Description
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Transportation Management accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-07-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authentication flaw in Oracle Transportation Management allows an attacker with low privileges and network access via HTTP to read a subset of accessible data. The issue does not provide denial of service or escalation beyond read access, limiting the impact to confidentiality only. The CVSS vector indicates low attack complexity while requiring network connectivity and low privilege.

Affected Systems

Oracle Corporation’s Transportation Management product, version 6.5.3, is affected. No other versions are listed as vulnerable.

Risk and Exploitability

The CVSS base score of 4.3 indicates a moderate confidentiality impact with low attack complexity and low privilege. The EPSS score of less than 1% signals that the vulnerability is rarely exploited in the wild, and it is not listed in the CISA KEV catalog, so no confirmed attacks are known. An attacker who can access the system over HTTP with low privileges could leverage the flaw to read a subset of Oracle Transportation Management data, making the likelihood of exploitation low but the potential impact (unauthorized data exposure) significant for those handling sensitive information. The risk remains modest, yet the vulnerability should be remediated promptly to prevent accidental data loss.

Generated by OpenCVE AI on August 4, 2026 at 17:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 patch for Transportation Management 6.5.3
  • Restrict HTTP access to the Transportation Management instance to trusted networks or VPNs
  • Configure authentication to enforce strong passwords or multi‑factor authentication

Generated by OpenCVE AI on August 4, 2026 at 17:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Authentication Weakness Enabling Unauthorized Data Access in Oracle Transportation Management

Tue, 28 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass Grants Unauthorized Data Access in Oracle Transportation Management
Weaknesses CWE-269

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass Grants Unauthorized Data Access in Oracle Transportation Management
Weaknesses CWE-269
CWE-287

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Transportation Management accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle transportation Management
CPEs cpe:2.3:a:oracle:transportation_management:6.5.3:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle transportation Management
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Transportation Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:26:33.321Z

Reserved: 2026-07-08T15:51:40.536Z

Link: CVE-2026-60434

cve-icon Vulnrichment

Updated: 2026-07-24T14:26:25.586Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:30:03Z

Weaknesses