CVE-2026-46817

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Configurations

Configuration 1 (hide)

cpe:2.3:a:oracle:e-business_suite:*:*:*:*:*:*:*:*

History

21 Jul 2026, 10:10

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad en el producto Oracle Payments de Oracle E-Business Suite (componente: File Transmission). Las versiones soportadas que están afectadas son 12.2.3-12.2.15. Una vulnerabilidad fácilmente explotable permite a un atacante no autenticado con acceso de red vía HTTP comprometer Oracle Payments. Ataques exitosos de esta vulnerabilidad pueden resultar en la toma de control de Oracle Payments. Puntuación Base CVSS 3.1 de 9.8 (impactos en Confidencialidad, Integridad y Disponibilidad). Vector CVSS: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

15 Jul 2026, 20:00

Type Values Removed Values Added
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-46817 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-46817 - US Government Resource

15 Jul 2026, 18:16

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-46817 -

04 Jun 2026, 13:45

Type Values Removed Values Added
CPE cpe:2.3:a:oracle:e-business_suite:*:*:*:*:*:*:*:*
References () https://www.oracle.com/security-alerts/cspumay2026.html - () https://www.oracle.com/security-alerts/cspumay2026.html - Vendor Advisory
First Time Oracle
Oracle e-business Suite

29 May 2026, 16:16

Type Values Removed Values Added
CWE CWE-287
CWE-269
CWE-306

28 May 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 21:16

Updated : 2026-07-21 10:10


NVD link : CVE-2026-46817

Mitre link : CVE-2026-46817

CVE.ORG link : CVE-2026-46817


JSON object : View

Products Affected

oracle

  • e-business_suite
CWE
CWE-269

Improper Privilege Management

CWE-287

Improper Authentication

CWE-306

Missing Authentication for Critical Function