Description
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Scripting accessible data as well as unauthorized access to critical data or complete access to all Oracle Scripting accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Scripting. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Scripting allows a low‑privileged attacker with network access via HTTP to create, delete, or modify critical data, or to gain full read or modify access to all Oracle Scripting data, and to cause a partial denial of service. This flaw enables attackers to violate confidentiality, integrity, and availability without interactive user input or elevated privileges. The weakness is characterized as improper access control, which can lead to significant data exposure or modification.

Affected Systems

Oracle Scripting for Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are vulnerable. These versions are available on internal operations components accessed through standard HTTP configuration.

Risk and Exploitability

The CVSS 3.1 base score of 7.1 indicates high severity. Because the attack requires only network access through HTTP and no special authentication, the risk is considerable even though exploitation is classified as difficult. No EPSS score is available, and the vulnerability is not listed in CISA KEV. The likely attack vector is network‑based HTTP requests sent by an attacker with limited privileges on the same network.

Generated by OpenCVE AI on August 21, 2026 at 05:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Scripting to a non‑affected version (≥12.2.16) or apply the vendor‑issued patch when available.
  • Restrict HTTP access to Oracle Scripting by implementing network segmentation or firewall rules that allow only trusted host ranges.
  • Enable strict access controls and role‑based permissions within the application to prevent unauthorized create, delete, or modify actions.
  • Monitor audit logs for anomalous data changes or repeated failed requests to detect exploitation attempts.

Generated by OpenCVE AI on August 21, 2026 at 05:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via HTTP in Oracle Scripting

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via HTTP in Oracle Scripting
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Scripting accessible data as well as unauthorized access to critical data or complete access to all Oracle Scripting accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Scripting. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).
First Time appeared Oracle
Oracle scripting
CPEs cpe:2.3:a:oracle:scripting:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle scripting
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Oracle Scripting
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:11.702Z

Reserved: 2026-08-04T22:06:34.598Z

Link: CVE-2026-70809

cve-icon Vulnrichment

Updated: 2026-08-19T12:11:00.441Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:35.377

Modified: 2026-08-28T14:47:15.313

Link: CVE-2026-70809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:00:03Z

Weaknesses