Description
Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trading Community. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Trading Community accessible data as well as unauthorized access to critical data or complete access to all Oracle Trading Community accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Party Search UI component of Oracle Trading Community. An attacker with low privileges who can reach the application over HTTP can exploit the interface to create, delete, or modify critical data. Because the flaw allows unauthorized changes to data that is critical to the application, confidentiality and integrity are both severely impacted, with the attacker able to read or alter sensitive information without proper authorization.

Affected Systems

This issue affects Oracle Trading Community for Oracle E‑Business Suite versions 12.2.3 through 12.2.15. The product is delivered by Oracle Corporation under the Oracle Trading Community brand. No earlier or later releases are reported as vulnerable in the supplied information.

Risk and Exploitability

The CVSS 3.1 base score is 8.1, indicating a high‑severity impact. The EPSS score is less than 1 %, so the likelihood of exploitation in the wild at the moment is low, and the vulnerability is not listed in CISA’s KEV catalog. The attack is achievable over a network using standard HTTP, requiring only low privilege credentials, and can lead to unauthorized data modification or deletion.

Generated by OpenCVE AI on August 4, 2026 at 16:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict network access to the Party Search UI by configuring firewalls or VPNs so that only trusted corporate hosts can reach the HTTP interface.
  • Enforce strict user‑level access controls, ensuring that users are granted only the minimum permissions required for their role.
  • Regularly review role assignments to prevent privilege misuse.

Generated by OpenCVE AI on August 4, 2026 at 16:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low-Privilege Party Search Interface in Oracle Trading Community
Weaknesses CWE-284
CWE-862

Tue, 04 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Exploit Enables Unauthorized Data Modification in Oracle Trading Community
Weaknesses CWE-284
CWE-862

Thu, 30 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Exploit Enables Unauthorized Data Modification in Oracle Trading Community
Weaknesses CWE-284
CWE-862

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Party Search UI in Oracle Trading Community
Weaknesses CWE-284

Fri, 24 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Party Search UI in Oracle Trading Community
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Party Search UI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trading Community. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Trading Community accessible data as well as unauthorized access to critical data or complete access to all Oracle Trading Community accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle trading Community
CPEs cpe:2.3:a:oracle:trading_community:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle trading Community
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Trading Community
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:20:58.408Z

Reserved: 2026-07-08T15:51:55.590Z

Link: CVE-2026-60784

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:17.383

Modified: 2026-07-29T15:21:58.963

Link: CVE-2026-60784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:00:13Z

Weaknesses