Executive brief
A vulnerability in Oracle Data Integrator's Patchset Assistant component allows unauthorized individuals to access sensitive information over the network. Oracle Data Integrator is a platform used for high-volume data movement and transformation between different systems. An exploit could lead to the unauthorized disclosure of critical business data or complete access to all data managed by the software.
Technical details
A vulnerability in the Patchset Assistant component of Oracle Data Integrator (part of Oracle Fusion Middleware) allows for unauthorized data access. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation results in a high confidentiality impact, potentially allowing the attacker to read all data accessible to the Oracle Data Integrator instance. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Data Integrator 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published.