Description
Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Trading Community. Successful attacks of this vulnerability can result in takeover of Oracle Trading Community. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Party Search UI of Oracle Trading Community allows an attacker who already possesses high‑privilege credentials and network access over HTTP to bypass proper access controls. This weakness can be leveraged to alter application state, exposing confidential data and disrupting service. The impact spans confidentiality, integrity, and availability, effectively granting the attacker full control of the platform.

Affected Systems

Oracle Trading Community product, versions 12.2.3 through 12.2.12, is affected. Users of these releases should confirm the exact version they are running to determine exposure.

Risk and Exploitability

The CVSS base score of 7.2 signals a high severity issue, yet the EPSS score of less than 1% indicates a low probability of current exploitation and the vulnerability is not listed in the CISA KEV catalog. Attackers would need high‑privilege credentials and HTTP access to the application, most likely within a trusted network. Successful exploitation of this vulnerability could lead to a full takeover of Oracle Trading Community.

Generated by OpenCVE AI on August 2, 2026 at 21:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle CPU release that contains the Party Search UI patch
  • Restrict HTTP access to the Trading Community application to trusted IP addresses or internal networks
  • Monitor audit logs for unusual Party Search UI activity that may indicate exploitation attempts

Generated by OpenCVE AI on August 2, 2026 at 21:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation in Oracle Trading Community Party Search UI

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title High-Privilege Takeover via Party Search UI in Oracle Trading Community
Weaknesses CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title High-Privilege Takeover via Party Search UI in Oracle Trading Community
Weaknesses CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Trading Community. Successful attacks of this vulnerability can result in takeover of Oracle Trading Community. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle trading Community
CPEs cpe:2.3:a:oracle:trading_community:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle trading Community
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Trading Community
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:23:44.896Z

Reserved: 2026-07-08T15:51:55.585Z

Link: CVE-2026-60734

cve-icon Vulnrichment

Updated: 2026-07-24T15:04:39.207Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-07-21T22:18:13.867

Modified: 2026-07-24T16:16:38.977

Link: CVE-2026-60734

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:15:02Z

Weaknesses