Junglewise Threat Intelligence

CVE-2026-60572: Oracle E-Business Suite Integrated SOA Gateway data manipulation in Web Service Provider

CVE-2026-60572 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle E-Business Suite Integrated SOA Gateway, a component used to manage web services and business processes. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive business data. Additionally, an exploit could cause a partial service outage, disrupting normal business operations.

Technical details

A vulnerability in the Web Service Provider component of Oracle E-Business Suite Integrated SOA Gateway (versions 12.2.3 through 12.2.15) allows an authenticated, low-privileged attacker with network access via HTTP to compromise the system. The flaw enables unauthorized read, update, insert, or delete access to a subset of data accessible through the gateway. Furthermore, an attacker can trigger a partial denial of service (DoS) condition. The vulnerability is classified as easily exploitable with a CVSS base score of 6.3. Users are advised to apply the relevant patches from the Oracle Critical Patch Update (CPU) for July 2026.

Affected products

  • Oracle E-Business Suite Integrated SOA Gateway 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References