Executive brief
A high-severity vulnerability has been identified in Oracle Scripting, a component of the Oracle E-Business Suite used for managing interactive scripts and customer service workflows. An unauthorized person could potentially take full control of the scripting system over the network. This could lead to the theft of sensitive business data, unauthorized modification of records, or a complete disruption of services managed by this component.
Technical details
A vulnerability in the Internal Operations component of Oracle Scripting (part of Oracle E-Business Suite) allows for a complete system takeover. The flaw is exploitable by an unauthenticated attacker with network access via HTTP. While the attack complexity is rated as high, suggesting specific timing or environmental conditions may be required, a successful exploit results in a total loss of confidentiality, integrity, and availability (score 8.1). Affected versions range from 12.2.3 to 12.2.15. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation steps.
Affected products
- Oracle Corporation Oracle Scripting 12.2.3 - 12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory