Impact
The vulnerability resides in the File Transmission component of Oracle Payments and permits a high‑privileged attacker with HTTP network access to forge, delete, or alter critical data. This leads to loss of confidentiality and integrity of all information processed by Oracle Payments, while availability remains largely unaffected. The flaw is a failure of access control and is difficult to exploit, requiring significant user privileges within the application. Because the flaw can change scope, attacks may also compromise additional Oracle products, extending the potential impact beyond Oracle Payments.
Affected Systems
Oracle Payments, part of Oracle E‑Business Suite, is impacted for versions 12.2.3 through 12.2.15. Attacking requires connectivity to the web interface and a user account possessing elevated privileges within the application.
Risk and Exploitability
The CVSS 3.1 score of 7.7 indicates a high‑severity flaw, with highly complex exploitation and high pre‑existing privileges required. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. The fact that it can change scope to affect other Oracle products raises the potential impact, making it a near‑critical issue that should be prioritized for remediation.
OpenCVE Enrichment