Impact
This vulnerability allows an attacker to compromise the Oracle Managed File Transfer runtime with only low privilege and simple HTTP network access. Successful exploitation would give the attacker control over the MFT component, resulting in loss of confidentiality, integrity, and availability of the system. The CVSS 3.1 base score of 8.8 indicates a high‑severity issue, with all three core impacts rated high. The weakness is a missing authentication/authorization control flaw (CWE‑306).
Affected Systems
Oracle Managed File Transfer version 12.2.1.4.0 and 14.1.2.0.0 are affected. Only these specific builds are vulnerable; newer or previous builds are not listed as impacted.
Risk and Exploitability
The EPSS score is reported as less than 1%, meaning the probability of exploitation at this time is very low, and the vulnerability is not listed in CISA's KEV catalog. Nonetheless, the attack vector is remote via HTTP and the attacker requires only low privileges. If an attacker is able to send crafted requests, they can gain full control of the MFT instance. The high CVSS score and availability of an essentially zero‑denial deniability exploit path warrant prompt attention.
OpenCVE Enrichment