Executive brief
A vulnerability in the Market Place component of Oracle Data Integrator allows a user with low-level access to the underlying system to gain full control over the application's data. This could lead to the unauthorized viewing, modification, or deletion of sensitive business information managed by the integration platform. Because the software interacts with multiple systems, an exploit could also impact other connected corporate products and services.
Technical details
This vulnerability exists in the Market Place component of Oracle Data Integrator (Fusion Middleware). It is classified as a local attack (AV:L) requiring low privileges (PR:L) and no user interaction. The root cause allows an attacker with local infrastructure access to compromise the application, resulting in a scope change (S:C) that may impact additional products. Successful exploitation grants unauthorized access to, or the ability to modify/delete, all data accessible to the Oracle Data Integrator instance. Affected versions include 12.2.1.4.0 and 14.1.2.0.0; users should refer to the Oracle July 2026 Critical Patch Update for remediation.
Affected products
- Oracle Data Integrator 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published