Executive brief
Oracle EDI Gateway, a component of the E-Business Suite used for electronic data interchange between businesses, contains a security vulnerability. An authorized user with low-level permissions can exploit this flaw over the network to view sensitive information they are not supposed to see. While the attacker cannot modify or delete data, this unauthorized access could lead to the exposure of private business communications or transaction details.
Technical details
A vulnerability in the EDI component of Oracle EDI Gateway (Oracle E-Business Suite) allows for unauthorized data disclosure. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation results in unauthorized read access to a subset of data accessible by the EDI Gateway. The vulnerability affects versions 12.2.3 through 12.2.15. The attack does not require user interaction and has no impact on data integrity or service availability.
Affected products
- Oracle EDI Gateway 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle released the July 2026 Critical Patch Update containing this advisory.
- 2026-07-21: disclosed