Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle EDI Gateway executes to compromise Oracle EDI Gateway. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle EDI Gateway accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html |
|
History
Sun, 02 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local High‑Privileged Data Read in Oracle EDI Gateway |
Sat, 01 Aug 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle EDI Gateway Local Privileged Data Exposure |
Tue, 28 Jul 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Oracle EDI Gateway Local Privileged Data Exposure |
Wed, 22 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 | |
| Metrics |
ssvc
|
Tue, 21 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle EDI Gateway executes to compromise Oracle EDI Gateway. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle EDI Gateway accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N). | |
| First Time appeared |
Oracle
Oracle edi Gateway |
|
| CPEs | cpe:2.3:a:oracle:edi_gateway:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle edi Gateway |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-07-21T21:39:20.024Z
Updated: 2026-07-22T18:07:27.520Z
Reserved: 2026-07-08T15:52:20.746Z
Link: CVE-2026-61303
Updated: 2026-07-22T18:07:19.455Z
No data.
No data.