Description
Vulnerability in the Oracle E-Business Suite Integrated SOA Gateway product of Oracle E-Business Suite (component: Web Service Provider). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Suite Integrated SOA Gateway. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle E-Business Suite Integrated SOA Gateway accessible data as well as unauthorized read access to a subset of Oracle E-Business Suite Integrated SOA Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle E-Business Suite Integrated SOA Gateway. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Web Service Provider component of Oracle E‑Business Suite Integrated SOA Gateway and is caused by improper authorization checks, a CWE‑284 authority control weakness. An attacker with low‑privilege credentials and network access via HTTP can execute update, insert, or delete operations on data that should be protected, read restricted data, and trigger a partial denial of service. This results in compromise of the confidentiality, integrity, and availability of the gateway’s data and services.

Affected Systems

Oracle E‑Business Suite Integrated SOA Gateway versions from 12.2.3 through 12.2.15 are vulnerable. The issue applies to all installations of these versions regardless of deployment configuration.

Risk and Exploitability

Based on the description, the likely attack vector is a network‑based HTTP request sent by a low‑privilege user. The CVSS V3.1 score of 6.3 indicates moderate risk, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Successful exploitation would allow data tampering, unauthorized data disclosure, and a partial denial of service of the gateway.

Generated by OpenCVE AI on August 4, 2026 at 17:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 patch for the Integrated SOA Gateway
  • Restrict HTTP access to the gateway by using firewalls or network segmentation so only trusted networks can reach it
  • Enforce least‑privilege access controls for all users interacting with the gateway so that only authorized accounts can modify data

Generated by OpenCVE AI on August 4, 2026 at 17:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial via Improper Authority Control in Oracle E‑Business Suite Integrated SOA Gateway

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote Data Modification in Oracle E‑Business Suite Integrated SOA Gateway
Weaknesses CWE-862

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote Data Modification in Oracle E‑Business Suite Integrated SOA Gateway
Weaknesses CWE-284
CWE-862

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle E-Business Suite Integrated SOA Gateway product of Oracle E-Business Suite (component: Web Service Provider). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle E-Business Suite Integrated SOA Gateway. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle E-Business Suite Integrated SOA Gateway accessible data as well as unauthorized read access to a subset of Oracle E-Business Suite Integrated SOA Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle E-Business Suite Integrated SOA Gateway. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle e-business Suite Integrated Soa Gateway
CPEs cpe:2.3:a:oracle:e-business_suite_integrated_soa_gateway:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle e-business Suite Integrated Soa Gateway
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle E-business Suite Integrated Soa Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T15:13:29.323Z

Reserved: 2026-07-08T15:51:40.545Z

Link: CVE-2026-60572

cve-icon Vulnrichment

Updated: 2026-07-27T15:13:11.504Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:03Z

Weaknesses