CVE-2026-61303: Infoleak
Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle EDI Gateway executes to compromise Oracle EDI Gateway. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle EDI Gateway accessible data. CVSS 3.1 Base Score 1.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle E-Business Suite - Oracle EDI Gateway (Internal Operations)to a version that resolves this vulnerability.Fixed in 12.2.3-12.2.15
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61303?
The severity of CVE-2026-61303 is classified as low with a score of 1.9.
How do I fix CVE-2026-61303?
To fix CVE-2026-61303, apply the recommended patches provided by Oracle for the affected Oracle EDI Gateway versions.
What is the impact of CVE-2026-61303?
CVE-2026-61303 can lead to an information leak if exploited by a high-privileged attacker with access to the infrastructure.
Which versions of Oracle EDI Gateway are affected by CVE-2026-61303?
The affected versions of Oracle EDI Gateway are 12.2.3 through 12.2.15.
Who is primarily affected by CVE-2026-61303?
Organizations using the affected versions of Oracle EDI Gateway within their Oracle E-Business Suite are primarily at risk.