Description
Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Execution. Successful attacks of this vulnerability can result in takeover of Oracle Transportation Execution. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Internal Operations component of Oracle Transportation Execution, part of Oracle E‑Business Suite. An attacker with low privileges who can reach the application via HTTP can exploit this flaw to compromise the system, resulting in full takeover of the application. The flaw is characterized by a CVSS 3.1 base score of 8.8, with severe confidentiality, integrity and availability impact, and an access vector of network, with low attack complexity and low privileges required.

Affected Systems

Affected versions are Oracle Transportation Execution 12.2.3 through 12.2.15, deployed under Oracle Corporation. The product in question is the Enterprise Business Suite’s transportation execution module, accessed over HTTP. Systems running any of the listed versions are vulnerable if they expose the internal operations component to the network.

Risk and Exploitability

The CVSS score of 8.8 places it in the critical range, whereas the EPSS score of less than 1 % indicates a low probability of observed exploitation, and it is not listed in the CISA KEV catalogue. Nevertheless, the low privilege attack requirement and accessible HTTP interface make the attack scenario straightforward for a motivated adversary. The description specifies that the flaw allows a low‑privileged attacker with network access, implying that authentication is not required for exploitation, and that the vulnerability resides in the internal operations functions, likely due to improper access control.

Generated by OpenCVE AI on August 4, 2026 at 02:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch released in Oracle CPU July 2026 for Transportation Execution 12.2.x to address the internal operations flaw.
  • Restrict or block HTTP access to the Transportation Execution application for non‑authorized IP ranges or enforce strong authentication prior to exposing internal operations.
  • Enable and monitor logging for authentication failures and abnormal activity on the Transportation Execution system to detect potential exploitation attempts.

Generated by OpenCVE AI on August 4, 2026 at 02:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Oracle Transportation Execution Internal Operations Vulnerability Enables Full System Takeover

Thu, 30 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Oracle Transportation Execution Internal Operations Vulnerability Enables Full System Takeover

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Enables Takeover of Oracle Transportation Execution
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Enables Takeover of Oracle Transportation Execution
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Execution. Successful attacks of this vulnerability can result in takeover of Oracle Transportation Execution. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle transportation Execution
CPEs cpe:2.3:a:oracle:transportation_execution:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle transportation Execution
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle E-business Suite Transportation Execution
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:41:47.939Z

Reserved: 2026-07-08T15:51:55.604Z

Link: CVE-2026-60952

cve-icon Vulnrichment

Updated: 2026-07-24T16:41:27.696Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:29.770

Modified: 2026-07-29T15:55:34.953

Link: CVE-2026-60952

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:30:02Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function