Impact
The Oracle Payments component for File Transmission contains a flaw that allows an unauthenticated attacker with network access over TCP to gain unauthorized control of the system. Once exploited, the attacker can read or manipulate all data normally accessible through Oracle Payments, compromising confidentiality and potentially allowing alteration of critical financial information. The weakness is an access control failure, as it permits privilege‑less network users to bypass standard authentication mechanisms.
Affected Systems
Oracle Corporation’s Oracle Payments product, part of Oracle E‑Business Suite, is affected. Versions 12.2.3 through 12.2.15 are reported to be vulnerable. Any deployment of Oracle Payments within this version range that exposes the File Transmission service to an external network must be considered at risk.
Risk and Exploitability
The flaw has a CVSS 3.1 Base Score of 7.5, indicating moderate complexity, no required privileges, and a high impact on confidentiality. The attack vector is network access via TCP and authentication is not required, so exploitation is straightforward for an attacker with network connectivity to the target. EPSS score 0.00303 indicates an extremely low probability of exploitation, but the vulnerability is not listed in CISA’s KEV catalog, making it a priority for remediation due to its direct network exposure.
OpenCVE Enrichment