Impact
A vulnerability in Oracle Scripting allows a low‑privileged attacker with network access via HTTP to create, delete, or modify critical data, or to gain full read or modify access to all Oracle Scripting data, and to cause a partial denial of service. This flaw enables attackers to violate confidentiality, integrity, and availability without interactive user input or elevated privileges. The weakness is characterized as improper access control, which can lead to significant data exposure or modification.
Affected Systems
Oracle Scripting for Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are vulnerable. These versions are available on internal operations components accessed through standard HTTP configuration.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 indicates high severity. Because the attack requires only network access through HTTP and no special authentication, the risk is considerable even though exploitation is classified as difficult. No EPSS score is available, and the vulnerability is not listed in CISA KEV. The likely attack vector is network‑based HTTP requests sent by an attacker with limited privileges on the same network.
OpenCVE Enrichment