Oracle Scripting vulnerabilities

8 known vulnerabilities affecting oracle/scripting.

Total CVEs
8
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH4MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2026-21943MEDIUMCVSS 6.1≥ 12.2.3, ≤ 12.2.152026-01-20
CVE-2026-21943 [MEDIUM] CWE-79 CVE-2026-21943: Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Scripting Admin Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Scripting Admin). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks require human interaction from a person other t
nvd
CVE-2025-61753MEDIUMCVSS 6.1≥ 12.2.3, ≤ 12.2.142025-10-21
CVE-2025-61753 [MEDIUM] CWE-601 CVE-2025-61753: Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks require human interaction from a person other th
nvd
CVE-2021-2029CRITICALCVSS 9.8≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.82021-01-20
CVE-2021-2029 [CRITICAL] CVE-2021-2029: Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in tak
nvd
CVE-2021-2091HIGHCVSS 8.2≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.102021-01-20
CVE-2021-2091 [HIGH] CVE-2021-2091: Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks require human interaction from a person ot
nvd
CVE-2020-2879HIGHCVSS 8.2≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.92020-04-15
CVE-2020-2879 [HIGH] CVE-2020-2879: Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks require human interaction from a person oth
nvd
CVE-2020-2817HIGHCVSS 8.2≥ 12.1.1, ≤ 12.1.32020-04-15
CVE-2020-2817 [HIGH] CVE-2020-2817: Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Miscellaneous). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks require human interaction from a person other than the attack
nvd
CVE-2018-2997HIGHCVSS 8.2v12.1.1v12.1.2+1 more2018-07-18
CVE-2018-2997 [HIGH] CVE-2018-2997: Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Script Aut Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Script Author). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks require human interaction from a person othe
nvd
CVE-2017-3549CRITICALCVSS 9.1PoCv12.1.1v12.1.2+5 more2017-04-24
CVE-2017-3549 [CRITICAL] CWE-89 CVE-2017-3549: Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successf
nvd