Impact
A vulnerability exists in the File Transmission component of Oracle Payments that permits an attacker without authentication, who can reach the system over HTTPS, to create, delete, or alter critical data. The impact includes loss of confidentiality and integrity of all Oracle Payments data accessible to the system. The flaw is categorized as an Improper Access Control weakness (CWE-284).
Affected Systems
The affected product is Oracle Payments from Oracle Corporation, within the Oracle E-Business Suite. Supported versions impacted are 12.2.3 through 12.2.15.
Risk and Exploitability
The CVSS v3.1 base score of 7.4 reflects moderate to high risk, with network attack vector, high complexity, no user interaction, and impacts on confidentiality and integrity. EPSS data is not available, the vulnerability is not currently listed in CISA KEV, and the likely attack vector is inferred as an unauthenticated HTTPS connection to the vulnerable File Transmission service, as stated in the description.
OpenCVE Enrichment