Description
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in takeover of Oracle Transportation Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Install component of Oracle Transportation Management 6.5.3 and enables a low‑privileged attacker with network access over HTTP to bypass authentication (CWE‑306) and exploit an access‑control weakness (CWE‑284). Successful exploitation grants full control over the entire application, resulting in loss of confidentiality, integrity, and availability, and demonstrates an account permissions policy violation (CWE‑269) as well as authentication failure (CWE‑287).

Affected Systems

Oracle Corporation’s Oracle Transportation Management product, version 6.5.3, is the only version listed as affected. The vulnerability is tied specifically to this build; other versions or patch levels are not reported to be impacted.

Risk and Exploitability

The CVSS v3.1 Base Score of 8.8 signals a high‑severity vulnerability that fully compromises confidentiality, integrity, and availability. The EPSS score of less than 1% suggests that exploitation is infrequent, and the flaw is not cataloged in CISA’s KEV list. Nonetheless, the attack vector is network‑based (HTTP) and requires only low privileges, making the flaw readily exploitable from any host with access to the affected system. Missing authentication and access‑control weaknesses permit immediate takeover of the install interface, leading to a full compromise.

Generated by OpenCVE AI on August 2, 2026 at 21:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Block HTTP access to the installation interface, restricting it to trusted IPs or a VPN.
  • Enforce authentication and role‑based access control for the Install component, mitigating missing authentication (CWE‑306) and access‑control issues (CWE‑284).
  • Enable detailed logging of all installation activity and regularly review logs for abnormal behavior to detect exploitation attempts.

Generated by OpenCVE AI on August 2, 2026 at 21:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title HTTP Install Interface Exploit Grants Full Compromise of Oracle Transportation Management

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Enables Full Compromise of Oracle Transportation Management

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Enables Full Compromise of Oracle Transportation Management
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in takeover of Oracle Transportation Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle transportation Management
CPEs cpe:2.3:a:oracle:transportation_management:6.5.3:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle transportation Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Transportation Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T12:29:55.133Z

Reserved: 2026-07-08T15:51:40.545Z

Link: CVE-2026-60583

cve-icon Vulnrichment

Updated: 2026-07-27T12:29:51.369Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:00:07Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function