Impact
A vulnerability exists in the CSV Management component of Oracle Transportation Management 6.5.3 that allows a low-privileged attacker with network access via HTTP to read, insert, update or delete critical data and to trigger a partial denial of service. The flaw is classified as an improper access control weakness (CWE-284) and is rated with a CVSS 3.1 base score of 7.6, reflecting high confidentiality impact and lower integrity and availability impacts.
Affected Systems
Oracle Corporation's Oracle Transportation Management product, version 6.5.3, specifically the CSV Management component, is affected.
Risk and Exploitability
The CVSS score indicates a high-severity vulnerability; the EPSS score of < 1% shows exploitation is currently unlikely in the wild, and the issue is not listed in the CISA KEV catalog. The attack vector is inferred to be over standard HTTP access; an attacker only needs network connectivity and a low-privileged account to interact with the vulnerable endpoint. Because the flaw is an improper access control weakness, responsible parties should verify that the system enforces strict role-based permissions and authenticates requests before allowing data manipulation or access.
OpenCVE Enrichment