Impact
This vulnerability is in the Oracle Managed File Transfer component of Oracle Fusion Middleware. A low‑privileged attacker who can reach the system over the network using the T3 or IIOP protocols can trigger an easily exploited flaw that allows full compromise of the MFT Runtime Server. The attacker can take over the service, granting them complete control over the targeted application and potentially other Oracle Fusion Middleware products. The flaw results in remote code execution, affecting confidentiality, integrity, and availability. The flaw is classified as CWE-284 (Improper Access Control).
Affected Systems
The affected products are Oracle Managed File Transfer versions 12.2.1.4.0 and 14.1.2.0.0. These versions are part of Oracle Fusion Middleware and should be prioritized for remediation if deployed.
Risk and Exploitability
The vulnerability carries a CVSS v3.1 base score of 9.9, indicating critical severity. The EPSS score is < 1%, suggesting a low but non‑negligible probability of exploitation. The exploitation requires only low‑privileged network access via the T3 or IIOP protocols and does not rely on user interaction, making it highly remotely exploitable. The vulnerability is not yet listed in the CISA KEV catalog, but its high CVSS combined with the remote nature and the requirement of minimal privileges warrant urgent attention. A low‑privileged attacker with network access can execute the attack, so the risk is significant if the system is exposed to untrusted networks.
OpenCVE Enrichment