Impact
The flaw is a missing authentication control (CWE‑306) in Oracle Managed File Transfer’s Runtime Server, enabling a low‑privileged attacker to gain unauthorized access over the network via the HTTP interface. The vulnerability can result in full compromise of the MFT service, allowing an attacker to read, modify, delete, or exfiltrate data and disrupt availability. The likely attack vector is anonymous HTTP requests to an exposed endpoint.
Affected Systems
Oracle Managed File Transfer versions 12.2.1.4.0 and 14.1.2.0.0, part of Oracle Fusion Middleware, are affected. The vulnerability targets the MFT Runtime Server component that exposes an HTTP endpoint.
Risk and Exploitability
The CVSS base score is 8.8, indicating high severity with impacts to confidentiality, integrity, and availability. The EPSS score is less than 1%, suggesting limited exploitation probability. The KEV catalog does not list this CVE, but the low attack complexity and no user interaction mean that an attacker who can reach the HTTP interface can exploit the flaw remotely. Although widespread exploitation is considered unlikely, the potential for complete service takeover requires prompt patching.
OpenCVE Enrichment