Impact
A vulnerability in the File Transmission component of Oracle Payments enables an attacker who can reach the system over HTTPS to perform unauthorized operations without authentication. An exploit would let the attacker create, delete, or modify critical data or obtain complete access to all Oracle Payments data, causing loss of confidentiality and integrity.
Affected Systems
Oracle Corporation offers Oracle Payments, and versions 12.2.3-12.2.15 are affected. Only these releases expose the vulnerable component and are susceptible to the described attacks.
Risk and Exploitability
The CVSS 3.1 score of 7.4 indicates a high severity with substantial confidentiality and integrity impact. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires network access over HTTPS and does not require authentication, suggesting that the flaw leverages improper authentication or access control mechanisms within the File Transmission component.
OpenCVE Enrichment