Description
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Market Place). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator. While the vulnerability is in Oracle Data Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Data Integrator accessible data as well as unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in Oracle Data Integrator allows an attacker logged into the host where the software runs to compromise it and perform unauthorized creation, deletion, or modification of critical data. This flaw is an instance of CWE-284 (Improper Access Control) and leads to significant confidentiality and integrity impact, as indicated by the CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N). Successful exploitation lets an attacker access all critical data available through the affected Data Integrator installation. The description does not explicitly state the level of access beyond this scope.

Affected Systems

Oracle Data Integrator versions 12.2.1.4.0 and 14.1.2.0.0 on the Oracle Fusion Middleware stack are affected. These installations run on infrastructure where users have local logon capability; the vulnerability is specific to the Market Place component of the product.

Risk and Exploitability

The CVSS base score of 8.4 denotes high severity, while the EPSS score of less than 1% indicates low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, yet its scope change could impact other Oracle products. Attackers only need low‑privilege local access, making it relatively easy to exploit compared to remote attacks.

Generated by OpenCVE AI on August 4, 2026 at 16:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download the security patch for Oracle Data Integrator from the official Oracle advisory and deploy it to all affected installations.
  • Restrict local account privileges on the infrastructure hosting Oracle Data Integrator to the minimum required for operation.
  • Segregate the Oracle Data Integrator environment from other critical systems and monitor logs for unauthorized data modifications.

Generated by OpenCVE AI on August 4, 2026 at 16:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Local Privileged Account Exploitation Enables Unauthorized Data Modification in Oracle Data Integrator

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Exploit in Oracle Data Integrator Allows Unauthorized Access to Critical Data

Fri, 24 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Exploit in Oracle Data Integrator Allows Unauthorized Access to Critical Data

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Market Place). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator. While the vulnerability is in Oracle Data Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Data Integrator accessible data as well as unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle data Integrator
CPEs cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:data_integrator:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle data Integrator
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Data Integrator
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:24:23.885Z

Reserved: 2026-07-08T15:51:55.583Z

Link: CVE-2026-60723

cve-icon Vulnrichment

Updated: 2026-07-24T15:04:44.049Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:12.363

Modified: 2026-08-03T16:40:20.960

Link: CVE-2026-60723

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:00:13Z

Weaknesses