Description
Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle EDI Gateway. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle EDI Gateway accessible data as well as unauthorized access to critical data or complete access to all Oracle EDI Gateway accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle EDI Gateway, part of Oracle E-Business Suite, contains a CWE-284 vulnerability that allows a low-privileged attacker with network access over HTTP to compromise the system. Successful exploitation enables the attacker to create, delete, or modify critical data, thereby violating confidentiality and integrity of all data accessible through the gateway. The CVSS 3.1 base score is 8.1, reflecting a high severity level.

Affected Systems

The affected product is Oracle EDI Gateway, an Oracle E-Business Suite component, with versions ranging from 12.2.3 through 12.2.15.

Risk and Exploitability

The vulnerability can be exploited remotely with only network access via HTTP and low privileges, making it relatively easy to attack. The EPSS score of less than 1% indicates a low probability of widespread exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. If exploited, the attacker gains unauthorized creation, deletion, or modification access to all data accessible through the gateway.

Generated by OpenCVE AI on August 4, 2026 at 02:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the CPU July 2026 patch for Oracle EDI Gateway from Oracle’s security site
  • Configure firewalls or ACLs to allow HTTP traffic to the gateway only from trusted IP ranges or through a VPN
  • Disable or restrict any unused HTTP services on the EDI Gateway server and monitor access logs for anomalous activity

Generated by OpenCVE AI on August 4, 2026 at 02:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low-privileged HTTP Access Exploitation in Oracle EDI Gateway

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via HTTP in Oracle EDI Gateway Allows Data Modification

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via HTTP in Oracle EDI Gateway Allows Data Modification
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle EDI Gateway. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle EDI Gateway accessible data as well as unauthorized access to critical data or complete access to all Oracle EDI Gateway accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle edi Gateway
CPEs cpe:2.3:a:oracle:edi_gateway:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle edi Gateway
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Edi Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T19:06:21.699Z

Reserved: 2026-07-08T15:51:55.581Z

Link: CVE-2026-60710

cve-icon Vulnrichment

Updated: 2026-07-24T19:06:16.332Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:00:02Z

Weaknesses