Impact
The flaw resides in the Oracle Managed File Transfer (MFT) Runtime Server component of Oracle Fusion Middleware. An attacker who can reach the MFT service over HTTP and has only low privileges can exploit this issue. The vulnerability is an instance of improper authentication (CWE‑306), allowing the attacker to bypass authentication controls and gain unauthorized access to the MFT server. Once authenticated, the attacker can take full control of the MFT installation, compromising confidentiality, integrity, and availability. Because the exploit changes the scope of the affected software, additional components may also be compromised as a consequence.
Affected Systems
The affected products are Oracle Managed File Transfer versions 12.2.1.4.0 and 14.1.2.0.0, released by Oracle Corporation. These versions are integrated into Oracle Fusion Middleware and expose HTTP interfaces for file transfer operations.
Risk and Exploitability
The CVSS base score of 9.9 indicates a severe impact on confidentiality, integrity, and availability. The vulnerability is not listed in the CISA KEV catalog, and the EPSS score of <1% indicates that the probability of public exploitation is very low, though the high CVSS 9.9 score points to severe impact. Because the attacker only needs low privileges and network access via HTTP, the attack surface is broad for both internal or external actors that can reach the service. Successful exploitation results in a full system takeover and can potentially affect other Oracle components due to the change in scope.
OpenCVE Enrichment