Impact
An authentication flaw in Oracle Transportation Management allows an attacker with low privileges and network access via HTTP to read a subset of accessible data. The issue does not provide denial of service or escalation beyond read access, limiting the impact to confidentiality only. The CVSS vector indicates low attack complexity while requiring network connectivity and low privilege.
Affected Systems
Oracle Corporation’s Transportation Management product, version 6.5.3, is affected. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS base score of 4.3 indicates a moderate confidentiality impact with low attack complexity and low privilege. The EPSS score of less than 1% signals that the vulnerability is rarely exploited in the wild, and it is not listed in the CISA KEV catalog, so no confirmed attacks are known. An attacker who can access the system over HTTP with low privileges could leverage the flaw to read a subset of Oracle Transportation Management data, making the likelihood of exploitation low but the potential impact (unauthorized data exposure) significant for those handling sensitive information. The risk remains modest, yet the vulnerability should be remediated promptly to prevent accidental data loss.
OpenCVE Enrichment