Executive brief
Oracle Payments is a core financial component of Oracle E-Business Suite that handles electronic payment transmission. This vulnerability allows a high-privileged network attacker to bypass access controls in the File Transmission component, potentially reading, modifying, or deleting sensitive payment and financial data, as well as impacting other connected business systems.
Technical details
The vulnerability is a difficult-to-exploit access control weakness in the File Transmission component of Oracle Payments within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It requires network access via HTTP and a high-privileged user context (such as an administrator or system account). The flaw allows an attacker to achieve unauthorized read, write, and delete access to critical financial data within Oracle Payments, and may also impact the confidentiality and integrity of data in other connected E-Business Suite components due to scope change. No public exploit code is currently known to be in active use.
Affected products
- Oracle E-Business Suite Oracle Payments 12.2.3 through 12.2.15
Timeline
- 2026-08-18: disclosed