Executive brief
A vulnerability exists in the Internal Operations component of Oracle Scripting, a tool within the Oracle E-Business Suite used for building interactive scripts and surveys. A high-privileged user could exploit this flaw to gain unauthorized access to sensitive business data or modify critical information. This could lead to significant data integrity issues or the exposure of confidential corporate records.
Technical details
This vulnerability affects the Internal Operations component of Oracle Scripting within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that allows a high-privileged attacker with network access via HTTP to compromise the system. Successful exploitation enables unauthorized creation, deletion, or modification of critical data, as well as complete unauthorized access to all data accessible by the Oracle Scripting module. The attack does not require user interaction and has a CVSS 3.1 base score of 6.5, primarily impacting confidentiality and integrity. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Oracle Scripting 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published