Description
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Integration). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Transportation Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Transportation Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Transportation Management 6.5.3 is affected by a vulnerability that allows an attacker who can access the system via HTTP and has high privileges to create, modify, or delete critical data. The flaw results in unauthorized access to all data accessible through the application and can be leveraged for complete subversion of the system’s data integrity. The weakness is an improper privilege management issue that elevates the attacker’s privileges beyond what is intended.

Affected Systems

The vulnerability is limited to Oracle Corporation’s Transportation Management product version 6.5.3. No other versions or products were listed as impacted.

Risk and Exploitability

The CVSS 3.1 base score is 6.5, indicating moderate severity. The EPSS score is less than 1 %, so exploitation is considered unlikely in the short term. The vulnerability is not present in the CISA KEV catalogue. The attack vector is inferred to be network‑based via HTTP, requiring the attacker to have high privileges on the target network. If enabled, attackers could potentially read, modify, or delete very sensitive data within the application.

Generated by OpenCVE AI on August 2, 2026 at 22:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 patch that addresses this issue for Transportation Management 6.5.3.
  • Restrict HTTP access to the TMS application to a known set of trusted IP addresses or place the service behind a secure VPN.
  • Enforce least privilege on the application user accounts running the TMS services.
  • Enable comprehensive logging of authentication and privilege‑related events, and monitor for anomalous activity.

Generated by OpenCVE AI on August 2, 2026 at 22:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
Title High-Privilege Data Modification via Improper Access Control in Oracle Transportation Management 6.5.3

Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title High‑Privilege Remote Exploitation in Oracle Transportation Management 6.5.3 via HTTP
Weaknesses CWE-269
CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title High‑Privilege Remote Exploitation in Oracle Transportation Management 6.5.3 via HTTP
Weaknesses CWE-269
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Integration). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Transportation Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Transportation Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle transportation Management
CPEs cpe:2.3:a:oracle:transportation_management:6.5.3:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle transportation Management
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Transportation Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:32:34.816Z

Reserved: 2026-07-08T15:51:40.536Z

Link: CVE-2026-60433

cve-icon Vulnrichment

Updated: 2026-07-24T15:32:30.451Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:30:04Z

Weaknesses