Executive brief
Oracle EDI Gateway, a component of the Oracle E-Business Suite used for electronic data interchange between businesses, contains a vulnerability that could allow a complete system takeover. An attacker with high-level administrative privileges can exploit this over the network to gain full control of the gateway. This could lead to the theft of sensitive business data, disruption of supply chain communications, and unauthorized modification of electronic transactions.
Technical details
A vulnerability exists in the 'All Miscellaneous EDI Issues' component of Oracle EDI Gateway within Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw is easily exploitable by a high-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to compromise the integrity, confidentiality, and availability of the EDI Gateway, potentially resulting in a complete takeover of the component. The vulnerability is tracked as CVE-2026-61314 and was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle EDI Gateway 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update (CPU) released