Executive brief
A vulnerability exists in Oracle Data Integrator, a tool used for high-performance data movement and transformation. An attacker with low-level access to the underlying server can exploit this flaw to gain unauthorized access to sensitive business data. This breach could potentially extend beyond the data integrator itself to impact other connected systems and products within the corporate infrastructure.
Technical details
This vulnerability is located in the Patchset Assistant component of Oracle Data Integrator (ODI). It is classified as an information disclosure issue that allows a low-privileged attacker with local logon access to the infrastructure where ODI executes to compromise the application. The exploit is characterized by a 'scope change' (S:C), meaning the impact can extend to resources beyond the security scope of the vulnerable component. Successful exploitation results in high confidentiality impacts, potentially granting complete access to all data accessible by Oracle Data Integrator. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Data Integrator 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle