قاعدة الثغرات (CVE)
CVE-2026-46817
إدارة صلاحيات غير سليمة تخترق Oracle Payments في E-Business Suite
حرجةمُستغلة فعليًاKEVالتصحيح متوفر: غير متوفر بعد
مهاجم غير مصادَق لديه وصول HTTP يستطيع اختراق وحدة Oracle Payments والوصول إلى بيانات مالية حساسة. تكرار لنمط استغلال EBS الواسع في 2025.
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
المنتجات المتأثرة
| Product | الإصدارات المتأثرة | تم الإصلاح في |
|---|---|---|
| E-Business Suite | — | — |
التغطية على سيبرانا
—