Description
Vulnerability in the Oracle Payables product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payables. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Payables. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Payables, part of Oracle E‑Business Suite, includes a flaw that lets an unauthenticated attacker with network access over HTTP trigger a crash or hang, eliminating availability without compromising confidentiality or integrity. The vulnerability requires no client authentication or elevated permissions and can be triggered by sending a well‑formed HTTP request to the Payables service. Because the code path is exercised during normal processing, the attack is straightforward and repeatable.

Affected Systems

The affected versions are Oracle Payables 12.2.3 through 12.2.15, which belong to the Internal Operations component of the E‑Business Suite. No other products or vendors are listed as impacted.

Risk and Exploitability

The CVSS v3.1 base score of 7.5 reflects a high availability impact, and the EPSS score of <1% indicates a low but non‑zero probability of exploitation at the time of this report. The vulnerability can be invoked remotely from any machine that can reach the Payables HTTP endpoint; no authentication or privileged access is needed. Although it is not catalogued in the CISA KEV list, the ability to force a denial of service by simply sending crafted HTTP traffic makes it a potential threat to production environments.

Generated by OpenCVE AI on August 26, 2026 at 06:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict external HTTP access to Oracle Payables to trusted IP ranges or VPN connections
  • Deploy or configure firewalls and intrusion detection systems to block anomalous traffic patterns that could trigger the crash
  • Review Oracle’s security advisories and monitor for any future patches or mitigations

Generated by OpenCVE AI on August 26, 2026 at 06:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle e-business Suite
CPEs cpe:2.3:a:oracle:e-business_suite:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:payables:-:*:*:*:*:*:*:*
Vendors & Products Oracle e-business Suite

Wed, 26 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title HTTP Denial of Service Vulnerability in Oracle Payables 12.2.3-12.2.15

Wed, 26 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title HTTP Denial of Service Vulnerability in Oracle Payables 12.2.3-12.2.15
Weaknesses CWE-400

Tue, 25 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Tue, 25 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Denial of Service in Oracle Payables
Weaknesses CWE-400

Tue, 25 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 21 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Denial of Service in Oracle Payables
Weaknesses CWE-400

Fri, 21 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Denial of Service in Oracle Payables
Weaknesses CWE-388
CWE-400

Wed, 19 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Denial of Service in Oracle Payables
Weaknesses CWE-388
CWE-400

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Payables product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payables. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Payables. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle payables
CPEs cpe:2.3:a:oracle:payables:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle payables
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle E-business Suite Payables
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T16:37:29.445Z

Reserved: 2026-08-04T22:06:34.590Z

Link: CVE-2026-70700

cve-icon Vulnrichment

Updated: 2026-08-25T15:23:07.183Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:22.130

Modified: 2026-08-31T15:07:28.793

Link: CVE-2026-70700

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T07:00:15Z

Weaknesses