Description
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in Oracle Data Integrator's Patchset Assistant component permits an unauthenticated attacker with network access via HTTP to gain unauthorized access to all data exposed by the application. The flaw results in data confidentiality compromise, with the attacker able to read or modify critical information without requiring prior authentication. This exposure is due to an access control weakness that allows unrestricted entry to privileged functionality. The impact is limited to confidentiality, but the potential loss of sensitive data can be significant for organizations relying on Oracle Data Integrator for data integration and processing workflows.

Affected Systems

Oracle Corporation's Data Integrator product in the Oracle Fusion Middleware suite is affected. Supported versions that contain the vulnerability are 12.2.1.4.0 and 14.1.2.0.0. If your environment runs either of these releases, the product is susceptible to exploitation until a security update is applied.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 reflects a moderate to high risk, driven by the high confidentiality impact. The EPSS score of less than 1% indicates that, while the vulnerability exists, the probability of public exploitation remains low at present. It is not listed in the CISA KEV catalog, suggesting no known widespread active exploitation. However, the attacker does not require any privileges or special configuration; a simple HTTP request to the vulnerable endpoint is sufficient. Organizations with open network exposure to Oracle Data Integrator should consider that exploitation could occur quickly if the vulnerability is discovered and a tool is released.

Generated by OpenCVE AI on August 4, 2026 at 04:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Data Integrator 12.2.1.4.0 and 14.1.2.0.0 from the referenced Oracle CPU for July 2026. This patch removes the unauthenticated access flaw in Patchset Assistant.
  • Restrict HTTP access to the Data Integrator service by configuring firewall rules or network segmentation so that only trusted internal hosts can reach the service.
  • Enable or enforce authentication mechanisms for all Data Integrator endpoints, ensuring that access requires valid credentials before any data can be retrieved or modified.

Generated by OpenCVE AI on August 4, 2026 at 04:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access to Oracle Data Integrator Allows Unauthorized Data Access

Thu, 30 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access to Oracle Data Integrator Allows Unauthorized Data Access

Tue, 28 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Data Access in Oracle Data Integrator via Patchset Assistant

Fri, 24 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Data Access in Oracle Data Integrator via Patchset Assistant
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle data Integrator
CPEs cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:data_integrator:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle data Integrator
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Data Integrator
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T14:07:51.905Z

Reserved: 2026-07-08T15:51:40.530Z

Link: CVE-2026-60320

cve-icon Vulnrichment

Updated: 2026-07-23T18:47:40.615Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T04:30:04Z

Weaknesses