Description
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Trade Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Trade Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Claim LOV component of Oracle Trade Management permits low‑privileged users, who can reach the system via HTTP, to create, delete, or modify critical data and to read data that should be restricted. The vulnerability is classified as an access control issue, reflected by CWE‑284, and results in significant confidentiality and integrity compromise as indicated by a CVSS v3.1 base score of 8.1.

Affected Systems

Oracle Corporation’s Oracle Trade Management product within Oracle E‑Business Suite is affected. The flaw applies to all supported versions from 12.2.3 through 12.2.15.

Risk and Exploitability

The relatively high CVSS score signals substantial risk, but the EPSS score of less than 1% suggests that, at present, exploitation attempts are unlikely. The vulnerability is not listed in CISA KEV. Attackers would require network access to the exposed HTTP interface and only low privileges, making the exploitation straightforward once containment controls are bypassed.

Generated by OpenCVE AI on August 4, 2026 at 02:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s CPU patch for Trade Management 12.2.3–12.2.15 as issued in the July 2026 security alert.
  • Restrict HTTP traffic to the Trade Management instance to trusted network zones or administrators only.
  • Enforce least‑privilege and disable or restrict the Claim LOV functionality for untrusted users until a patch is applied.

Generated by OpenCVE AI on August 4, 2026 at 02:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Access Control Failure in Oracle Trade Management Claim LOV

Thu, 30 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Access Control Failure in Oracle Trade Management Claim LOV

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low-Privilege HTTP in Oracle Trade Management
Weaknesses CWE-285

Sat, 25 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Low-Privilege HTTP in Oracle Trade Management
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Trade Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Trade Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle trade Management
CPEs cpe:2.3:a:oracle:trade_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle trade Management
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Trade Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:40:06.909Z

Reserved: 2026-07-08T15:51:55.598Z

Link: CVE-2026-60875

cve-icon Vulnrichment

Updated: 2026-07-24T17:39:59.893Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-07-21T22:18:24.243

Modified: 2026-07-24T18:18:02.130

Link: CVE-2026-60875

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:45:02Z

Weaknesses