Description
Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle EDI Gateway. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle EDI Gateway accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Oracle EDI Gateway component enables a low‑privileged attacker with network access over HTTP to read a subset of data that should be restricted. The vulnerability is classified as a confidentiality compromise, mapped to CWE‑200, highlighting insufficient protection of information.

Affected Systems

The affected product is Oracle EDI Gateway, part of Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are impacted. These versions are provided by Oracle Corporation.

Risk and Exploitability

The CVSS 3.1 base score of 4.3 indicates low‑to‑moderate severity, focusing on confidentiality. The EPSS score is less than 1%, showing a low likelihood of widespread exploitation; the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is network traffic over HTTP, requiring only low‑privileged or unauthenticated access to the network segment hosting the gateway. The exploitation path does not require elevated privileges or complex prerequisites, making it achievable by remote attackers who can reach the service.

Generated by OpenCVE AI on August 4, 2026 at 15:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for CVE-2026-61315 released in the July 2026 CPU advisory.
  • Restrict HTTP access to the Oracle EDI Gateway with firewall rules or VPN so only trusted IP ranges can reach the service.
  • Enable detailed logging and set alerts for read operations on sensitive EDI data to detect unauthorized access attempts.

Generated by OpenCVE AI on August 4, 2026 at 15:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title HTTP Access Data Exposure in Oracle EDI Gateway

Sun, 02 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title HTTP Access Data Exposure in Oracle EDI Gateway

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Oracle EDI Gateway Unauthorized Data Read Vulnerability

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Oracle EDI Gateway Unauthorized Data Read Vulnerability

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle EDI Gateway. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle EDI Gateway accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle edi Gateway
CPEs cpe:2.3:a:oracle:edi_gateway:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle edi Gateway
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Edi Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:02:19.866Z

Reserved: 2026-07-08T15:52:20.747Z

Link: CVE-2026-61315

cve-icon Vulnrichment

Updated: 2026-07-22T18:02:15.690Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:00:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor