Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. The vulnerability is classified as an improper privilege management flaw. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). First reported exploitation observed on June 29 by Defused threat intelligence company on Oracle E-Business honeypots. CISA confirmed active exploitation on July 16 and issued binding operational directive requiring U.S. federal agencies to patch by July 18, 2026.
| Vendor | Product | Versions |
|---|---|---|
| oracle | e-business_suite | 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.9, 12.2.10, 12.2.11, 12.2.12, 12.2.13, 12.2.14, 12.2.15 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| oracle | e-business | cert_advisory | 90% |
Expanded affected versions to full range 12.2.3-12.2.15, added CWE-269 (improper privilege management), and updated description with additional technical context including initial exploitation timeline, Defused discovery, CISA confirmation, and federal patching deadline.
Updated description with new technical details and clarified that the patch is now considered urgent.
Updated description with details on in-the-wild exploitation and added new tag for in-the-wild exploitation.
Updated affected versions to include 12.2.15, marked exploit as available, changed severity to HIGH, and noted no specific IOCs provided.
Updated description with new details on improper privilege management and added tags indicating active exploitation.
Marked exploitAvailable as true, updated patchAvailable to null, and added IoCs from the article.
Updated description with new details about Remote Code Execution and changed exploit availability to false.
Initial creation