Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Scripting accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Mon, 24 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Remote Data Access in Oracle Scripting via HTTP | |
| Weaknesses | CWE-284 |
Fri, 21 Aug 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Remote Access via HTTP in Oracle Scripting | |
| Weaknesses | CWE-200 CWE-284 |
Wed, 19 Aug 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Remote Access via HTTP in Oracle Scripting | |
| Weaknesses | CWE-200 CWE-284 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Scripting accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). | |
| First Time appeared |
Oracle
Oracle scripting |
|
| CPEs | cpe:2.3:a:oracle:scripting:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle scripting |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T21:01:56.353Z
Updated: 2026-08-24T19:54:21.086Z
Reserved: 2026-08-04T22:06:34.598Z
Link: CVE-2026-70810
Updated: 2026-08-24T19:49:36.083Z
Status : Awaiting Analysis
Published: 2026-08-18T21:17:35.517
Modified: 2026-08-24T20:17:06.427
Link: CVE-2026-70810
No data.