Description
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Payments accessible data as well as unauthorized access to critical data or complete access to all Oracle Payments accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the File Transmission component of Oracle Payments within Oracle E‑Business Suite. It allows a low‑privileged attacker who can reach the application over HTTP to create, delete or modify critical data, thereby compromising confidentiality and integrity. The weakness appears to stem from improper access control, a flaw that is inferred from the documented ability to perform unauthorized operations; this inference is not explicitly stated in the description.

Affected Systems

Oracle Payments product by Oracle Corporation, running versions 12.2.3 through 12.2.15 of Oracle E‑Business Suite. These versions retain the file transmission flaw until a patch is applied or the component is removed.

Risk and Exploitability

The CVSS score of 8.1 classifies the issue as high severity, while the EPSS score of less than 1% indicates that exploitation attempts are expected to be rare. The vulnerability is not listed in CISA’s KEV catalog, but a low‑privileged attacker only requires network connectivity to the Oracle Payments HTTP interface and no user interaction to exploit it. No additional prerequisites beyond network access are specified.

Generated by OpenCVE AI on August 12, 2026 at 10:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU Jul 2026 patch for Oracle Payments to address the file transmission flaw.
  • Restrict HTTP access to the Oracle Payments service to trusted hosts or disable the service for non‑essential network segments.
  • Re‑configure firewall and reverse‑proxy rules to block unauthorized IPs and enforce least‑privilege network segmentation for Oracle Payments endpoints.

Generated by OpenCVE AI on August 12, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title File Transmission Access Control Vulnerability in Oracle Payments

Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege File Transmission Vulnerability in Oracle Payments Exploitable Over HTTP
Weaknesses CWE-284

Thu, 30 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege File Transmission Vulnerability in Oracle Payments Exploitable Over HTTP
Weaknesses CWE-284

Mon, 27 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Exploitation in Oracle Payments File Transmission
Weaknesses CWE-284

Fri, 24 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged HTTP Exploitation in Oracle Payments File Transmission
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Payments accessible data as well as unauthorized access to critical data or complete access to all Oracle Payments accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle payments
CPEs cpe:2.3:a:oracle:payments:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle payments
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:21:25.806Z

Reserved: 2026-07-08T15:51:55.589Z

Link: CVE-2026-60778

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:17.030

Modified: 2026-07-29T15:32:04.637

Link: CVE-2026-60778

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T10:30:02Z

Weaknesses