Description
Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite. While the vulnerability is in Oracle SOA Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle SOA Suite accessible data as well as unauthorized access to critical data or complete access to all Oracle SOA Suite accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a low‑privilege, network‑accessible weakness in the Integration Business Insight component of Oracle SOA Suite. An attacker who can reach the system over HTTP can overwrite, delete, or create sensitive data without having administrative rights, thereby compromising confidentiality and integrity of all data exposed by the suite. The flaw is not an availability issue but offers an attacker full read/write control over the application’s data store.

Affected Systems

Oracle SOA Suite versions 12.2.1.4.0 and 14.1.2.0.0 are affected. The weakness resides in the Integration Business Insight module of the Fusion Middleware stack.

Risk and Exploitability

The CVSS 3.1 base score of 9.6 classifies this as a critical flaw. The EPSS score of less than 1 % indicates that exploitation is currently rare, yet the high severity keeps the overall risk elevated. The vulnerability is not listed in CISA KEV. Exploitation requires only a low‑privilege attacker capable of sending crafted HTTP requests to reachable endpoints; no special hardware or privileged access is required.

Generated by OpenCVE AI on August 2, 2026 at 22:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the July 2026 Oracle SOA Suite security patch for versions 12.2.1.4.0 and 14.1.2.0.0 as detailed in Oracle’s security update.
  • Limit inbound HTTP traffic to the SOA Suite to trusted internal hosts or VPN‑connected users to reduce exposure.
  • Configure role‑based access controls within SOA Suite to enforce least privilege for low‑privilege accounts.
  • Monitor application logs for suspicious HTTP requests and unauthorized data manipulation attempts.

Generated by OpenCVE AI on August 2, 2026 at 22:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Oracle SOA Suite Integration Component Allows Unprivileged HTTP Attacker to Modify Sensitive Data

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Remote Data Modification via Low Privilege HTTP Access in Oracle SOA Suite

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Remote Data Modification via Low Privilege HTTP Access in Oracle SOA Suite
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite. While the vulnerability is in Oracle SOA Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle SOA Suite accessible data as well as unauthorized access to critical data or complete access to all Oracle SOA Suite accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle soa Suite
CPEs cpe:2.3:a:oracle:soa_suite:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:soa_suite:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle soa Suite
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Soa Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T11:05:04.388Z

Reserved: 2026-07-08T15:51:40.543Z

Link: CVE-2026-60540

cve-icon Vulnrichment

Updated: 2026-07-27T11:04:51.093Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:15:03Z

Weaknesses