CVE-2026-61314: High severity Oracle Oracle EDI Gateway vulnerability
Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: All Miscellaneous EDI Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle EDI Gateway. Successful attacks of this vulnerability can result in takeover of Oracle EDI Gateway. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61314?
The severity of CVE-2026-61314 is high with a CVSS score of 7.2.
How do I fix CVE-2026-61314?
To fix CVE-2026-61314, apply the latest security patches provided by Oracle for the affected versions of Oracle EDI Gateway.
What versions are affected by CVE-2026-61314?
The versions affected by CVE-2026-61314 are Oracle EDI Gateway versions 12.2.3 to 12.2.15.
What is the impact of CVE-2026-61314?
CVE-2026-61314 allows a high privileged attacker with network access via HTTP to compromise the Oracle EDI Gateway.
Is CVE-2026-61314 easily exploitable?
Yes, CVE-2026-61314 is considered easily exploitable for attackers with network access.