Executive brief
Oracle Data Integrator is a platform used by organizations to move and transform large volumes of data across different systems. A security vulnerability in the Studio component allows an individual with low-level access to the underlying server to take full control of the application. This could lead to the unauthorized viewing, modification, or deletion of sensitive business data and a total disruption of data integration workflows.
Technical details
A vulnerability in the Studio component of Oracle Data Integrator (part of Oracle Fusion Middleware) allows for a complete takeover of the product. The flaw is categorized as easily exploitable but requires the attacker to have local logon access to the infrastructure where the software executes. With low-privileged access (PR:L), an attacker can achieve high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H). The vulnerability affects supported versions 12.2.1.4.0 and 14.1.2.0.0. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Data Integrator 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory