Impact
The flaw resides in the Install component of Oracle Transportation Management 6.5.3 and enables a low‑privileged attacker with network access over HTTP to bypass authentication (CWE‑306) and exploit an access‑control weakness (CWE‑284). Successful exploitation grants full control over the entire application, resulting in loss of confidentiality, integrity, and availability, and demonstrates an account permissions policy violation (CWE‑269) as well as authentication failure (CWE‑287).
Affected Systems
Oracle Corporation’s Oracle Transportation Management product, version 6.5.3, is the only version listed as affected. The vulnerability is tied specifically to this build; other versions or patch levels are not reported to be impacted.
Risk and Exploitability
The CVSS v3.1 Base Score of 8.8 signals a high‑severity vulnerability that fully compromises confidentiality, integrity, and availability. The EPSS score of less than 1% suggests that exploitation is infrequent, and the flaw is not cataloged in CISA’s KEV list. Nonetheless, the attack vector is network‑based (HTTP) and requires only low privileges, making the flaw readily exploitable from any host with access to the affected system. Missing authentication and access‑control weaknesses permit immediate takeover of the install interface, leading to a full compromise.
OpenCVE Enrichment