Impact
The vulnerability in Oracle Payments’ File Transmission component allows attackers to send unauthenticated HTTP requests that fully compromise the system. The flaw provides complete control over confidentiality, integrity, and availability, enabling a remote attacker to take over Oracle Payments. The weakness is identified as CWE-306, representing insecure authentication. The CVSS 3.1 vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H confirms that the vulnerability is easily exploitable without any user interaction.
Affected Systems
Oracle Payments in Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected. All deployments of this product in those releases remain vulnerable until an official patch is applied.
Risk and Exploitability
The CVSS Base Score of 9.8 places this flaw in the critical severity range. The EPSS score is less than 1%, indicating an extremely low but nonzero probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector is through unauthenticated HTTP requests to the File Transmission component, as inferred from the description of network access via HTTP to compromise Oracle Payments.
OpenCVE Enrichment