Description
Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Supply Chain Trading Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Supply Chain Trading Connector accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Supply Chain Trading Connector for Oracle E‑Business Suite suffers an easily exploitable flaw within the Collaboration History component. An attacker with a low level of privileges and network access through HTTP can exploit the bug to read sensitive data or gain full access to all data available in the Connector. The defect poses a high confidentiality impact, as detailed in the CVSS vector.

Affected Systems

All versions of Oracle Supply Chain Trading Connector from 12.2.3 to 12.2.15 are vulnerable. Affected deployments are those running Oracle E‑Business Suite with the Connector service exposed to the network.

Risk and Exploitability

The CVSS base score of 6.5 indicates moderate severity, with confidentiality compromised and no impact on integrity or availability. The EPSS score of < 1% indicates a very low probability of successful exploitation at the time of this analysis, suggesting that the vulnerability is unlikely to be actively targeted. Because the vulnerability is not listed in the CISA KEV catalog, no known active exploitation is reported. Attackers would likely send crafted HTTP requests to the Connector’s Collaboration History endpoint from a low‑privileged or unauthenticated context, granting unauthorized read access to critical data and enabling extraction of proprietary information.

Generated by OpenCVE AI on August 2, 2026 at 20:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle E‑Business Suite patch addressing CVE‑2026‑60812 for the Supply Chain Trading Connector.
  • Configure firewall or network segmentation rules to limit HTTP access to the Connector only to trusted hosts or internal networks.
  • Enforce strict user privilege management, ensuring that low‑privileged accounts do not possess unnecessary access to the Connector’s data or administration interfaces.

Generated by OpenCVE AI on August 2, 2026 at 20:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Collaboration History Flaw Allows Unauthorized Data Access in Oracle Supply Chain Trading Connector

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via HTTP in Oracle Supply Chain Trading Connector
Weaknesses CWE-284

Fri, 24 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via HTTP in Oracle Supply Chain Trading Connector
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Supply Chain Trading Connector product of Oracle E-Business Suite (component: Collaboration History). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Supply Chain Trading Connector. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Supply Chain Trading Connector accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle supply Chain Trading Connector
CPEs cpe:2.3:a:oracle:supply_chain_trading_connector:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle supply Chain Trading Connector
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle E-business Suite Supply Chain Trading Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:15:50.528Z

Reserved: 2026-07-08T15:51:55.592Z

Link: CVE-2026-60812

cve-icon Vulnrichment

Updated: 2026-07-24T15:15:11.381Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:19.670

Modified: 2026-08-07T20:49:52.630

Link: CVE-2026-60812

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:00:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor