Executive brief
Oracle E-Business Suite Payments is a component handling payment processing and financial transactions for enterprise resource planning systems. An unauthenticated attacker can exploit a vulnerability in the File Transmission component via HTTP to gain unauthorized access to sensitive payment and financial data, including the ability to view, modify, or delete critical information without requiring valid credentials.
Technical details
The vulnerability is an unauthenticated network-accessible flaw in the File Transmission component of Oracle E-Business Suite Payments. An attacker with network access to the HTTP interface can exploit this vulnerability without authentication to achieve unauthorized read and limited write access to payment data. The attack requires no user interaction and has a low attack complexity. Affected versions include Oracle E-Business Suite 12.2.3 through 12.2.15. Oracle has released security updates to remediate this issue.
Affected products
- Oracle E-Business Suite Payments 12.2.3 through 12.2.15
Timeline
- 2026-08-18: disclosed