Oracle E-Business Suite Scripting Component Scripting Admin Unauthenticated Data Access Vulnerability

Vulnerability

A vulnerability exists in the Oracle Scripting product of Oracle E-Business Suite, specifically in the Scripting Admin component. This issue affects versions 12.2.3 through 12.2.15. The vulnerability allows an unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Exploitation of this vulnerability requires human interaction from a third party. While the vulnerability is contained within Oracle Scripting, successful attacks could significantly impact additional products. Exploiting this vulnerability could lead to unauthorized read access to certain Oracle Scripting data, as well as unauthorized update, insert, or delete access to other accessible data.

Impact

Exploitation of this vulnerability could result in unauthorized access to read, update, insert, or delete certain data within Oracle Scripting.

Added: Jan 20, 2026, 11:12 PM
Updated: Jan 20, 2026, 11:12 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
4.2
remediation
0.0
relevance
2.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.