PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60572 Oracle Corporation CVE debrief

A vulnerability was found in Oracle E-Business Suite Integrated SOA Gateway. The vulnerability is in the Web Service Provider component. Supported versions that are affected are 12.2.3-12.2.15. The vulnerability can be easily exploited by a low privileged attacker with network access via HTTP, allowing unauthorized update, insert or delete access to some accessible data as well as unauthorized read access to a subset of accessible data and unauthorized ability to cause a partial denial of service of Oracle E-Business Suite Integrated SOA Gateway.

Vendor
Oracle Corporation
Product
Oracle E-Business Suite Integrated SOA Gateway
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-27
Advisory published
2026-07-21
Advisory updated
2026-07-27

Who should care

Users of Oracle E-Business Suite Integrated SOA Gateway versions 12.2.3-12.2.15 should prioritize patching this vulnerability, as it can be exploited by low privileged attackers with network access via HTTP.

Technical summary

The vulnerability in Oracle E-Business Suite Integrated SOA Gateway has a CVSS 3.1 Base Score of 6.3, indicating a medium severity. The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L). Successful attacks can result in unauthorized update, insert or delete access to some accessible data, unauthorized read access to a subset of accessible data, and unauthorized ability to cause a partial denial of service.

Defensive priority

Medium priority should be given to patching this vulnerability, as it can be exploited by low privileged attackers and has a medium CVSS score.

Recommended defensive actions

  • Apply the patch from Oracle as soon as possible
  • Review and update access controls for Oracle E-Business Suite Integrated SOA Gateway
  • Monitor for suspicious activity on the affected systems
  • Consider implementing compensating controls, such as Web Application Firewalls
  • Perform a thorough review of the affected system's asset inventory
  • Establish a rollback plan in case of issues during patching
  • Track the patching process and verify its success

Evidence notes

The CVE record was published on 2026-07-21T22:17:57.487Z and was last modified on 2026-07-27T16:18:06.583Z. The NVD entry is currently Awaiting Analysis. The vulnerability is in the Web Service Provider component of Oracle E-Business Suite Integrated SOA Gateway.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:57.487Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.