Executive brief
A vulnerability exists in the File Transmission component of Oracle Payments, a module within the Oracle E-Business Suite used for managing financial transactions and electronic funds transfers. An attacker could exploit this flaw to gain unauthorized access to sensitive financial data or modify critical payment information. This could lead to significant financial fraud, data breaches, or the disruption of corporate payment processing operations.
Technical details
This vulnerability affects the File Transmission component of Oracle Payments within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is an unauthenticated, network-based attack reachable via HTTPS, though it is classified as having high attack complexity. Successful exploitation allows an attacker to gain full or critical access to data within the Oracle Payments module, including the ability to create, delete, or modify records. The vulnerability primarily impacts data confidentiality and integrity, while availability is not directly affected according to the CVSS metrics. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle E-Business Suite (Oracle Payments) 12.2.3-12.2.15
Timeline
- 2026-05-28: disclosed
- 2026-05-28: advisory