Oracle EDI Gateway: data exposure via Internal Operations
Low1.9CVE-2026-61303 · Published Jul 21, 2026 · updated Aug 11, 2026
Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle EDI Gateway executes to compromise Oracle EDI Gateway. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle EDI Gateway accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Oracle EDI Gateway Product | >= 12.2.3, <= 12.2.15 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-200
More Oracle advisories
All Oracle| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 21 | Oracle HRMS (US): takeover via Internal Operations | High7.8 | No fix yet |
| Jul 21 | Oracle HRMS (US): data exposure via Internal Operations | Medium6.5 | No fix yet |
| Jul 21 | Oracle Work in Process: data tampering via Internal Operations | Medium5.4 | No fix yet |
| Jul 21 | Oracle HRMS (US): data tampering via US Payroll Year End | High7.1 | No fix yet |
| Jul 21 | Oracle HRMS (UK): data exposure via UK Payroll | High7.7 | No fix yet |
| Jul 21 | Oracle Java SE: takeover via Install | High7.8 | No fix yet |