Impact
The defect resides in the File Transmission component of Oracle Payments within Oracle E‑Business Suite. An attacker with high privileges and the ability to send HTTP requests can create, delete, or modify critical data. This results in significant confidentiality and integrity impacts across all data accessible through Oracle Payments. The description indicates that the vulnerability neither grants direct system compromise nor causes denial of service; it is inferred that these capabilities are absent because no exploit paths to those outcomes are described.
Affected Systems
Affected versions are Oracle Payments for Oracle E‑Business Suite, from 12.2.3 through 12.2.15. The scope change indicates potential impact on other Oracle products, although the primary affected product is the Payments module.
Risk and Exploitability
The CVSS v3.1 base score of 7.7 reflects high severity. Exploitation requires the attacker to hold high privileges and network access via HTTP; the AC:H rating suggests moderate to difficult exploitation. The EPSS score is less than 1 %, indicating a very low likelihood of widespread exploitation. The vulnerability is not listed in CISA KEV, so no publicly known active exploits are reported. The risk is primarily driven by the potential for unauthorized data modification and deletion, and the requirement of high privileges limits the attack surface compared to low‑privileged threats.
OpenCVE Enrichment