Description
Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite. While the vulnerability is in Oracle SOA Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle SOA Suite accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle SOA Suite’s Integration Business Insight component allows an attacker with low privileges and network access via HTTP to obtain unauthorized access to critical data. The vulnerability enables the adversary to read data stored in the SOA environment; because the CVSS vector indicates a scope change, a successful compromise may also affect additional components within the SOA deployment, potentially broadening the data exposure.

Affected Systems

Oracle SOA Suite versions 12.2.1.4.0 and 14.1.2.0.0, as identified by Oracle in their CPU July 2026 advisory, are impacted by this issue.

Risk and Exploitability

The CVSS 3.1 score of 7.7 classifies the vulnerability as high severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and it is not listed in the CISA KEV catalog. An attacker only needs network connectivity to the exposed HTTP endpoint and does not require any special privileges beyond a low‑privilege account, making the exploitation path simple for a network‑reachable adversary.

Generated by OpenCVE AI on August 2, 2026 at 21:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Oracle SOA Suite security patch released in the July 2026 CPU advisory for versions 12.2.1.4.0 and 14.1.2.0.0.
  • Configure network segmentation or firewall rules to restrict HTTP traffic to the Integration Business Insight component so that only trusted networks or hosts can access it.
  • Enforce least privilege by reviewing and limiting permissions granted to all users and service accounts that interact with Oracle SOA Suite.
  • Monitor access logs for the Integration Business Insight component for anomalous activity and investigate any unexpected access patterns.

Generated by OpenCVE AI on August 2, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via Integration Business Insight in Oracle SOA Suite

Tue, 28 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Oracle SOA Suite Unauthorized Data Access via Low‑Privilege HTTP Exploit
Weaknesses CWE-284

Mon, 27 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Oracle SOA Suite Unauthorized Data Access via Low‑Privilege HTTP Exploit
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Integration Business Insight). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SOA Suite. While the vulnerability is in Oracle SOA Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle SOA Suite accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle soa Suite
CPEs cpe:2.3:a:oracle:soa_suite:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:soa_suite:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle soa Suite
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Soa Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T11:14:58.636Z

Reserved: 2026-07-08T15:51:40.544Z

Link: CVE-2026-60548

cve-icon Vulnrichment

Updated: 2026-07-27T11:14:42.422Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:00:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor