Impact
Oracle Managed File Transfer contains a flaw that lets a low‑privilege attacker who can reach the service over HTTP perform unauthorized creation, deletion, or modification of data. The flaw is a known access control weakness (CWE-284) that enables this manipulation, resulting in both confidentiality and integrity compromise as the attacker can alter or change the effective scope of the application, enabling the attacker to affect additional components that rely on the same runtime environment.
Affected Systems
The affected product is Oracle Corporation's Managed File Transfer component of Oracle Fusion Middleware. Vulnerable releases are 12.2.1.4.0 and 14.1.2.0.0; no other versions are listed as affected, though other Oracle products that share the same runtime could be impacted through scope change.
Risk and Exploitability
The CVSS 3.1 vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N yields a base score of 9.6, indicating a severe confidentiality and integrity impact. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, because the vector includes a changed scope (S:C) and the product shares its runtime with other Oracle Fusion Middleware components, a successful attack could also affect additional products that use the same MFT Runtime Server. Exploitation would require only network access over HTTP and does not require user interaction or elevated privileges, enabling a low‑privilege attacker to send crafted requests to the MFT Runtime Server.
OpenCVE Enrichment