Description
Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Supply Chain Trading Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Supply Chain Trading Connector accessible data as well as unauthorized update, insert or delete access to some of Oracle Supply Chain Trading Connector accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-07-21
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Oracle Supply Chain Trading Connector product, specifically the Collaboration History component. It allows an unauthenticated attacker with network access via HTTP to read critical data and perform unauthorized updates, insertions, or deletions on data handled by the connector. The CVSS 3.1 base score of 8.2 highlights a high confidentiality impact and a low integrity impact, while availability is not affected. The weakness originates from improper authentication in the HTTP interface.

Affected Systems

All installations of Oracle Supply Chain Trading Connector version 12.2.3 through 12.2.15 are vulnerable. The affected product is the connector component, and no other vendors are listed as impacted.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity, but the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability can be reached remotely over HTTP without authentication, implying that an attacker can compromise sensitive data. Although not listed in CISA’s KEV catalog, the high confidentiality impact warrants prompt remediation to prevent data breach or alteration.

Generated by OpenCVE AI on August 4, 2026 at 02:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Oracle patch or upgrade for Oracle Supply Chain Trading Connector versions 12.2.3 through 12.2.15 as soon as possible.
  • If a patch is not immediately available, restrict HTTP access to the connector by placing it behind a firewall and limiting connectivity to trusted systems only.
  • Implement additional authentication controls on the connector or disable the vulnerable Collaboration History feature until a fix is applied.
  • Monitor logs for suspicious activity on the connector and perform regular vulnerability scans to detect exploitation attempts.

Generated by OpenCVE AI on August 4, 2026 at 02:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enabling Data Compromise in Oracle Supply Chain Trading Connector

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Access and Unauthorized Data Modification in Oracle Supply Chain Trading Connector
Weaknesses CWE-284
CWE-602

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Access and Unauthorized Data Modification in Oracle Supply Chain Trading Connector
Weaknesses CWE-284
CWE-602

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Supply Chain Trading Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Supply Chain Trading Connector accessible data as well as unauthorized update, insert or delete access to some of Oracle Supply Chain Trading Connector accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle supply Chain Trading Connector
CPEs cpe:2.3:a:oracle:supply_chain_trading_connector:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle supply Chain Trading Connector
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle E-business Suite Supply Chain Trading Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-30T13:02:38.827Z

Reserved: 2026-07-08T15:51:55.592Z

Link: CVE-2026-60810

cve-icon Vulnrichment

Updated: 2026-07-28T13:42:58.308Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:19.443

Modified: 2026-08-07T21:06:55.000

Link: CVE-2026-60810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:45:02Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function