Impact
Oracle Transportation Management 6.5.3 is affected by a vulnerability that allows an attacker who can access the system via HTTP and has high privileges to create, modify, or delete critical data. The flaw results in unauthorized access to all data accessible through the application and can be leveraged for complete subversion of the system’s data integrity. The weakness is an improper privilege management issue that elevates the attacker’s privileges beyond what is intended.
Affected Systems
The vulnerability is limited to Oracle Corporation’s Transportation Management product version 6.5.3. No other versions or products were listed as impacted.
Risk and Exploitability
The CVSS 3.1 base score is 6.5, indicating moderate severity. The EPSS score is less than 1 %, so exploitation is considered unlikely in the short term. The vulnerability is not present in the CISA KEV catalogue. The attack vector is inferred to be network‑based via HTTP, requiring the attacker to have high privileges on the target network. If enabled, attackers could potentially read, modify, or delete very sensitive data within the application.
OpenCVE Enrichment