Impact
This vulnerability allows a low‑privileged attacker with network access through the T3 or IIOP protocols to create, delete, or modify files, read restricted data, and trigger a hang or crash that results in a denial of service. The impact includes confidentiality, integrity, and availability compromise, as described by a CVSS 3.1 base score of 8.3. The weakness enables unauthorized manipulation of critical data and repeatedly disrupts the Oracle Managed File Transfer service.
Affected Systems
Oracle Corporation’s Managed File Transfer component of Oracle Fusion Middleware, specifically the MFT Runtime Server, is affected in versions 12.2.1.4.0 and 14.1.2.0.0. Users of these releases should verify their installed versions against the cited identifiers.
Risk and Exploitability
The EPSS score indicates very low exploitation probability (<1%), and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack vector is network‑based, requiring only local or remote access through standard ports, and the low privilege requirement makes it attainable by a broad range of adversaries. The CVSS vector conveys limited confidentiality impact, but high integrity and availability effects, underscoring the risk when the weakness is present.
OpenCVE Enrichment