Unauthenticated Access Vulnerability in Oracle E-Business Suite Scripting Component
CVE-2018-2997
What is CVE-2018-2997?
A vulnerability exists in the Oracle Scripting component of Oracle E-Business Suite, affecting versions 12.1.1, 12.1.2, and 12.1.3. This flaw allows an unauthenticated attacker with network access via HTTP to exploit the Oracle Scripting feature, necessitating human action from a user who is not the attacker for successful exploitation. While the primary vulnerability is located in the scripting component, the ramifications of an attack can extend to compromise critical data across additional products. Successful exploitation grants the attacker unauthorized access to sensitive data, potentially allowing them to execute operations such as updating, inserting, or deleting data within Oracle Scripting, thus posing significant risks to data integrity and confidentiality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Scripting 12.1.1
Scripting 12.1.2
Scripting 12.1.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved