Vulnerability in Oracle E-Business Suite Integrated SOA Gateway
CVE-2026-60572

6.3MEDIUM

What is CVE-2026-60572?

A security flaw in Oracle E-Business Suite Integrated SOA Gateway enables low-privileged attackers with network access via HTTP to exploit the vulnerability. This exploitation can lead to unauthorized actions including updates, inserts, or deletions of accessible data. Moreover, attackers might achieve unauthorized read access to a subset of data and potentially trigger partial denial-of-service, thereby affecting the service reliability of Oracle E-Business Suite Integrated SOA Gateway.

Affected Version(s)

Oracle E-Business Suite Integrated SOA Gateway 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.