Impact
Oracle Payables, part of Oracle E‑Business Suite, includes a flaw that lets an unauthenticated attacker with network access over HTTP trigger a crash or hang, eliminating availability without compromising confidentiality or integrity. The vulnerability requires no client authentication or elevated permissions and can be triggered by sending a well‑formed HTTP request to the Payables service. Because the code path is exercised during normal processing, the attack is straightforward and repeatable.
Affected Systems
The affected versions are Oracle Payables 12.2.3 through 12.2.15, which belong to the Internal Operations component of the E‑Business Suite. No other products or vendors are listed as impacted.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 reflects a high availability impact, and the EPSS score of <1% indicates a low but non‑zero probability of exploitation at the time of this report. The vulnerability can be invoked remotely from any machine that can reach the Payables HTTP endpoint; no authentication or privileged access is needed. Although it is not catalogued in the CISA KEV list, the ability to force a denial of service by simply sending crafted HTTP traffic makes it a potential threat to production environments.
OpenCVE Enrichment