Impact
Vulnerability in the Oracle Payments File Transmission component permits a low‑privileged attacker with HTTP network access to read sensitive data and potentially disrupt service availability. The flaw is an information exposure (CWE‑200), allowing unauthorized access to critical or all data available through Oracle Payments.
Affected Systems
Oracle Payments, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15. All installations of these releases running the File Transmission component are susceptible.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 signals moderate‑to‑high risk with significant confidentiality and availability impact. The EPSS score of less than 1% indicates a low current likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw without authentication, using a network‑based HTTP request from a low‑privileged user to obtain sensitive data or cause a partial denial of service.
OpenCVE Enrichment