Description
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Data Integrator accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Data Integrator’s Patchset Assistant contains a vulnerability that allows a low‑privileged user who has logged into the underlying infrastructure to read restricted data that should be confidential (CWE‑200). The problem is localized to the data integrator component and results in a confidentiality impact only, as reflected in the CVSS vector AV:L/AC:L/PR:L/UI:N/S:U/C:L.

Affected Systems

The affected products are Oracle Data Integrator versions 12.2.1.4.0 and 14.1.2.0.0. These releases are part of Oracle Fusion Middleware and are named Oracle Data Integrator.

Risk and Exploitability

This vulnerability includes information disclosure (CWE‑200), the CVSS base score of 3.3 indicates low severity, and the EPSS score of less than 1% shows a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need local access to the infrastructure where Oracle Data Integrator runs; no remote exploitation capability is specified. Successful exploitation could let an attacker read a subset of data that it normally could not access.

Generated by OpenCVE AI on August 2, 2026 at 22:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch or upgrade to the latest supported version of Oracle Data Integrator 12.2.1.4.0 and 14.1.2.0.0 to eliminate the Patchset Assistant flaw
  • Restrict local account privileges on all servers running Oracle Data Integrator to the minimum required for operation, preventing non‑privileged users from accessing integrator processes
  • Monitor audit logs for unexpected read activity against Oracle Data Integrator components and enforce strict access controls to ensure only authorized users can retrieve sensitive data
  • Encrypt sensitive data stored and transferred by Oracle Data Integrator to mitigate data exposure risks (CWE‑200)

Generated by OpenCVE AI on August 2, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Local Data Disclosure in Oracle Data Integrator Patchset Assistant

Tue, 28 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Low Privilege Read Access in Oracle Data Integrator Patchset Assistant
Weaknesses CWE-284
CWE-285

Fri, 24 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Low Privilege Read Access in Oracle Data Integrator Patchset Assistant
Weaknesses CWE-284
CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Data Integrator accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle data Integrator
CPEs cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:data_integrator:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle data Integrator
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Data Integrator
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:35:26.416Z

Reserved: 2026-07-08T15:51:40.530Z

Link: CVE-2026-60318

cve-icon Vulnrichment

Updated: 2026-07-23T19:35:00.664Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:00:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor