Description
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Payments. While the vulnerability is in Oracle Payments, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Payments accessible data as well as unauthorized access to critical data or complete access to all Oracle Payments accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The defect resides in the File Transmission component of Oracle Payments within Oracle E‑Business Suite. An attacker with high privileges and the ability to send HTTP requests can create, delete, or modify critical data. This results in significant confidentiality and integrity impacts across all data accessible through Oracle Payments. The description indicates that the vulnerability neither grants direct system compromise nor causes denial of service; it is inferred that these capabilities are absent because no exploit paths to those outcomes are described.

Affected Systems

Affected versions are Oracle Payments for Oracle E‑Business Suite, from 12.2.3 through 12.2.15. The scope change indicates potential impact on other Oracle products, although the primary affected product is the Payments module.

Risk and Exploitability

The CVSS v3.1 base score of 7.7 reflects high severity. Exploitation requires the attacker to hold high privileges and network access via HTTP; the AC:H rating suggests moderate to difficult exploitation. The EPSS score is less than 1 %, indicating a very low likelihood of widespread exploitation. The vulnerability is not listed in CISA KEV, so no publicly known active exploits are reported. The risk is primarily driven by the potential for unauthorized data modification and deletion, and the requirement of high privileges limits the attack surface compared to low‑privileged threats.

Generated by OpenCVE AI on August 26, 2026 at 03:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Payments security patch that addresses the File Transmission issue, or upgrade to a version newer than 12.2.15.
  • Restrict HTTP access to the Oracle Payments interface to trusted IP addresses or enforce VPN connectivity to limit exposure.
  • Enforce the principle of least privilege by ensuring only authorized users can perform file transmission operations; audit permissions.
  • Monitor transaction logs for anomalous file transmission activity and enforce alerting for unauthorized modifications.
  • Consult advisories for any temporary mitigations until the patch can be applied.

Generated by OpenCVE AI on August 26, 2026 at 03:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Oracle Payments File Transmission Vulnerability Enables Unauthorized Data Modification
Weaknesses CWE-285

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Oracle Payments File Transmission Vulnerability Enables Unauthorized Data Modification
Weaknesses CWE-285

Fri, 21 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title High Privilege File Transmission Vulnerability in Oracle Payments Allows Unauthorized Data Modification
Weaknesses CWE-284

Wed, 19 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title High Privilege File Transmission Vulnerability in Oracle Payments Allows Unauthorized Data Modification
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Payments. While the vulnerability is in Oracle Payments, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Payments accessible data as well as unauthorized access to critical data or complete access to all Oracle Payments accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle payments
CPEs cpe:2.3:a:oracle:payments:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle payments
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:13:30.289Z

Reserved: 2026-08-04T22:06:34.590Z

Link: CVE-2026-70694

cve-icon Vulnrichment

Updated: 2026-08-25T14:25:31.653Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:21.450

Modified: 2026-08-26T17:43:43.637

Link: CVE-2026-70694

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T04:00:04Z

Weaknesses