CVE-2026-60318: Infoleak
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Patchset Assistant). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Data Integrator executes to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Data Integrator accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60318?
The severity of CVE-2026-60318 is classified as low with a score of 3.3.
How do I fix CVE-2026-60318?
To fix CVE-2026-60318, it is recommended to update to the latest version of Oracle Data Integrator, and apply relevant patches.
What is the impact of CVE-2026-60318?
CVE-2026-60318 can lead to information leakage for low privileged attackers with logon access to the affected infrastructure.
Which versions of Oracle Data Integrator are affected by CVE-2026-60318?
The affected versions of Oracle Data Integrator are 12.2.1.4.0 and 14.1.2.0.0.
Can CVE-2026-60318 be exploited remotely?
CVE-2026-60318 requires the attacker to have logon access to the infrastructure, making it a less likely remote exploit.