Impact
A flaw in Oracle Managed File Transfer allows attackers with low privileges and network access via HTTP to compromise the runtime server. When exploited successfully, the attacker gains full control of the system, threatening confidentiality, integrity, and availability of data and services.
Affected Systems
Oracle Managed File Transfer versions 12.2.1.4.0 and 14.1.2.0.0 in Oracle Fusion Middleware are affected and can be deployed in many environments.
Risk and Exploitability
The CVSS v3.1 score of 9.9 indicates critical severity, while the EPSS score of less than 1% suggests a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attack requires network reachability to HTTP and low privilege credentials; the flaw changes scope, so consequences may extend beyond the MFT component to other parts of the application.
OpenCVE Enrichment