Executive brief
A high-severity vulnerability has been identified in the Oracle EDI Gateway, a component of the Oracle E-Business Suite used for electronic data interchange between businesses. An unauthenticated attacker could exploit this flaw over the network to gain full control of the gateway. A successful compromise could lead to the theft of sensitive business data, disruption of supply chain operations, and unauthorized modification of electronic transactions.
Technical details
This vulnerability exists in the 'All Miscellaneous EDI Issues' component of Oracle EDI Gateway. It is exploitable by an unauthenticated attacker with network access via HTTP. While the attack complexity is rated as high, a successful exploit results in a complete compromise of confidentiality, integrity, and availability (takeover of the gateway). The issue affects Oracle E-Business Suite versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Oracle EDI Gateway 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD