Executive brief
A vulnerability exists in the Oracle EDI Gateway, a component of the Oracle E-Business Suite used for electronic data interchange between businesses. A highly privileged attacker with existing access to the underlying server could potentially view a limited amount of sensitive data. This issue is considered low risk as it requires significant technical access and specific conditions to exploit.
Technical details
This vulnerability affects the Internal Operations component of Oracle EDI Gateway within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is characterized by a low CVSS score due to the high complexity of the attack and the requirement for the attacker to already possess high-level privileges on the local infrastructure where the gateway is running. If successfully exploited, the attacker can achieve unauthorized read access to a limited subset of data accessible by the EDI Gateway. The vulnerability does not impact system integrity or availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle EDI Gateway 12.2.3 - 12.2.15
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle via NVD and security alert.