Executive brief
Oracle Payments is a module of Oracle E-Business Suite used to manage payment processing and transactions. An unauthenticated attacker can remotely exploit a flaw in the File Transmission component to gain unauthorized access to sensitive payment data, potentially compromising customer financial information and transaction records.
Technical details
This vulnerability in Oracle Payments (versions 12.2.3 through 12.2.15) affects the File Transmission component and allows unauthenticated attackers with network access to compromise the system via TCP. The vulnerability is easily exploitable (low complexity, no privileges or user interaction required) and results in high confidentiality impact—attackers can gain unauthorized access to critical payment data accessible within Oracle Payments. The attack vector is network-based. No information on available patches or workarounds is currently available in the advisory.
Affected products
- Oracle E-Business Suite Payments 12.2.3–12.2.15
Timeline
- 2026-08-18: disclosed