Description
Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: All Miscellaneous EDI Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle EDI Gateway. Successful attacks of this vulnerability can result in takeover of Oracle EDI Gateway. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle EDI Gateway, arising from improper access control (CWE-284), allows a high‑privileged attacker with network access over HTTP to take control of the gateway, enabling full compromise of confidentiality, integrity, and availability.

Affected Systems

Oracle EDI Gateway, part of Oracle E‑Business Suite, affected versions 12.2.3 through 12.2.15.

Risk and Exploitability

The CVSS base score is 7.2, indicating high impact when exploited. The EPSS score is below 1 % and the issue is not listed in CISA’s KEV catalog, suggesting a low current exploitation likelihood, but the potential impact is severe. The attack vector is network‑based via HTTP and requires a privileged attacker, making the vulnerability highly exploitative if the gateway is exposed to untrusted networks.

Generated by OpenCVE AI on August 4, 2026 at 00:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle EDI Gateway security patch released by Oracle
  • Restrict HTTP access to the gateway to trusted hosts or IP ranges
  • Enforce that only legitimate privileged accounts are used and consider disabling accounts that are not required for normal operation

Generated by OpenCVE AI on August 4, 2026 at 00:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title High-Privilege EDI Gateway HTTP Compromise

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title High-Privilege EDI Gateway HTTP Compromise

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation via HTTP in Oracle EDI Gateway

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation via HTTP in Oracle EDI Gateway

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: All Miscellaneous EDI Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle EDI Gateway. Successful attacks of this vulnerability can result in takeover of Oracle EDI Gateway. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle edi Gateway
CPEs cpe:2.3:a:oracle:edi_gateway:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle edi Gateway
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Edi Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:01:38.606Z

Reserved: 2026-07-08T15:52:20.746Z

Link: CVE-2026-61314

cve-icon Vulnrichment

Updated: 2026-07-22T18:01:34.832Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:00:05Z

Weaknesses