Executive brief
Oracle Data Integrator, a tool used for high-performance data movement and transformation, contains a critical security flaw in its Rest Service component. An unauthorized person can use this flaw over the network to take complete control of the system without needing a username or password. This could lead to the theft of sensitive business data, disruption of data processing operations, and a total compromise of the affected server.
Technical details
A critical vulnerability exists in the Rest Service component of Oracle Data Integrator version 14.1.2.0.0. The flaw is categorized by a CVSS 3.1 score of 9.8, indicating it is easily exploitable by an unauthenticated attacker with network access via HTTPS. Successful exploitation allows for a complete takeover of the Oracle Data Integrator instance, impacting confidentiality, integrity, and availability. While the specific CWE is not detailed in the advisory, the 'takeover' description and CVSS vector suggest a remote code execution or severe authentication bypass. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Data Integrator 14.1.2.0.0
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory