Description
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Payments accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Payments. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the Oracle Payments File Transmission component permits a low‑privileged attacker with HTTP network access to read sensitive data and potentially disrupt service availability. The flaw is an information exposure (CWE‑200), allowing unauthorized access to critical or all data available through Oracle Payments.

Affected Systems

Oracle Payments, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15. All installations of these releases running the File Transmission component are susceptible.

Risk and Exploitability

The CVSS v3.1 base score of 7.1 signals moderate‑to‑high risk with significant confidentiality and availability impact. The EPSS score of less than 1% indicates a low current likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw without authentication, using a network‑based HTTP request from a low‑privileged user to obtain sensitive data or cause a partial denial of service.

Generated by OpenCVE AI on August 4, 2026 at 04:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or update released in the CPU July 2026 security advisory to address the File Transmission access issue.
  • Restrict or disable HTTP access to the File Transmission component for non‑trusted networks and ensure firewall rules enforce least‑privilege communication.
  • Segment the Oracle Payments network or implement additional security controls to isolate the Payments service from the broader network, reducing exposure to low‑privileged users.

Generated by OpenCVE AI on August 4, 2026 at 04:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Oracle Payments File Transmission Vulnerability Allows Unauthorized Data Access

Thu, 30 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Oracle Payments File Transmission Vulnerability Allows Unauthorized Data Access

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Low‑privilege HTTP Vulnerability in Oracle Payments File Transmission Component
Weaknesses CWE-284

Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Low‑privilege HTTP Vulnerability in Oracle Payments File Transmission Component
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Payments accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Payments. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).
First Time appeared Oracle
Oracle payments
CPEs cpe:2.3:a:oracle:payments:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle payments
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T16:14:13.327Z

Reserved: 2026-07-08T15:51:40.518Z

Link: CVE-2026-60176

cve-icon Vulnrichment

Updated: 2026-07-23T16:14:09.872Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor