Description
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator. While the vulnerability is in Oracle Data Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Data Integrator includes a Patchset Assistant that contains a security weakness. An attacker who has only low‑privilege logon access to the host where Oracle Data Integrator runs can exploit this flaw to bypass normal access controls and read any data the application can access. The vulnerability permits an unauthorized user to obtain confidential information but does not allow changes to the data or the system.

Affected Systems

Oracle Corporation’s Oracle Data Integrator, part of Oracle Fusion Middleware, is affected. The problematic versions are 12.2.1.4.0 and 14.1.2.0.0. These are the only releases explicitly cited in the advisory.

Risk and Exploitability

The CVSS base score of 6.5 marks the issue as medium severity, and the EPSS score of less than 1% indicates it is not yet widely exploited. The vulnerability is not listed in the CISA KEV catalog. Because exploitation requires only local low‑privileged access and the flaw can be used to read all data that the application can reach, the risk to organizations running the affected releases remains significant, especially if local accounts have unconstrained access or the system is exposed to potential local adversaries. The advisory notes a scope change, implying that compromise of Oracle Data Integrator could affect other Oracle products that interact with it.

Generated by OpenCVE AI on August 4, 2026 at 04:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Data Integrator security patch released in the 2026‑07 CPU advisory
  • Limit or eliminate local accounts with low privileges from accessing the Oracle Data Integrator host, or re‑group them to a non‑privileged role
  • If the Patchset Assistant feature can be disabled, temporarily disable it until the patch is deployed

Generated by OpenCVE AI on August 4, 2026 at 04:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Local Low‑Privilege Exploit in Oracle Data Integrator Patchset Assistant Enables Unauthorized Data Access

Thu, 30 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Local Low‑Privilege Exploit in Oracle Data Integrator Patchset Assistant Enables Unauthorized Data Access

Tue, 28 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Attacker Can Compromise Oracle Data Integrator via Patchset Assistant

Fri, 24 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Attacker Can Compromise Oracle Data Integrator via Patchset Assistant

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator. While the vulnerability is in Oracle Data Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle data Integrator
CPEs cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:data_integrator:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle data Integrator
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Data Integrator
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T19:36:10.978Z

Reserved: 2026-07-08T15:51:40.530Z

Link: CVE-2026-60319

cve-icon Vulnrichment

Updated: 2026-07-23T19:35:55.424Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:30:04Z

Weaknesses