Executive brief
A vulnerability exists in the Oracle EDI Gateway, a component of the Oracle E-Business Suite used for electronic data interchange between businesses. An attacker with basic user credentials can exploit this flaw over the network to gain full access to sensitive business data. This could lead to the unauthorized viewing, modification, or deletion of critical corporate records and transaction data.
Technical details
This vulnerability affects the Internal Operations component of Oracle EDI Gateway within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can achieve high confidentiality and integrity impacts, allowing for the unauthorized creation, deletion, or modification of all data accessible to the EDI Gateway. The vulnerability does not impact system availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle EDI Gateway (Oracle E-Business Suite) 12.2.3 - 12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD record published