Description
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: CSV Management). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Transportation Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Transportation Management. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).
Published: 2026-07-21
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the CSV Management component of Oracle Transportation Management 6.5.3 that allows a low-privileged attacker with network access via HTTP to read, insert, update or delete critical data and to trigger a partial denial of service. The flaw is classified as an improper access control weakness (CWE-284) and is rated with a CVSS 3.1 base score of 7.6, reflecting high confidentiality impact and lower integrity and availability impacts.

Affected Systems

Oracle Corporation's Oracle Transportation Management product, version 6.5.3, specifically the CSV Management component, is affected.

Risk and Exploitability

The CVSS score indicates a high-severity vulnerability; the EPSS score of < 1% shows exploitation is currently unlikely in the wild, and the issue is not listed in the CISA KEV catalog. The attack vector is inferred to be over standard HTTP access; an attacker only needs network connectivity and a low-privileged account to interact with the vulnerable endpoint. Because the flaw is an improper access control weakness, responsible parties should verify that the system enforces strict role-based permissions and authenticates requests before allowing data manipulation or access.

Generated by OpenCVE AI on August 4, 2026 at 17:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor-provided patch or upgrade to the latest Oracle Transportation Management release that addresses the CSV Management vulnerability.
  • Enforce strict role-based access control so that only authorized roles can read, modify, or delete data via the CSV Management interface, thereby mitigating the improper access control weakness (CWE-284).
  • Restrict network access to the CSV Management service by configuring firewall rules or VPNs to allow only trusted hosts and authenticated users to reach the vulnerable endpoint.

Generated by OpenCVE AI on August 4, 2026 at 17:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Unprivileged Data Access and Partial DoS in Oracle Transportation Management CSV Management

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unprivileged Data Access and Partial DoS in Oracle Transportation Management CSV Management

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Oracle Transportation Management 6.5.3 CSV Management Vulnerability Allows Low‑Privileged HTTP Exploitation for Data Disclosure, Modification and Partial Denial of Service
Weaknesses CWE-284

Thu, 23 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Oracle Transportation Management 6.5.3 CSV Management Vulnerability Allows Low‑Privileged HTTP Exploitation for Data Disclosure, Modification and Partial Denial of Service
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: CSV Management). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Transportation Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Transportation Management. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).
First Time appeared Oracle
Oracle transportation Management
CPEs cpe:2.3:a:oracle:transportation_management:6.5.3:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle transportation Management
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Oracle Transportation Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T15:27:38.136Z

Reserved: 2026-07-08T15:51:40.546Z

Link: CVE-2026-60584

cve-icon Vulnrichment

Updated: 2026-07-27T15:27:34.119Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:15:03Z

Weaknesses