Description
Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Integration Business Insight component of Oracle SOA Suite. An attacker who can reach the system over HTTP and possesses high‑privilege credentials can exploit the weakness, leading to violations of confidentiality, integrity, and availability and ultimately achieving full takeover of the entire SOA Suite instance.

Affected Systems

Oracle SOA Suite versions 12.2.1.4.0 and 14.1.2.0 are affected by the vulnerability.

Risk and Exploitability

The CVSS 3.1 base score of 7.2 reflects a medium‑to‑high severity, with full control possible if successfully exploited. The EPSS score of less than 1% indicates that, as of now, exploitation appears unlikely, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be network‑based HTTP requests to a privileged endpoint within the Integration Business Insight component, and the attacker must already possess high privileges to perform the exploitation.

Generated by OpenCVE AI on August 4, 2026 at 17:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s security patch released in the July 2026 CPU to bring Oracle SOA Suite up to a fixed version.
  • Restrict HTTP access to the SOA Suite installation to trusted networks or enforce strict authentication on the Integration Business Insight component.
  • Disable or remove the Integration Business Insight feature if it is not required for your deployment.

Generated by OpenCVE AI on August 4, 2026 at 17:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle SOA Suite Integration Business Insight Component Leading to Full Compromise

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle SOA Suite Integration Business Insight Component Leading to Full Compromise

Mon, 27 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Oracle SOA Suite Integration Business Insight Remote Code Execution Vulnerability
Weaknesses CWE-284
CWE-78

Mon, 27 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Oracle SOA Suite Integration Business Insight Remote Code Execution Vulnerability
Weaknesses CWE-284
CWE-78

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in takeover of Oracle SOA Suite. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle soa Suite
CPEs cpe:2.3:a:oracle:soa_suite:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:soa_suite:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle soa Suite
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Soa Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T11:12:59.395Z

Reserved: 2026-07-08T15:51:40.543Z

Link: CVE-2026-60546

cve-icon Vulnrichment

Updated: 2026-07-27T11:12:52.707Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management