Impact
The vulnerability is located in the File Transmission component of Oracle Payments and allows an unauthenticated attacker to reach the service through an open HTTP interface. When exploited, an attacker can read sensitive customer and payment data and can also insert, update, or delete records, thereby compromising data integrity. The flaw leads to high confidentiality damage with moderate integrity impact and does not affect availability.
Affected Systems
All supported releases of Oracle Payments in the Oracle E‑Business Suite from version 12.2.3 through 12.2.15 are impacted.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 reflects a high confidentiality impact. The EPSS score of less than 1% indicates a very low but nonzero likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is over an open HTTP interface without authentication, making the flaw easily exploitable for those with network access.
OpenCVE Enrichment