Description
Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle SOA Suite’s Integration Business Insight component allows an attacker with low privileges and network access via HTTP to execute code and take full control. The flaw is easily exploitable and can lead to complete compromise of the SOA Suite instance, exposing or altering confidential data and disrupting all services.

Affected Systems

The affected product is Oracle SOA Suite from Oracle Corporation, specifically versions 12.2.1.4.0 and 14.1.2.0.0. These releases are part of the Oracle Fusion Middleware stack.

Risk and Exploitability

The CVSS v3.1 ranking is 8.8 with a vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating a high severity. The EPSS score is less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting that while exploitation is unlikely at present, the low attack effort and network exposure provide an opportunity for attackers. The remote HTTP interface can be targeted by adversaries who already have network reach, without the need for privileged credentials or additional pre‑conditions.

Generated by OpenCVE AI on August 4, 2026 at 03:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle's July 2026 patch for SOA Suite 12.2.1.4.0 and 14.1.2.0.0 to fix the flaw.
  • Limit HTTP exposure by restricting access to the SOA Suite to trusted IP ranges or by placing it behind a firewall and only allowing traffic from authorized networks.
  • If a patch cannot be applied immediately, disable or remove the vulnerable Integration Business Insight component and reconfigure services to prevent unauthenticated access.

Generated by OpenCVE AI on August 4, 2026 at 03:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title HTTP Low-Privilege Exploit Allows Full Compromise of Oracle SOA Suite

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title HTTP Low-Privilege Exploit Allows Full Compromise of Oracle SOA Suite

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306

Mon, 27 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution Vulnerability in Oracle SOA Suite via HTTP
Weaknesses CWE-284

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution Vulnerability in Oracle SOA Suite via HTTP
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle soa Suite
CPEs cpe:2.3:a:oracle:soa_suite:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:soa_suite:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle soa Suite
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Soa Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T14:07:52.194Z

Reserved: 2026-07-08T15:51:40.543Z

Link: CVE-2026-60539

cve-icon Vulnrichment

Updated: 2026-07-24T18:00:15.599Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function