Description
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Payments. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Payments accessible data as well as unauthorized access to critical data or complete access to all Oracle Payments accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-05-28
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the File Transmission component of Oracle Payments that permits an attacker without authentication, who can reach the system over HTTPS, to create, delete, or alter critical data. The impact includes loss of confidentiality and integrity of all Oracle Payments data accessible to the system. The flaw is categorized as an Improper Access Control weakness (CWE-284).

Affected Systems

The affected product is Oracle Payments from Oracle Corporation, within the Oracle E-Business Suite. Supported versions impacted are 12.2.3 through 12.2.15.

Risk and Exploitability

The CVSS v3.1 base score of 7.4 reflects moderate to high risk, with network attack vector, high complexity, no user interaction, and impacts on confidentiality and integrity. EPSS data is not available, the vulnerability is not currently listed in CISA KEV, and the likely attack vector is inferred as an unauthenticated HTTPS connection to the vulnerable File Transmission service, as stated in the description.

Generated by OpenCVE AI on May 28, 2026 at 21:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle payment patch release that addresses the File Transmission flaw, as documented in Oracle's May 2026 security alert.
  • Restrict HTTPS traffic to the File Transmission service by firewall rules or deny inbound connections from untrusted networks until the patch is applied.
  • If patch deployment cannot occur immediately, isolate the vulnerable component or disable its network entry points to prevent external access.

Generated by OpenCVE AI on May 28, 2026 at 21:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 28 May 2026 22:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTPS File Transmission Vulnerability in Oracle Payments Allows Data Modification and Unauthorized Access
Weaknesses CWE-284

Thu, 28 May 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Payments. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Payments accessible data as well as unauthorized access to critical data or complete access to all Oracle Payments accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle payments
CPEs cpe:2.3:a:oracle:payments:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle payments
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-05-29T15:41:20.124Z

Reserved: 2026-05-18T15:55:10.302Z

Link: CVE-2026-46818

cve-icon Vulnrichment

Updated: 2026-05-29T15:41:09.842Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-28T21:16:31.637

Modified: 2026-05-29T16:16:28.757

Link: CVE-2026-46818

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T22:00:13Z

Weaknesses