PatchSiren cyber security CVE debrief
CVE-2026-60572 Oracle Corporation CVE debrief
A vulnerability was found in Oracle E-Business Suite Integrated SOA Gateway. The vulnerability is in the Web Service Provider component. Supported versions that are affected are 12.2.3-12.2.15. The vulnerability can be easily exploited by a low privileged attacker with network access via HTTP, allowing unauthorized update, insert or delete access to some accessible data as well as unauthorized read access to a subset of accessible data and unauthorized ability to cause a partial denial of service of Oracle E-Business Suite Integrated SOA Gateway.
- Vendor
- Oracle Corporation
- Product
- Oracle E-Business Suite Integrated SOA Gateway
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-27
Who should care
Users of Oracle E-Business Suite Integrated SOA Gateway versions 12.2.3-12.2.15 should prioritize patching this vulnerability, as it can be exploited by low privileged attackers with network access via HTTP.
Technical summary
The vulnerability in Oracle E-Business Suite Integrated SOA Gateway has a CVSS 3.1 Base Score of 6.3, indicating a medium severity. The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L). Successful attacks can result in unauthorized update, insert or delete access to some accessible data, unauthorized read access to a subset of accessible data, and unauthorized ability to cause a partial denial of service.
Defensive priority
Medium priority should be given to patching this vulnerability, as it can be exploited by low privileged attackers and has a medium CVSS score.
Recommended defensive actions
- Apply the patch from Oracle as soon as possible
- Review and update access controls for Oracle E-Business Suite Integrated SOA Gateway
- Monitor for suspicious activity on the affected systems
- Consider implementing compensating controls, such as Web Application Firewalls
- Perform a thorough review of the affected system's asset inventory
- Establish a rollback plan in case of issues during patching
- Track the patching process and verify its success
Evidence notes
The CVE record was published on 2026-07-21T22:17:57.487Z and was last modified on 2026-07-27T16:18:06.583Z. The NVD entry is currently Awaiting Analysis. The vulnerability is in the Web Service Provider component of Oracle E-Business Suite Integrated SOA Gateway.
Official resources
-
CVE-2026-60572 CVE record
CVE.org
-
CVE-2026-60572 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:57.487Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.