
Oracle Scripting, part of Oracle E-Business Suite, contains a vulnerability that allows a low-privileged attacker with network access via HTTP to gain unauthorized access to critical data and, in some cases, to insert, update, or delete data. The weakness permits breaches of confidentiality and limited integrity, enabling the attacker to view or modify data that they should not have permission to access.
Affected Systems
Oracle Scripting is affected in Oracle E-Business Suite versions 12.2.3 through 12.2.15, specifically within the Internal Operations component. Only these versions and that component are listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 score of 7.1 points to a high impact vulnerability. Attackers require only local or low privileges and network connectivity over HTTP, making exploitation relatively straightforward. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog, but the combination of high CVSS and network reachability still represents a significant risk. A successful exploit grants the attacker unauthorized read or modify access to all data exposed by Oracle Scripting.
OpenCVE Enrichment