Impact
The vulnerability exists in the File Transmission component of Oracle Payments within Oracle E‑Business Suite. It allows a low‑privileged attacker who can reach the application over HTTP to create, delete or modify critical data, thereby compromising confidentiality and integrity. The weakness appears to stem from improper access control, a flaw that is inferred from the documented ability to perform unauthorized operations; this inference is not explicitly stated in the description.
Affected Systems
Oracle Payments product by Oracle Corporation, running versions 12.2.3 through 12.2.15 of Oracle E‑Business Suite. These versions retain the file transmission flaw until a patch is applied or the component is removed.
Risk and Exploitability
The CVSS score of 8.1 classifies the issue as high severity, while the EPSS score of less than 1% indicates that exploitation attempts are expected to be rare. The vulnerability is not listed in CISA’s KEV catalog, but a low‑privileged attacker only requires network connectivity to the Oracle Payments HTTP interface and no user interaction to exploit it. No additional prerequisites beyond network access are specified.
OpenCVE Enrichment