Description
Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Execution. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Transportation Execution, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Execution accessible data as well as unauthorized read access to a subset of Oracle Transportation Execution accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Transportation Execution (Oracle E-Business Suite component Internal Operations) contains an access control flaw that allows an attacker with low privileges to modify, insert, or delete data and read restricted data. The weakness is triggered via an HTTP interface and requires user interaction from someone other than the attacker. The impact includes confidentiality and integrity compromise but does not affect availability.

Affected Systems

Affected products are Oracle Corporation’s Oracle Transportation Execution for versions 12.2.3 through 12.2.15.

Risk and Exploitability

The CVSS v3.1 score of 5.4 indicates moderate risk. The very low EPSS score (<1%) and absence from CISA KEV suggest exploitation is unlikely in the wild. However, the vulnerability can be leveraged only after a successful attack involving a low‑privileged user and human interaction, making it a targeted, low‑impact attack vector.

Generated by OpenCVE AI on August 2, 2026 at 20:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Acquire and install the latest Oracle Transportation Execution patch that addresses CVE-2026-60957 from Oracle’s official patch portal.
  • Restart affected services.
  • Restrict HTTP access to the application to trusted, authenticated users and consider placing the system behind a firewall or VPN to reduce exposure.
  • Audit user privileges and disable any unnecessary functions that expose the vulnerable HTTP endpoint.

Generated by OpenCVE AI on August 2, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low-Privilege User in Oracle Transportation Execution

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low-Privilege User in Oracle Transportation Execution
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-285
CWE-352
CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Execution. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Transportation Execution, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Execution accessible data as well as unauthorized read access to a subset of Oracle Transportation Execution accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle transportation Execution
CPEs cpe:2.3:a:oracle:transportation_execution:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle transportation Execution
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oracle Transportation Execution
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T16:39:48.550Z

Reserved: 2026-07-08T15:51:55.604Z

Link: CVE-2026-60957

cve-icon Vulnrichment

Updated: 2026-07-24T16:39:30.835Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-07-21T22:18:29.997

Modified: 2026-07-24T17:17:33.833

Link: CVE-2026-60957

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:30:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-285

    Improper Authorization

  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')