Description
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks of this vulnerability can result in takeover of Oracle Trade Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is located in the Claim LOV component of Oracle Trade Management, part of Oracle E‑Business Suite. It stems from insufficient authorization and authentication controls, allowing an attacker with only low‑privilege network access over HTTP to exploit the flaw. Successful exploitation can lead to loss of confidentiality, integrity and availability, effectively enabling the attacker to take full control of the Oracle Trade Management instance.

Affected Systems

Oracle Corporation’s Oracle Trade Management, versions 12.2.3 through 12.2.15, are affected. These releases are part of the Oracle E‑Business Suite and are vulnerable to the Claim LOV flaw.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 indicates a high‑severity vulnerability with full impact on confidentiality, integrity and availability. The EPSS score is below 1%, suggesting the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the flaw is easily exploitable over HTTP by an attacker who only needs low‑privilege credentials, making it a serious risk for exposed systems. The attack vector is network‑based, with no user interaction required.

Generated by OpenCVE AI on August 4, 2026 at 00:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s latest CPU update for Trade Management, which resolves the Claim LOV vulnerability in all affected releases.
  • Limit HTTP access to the Trade Management instance by configuring firewalls or network ACLs so only trusted networks can reach the service.
  • Enforce strict access controls and ensure users have the minimum privileges necessary, reducing the risk of low‑privilege attackers exploiting the flaw.

Generated by OpenCVE AI on August 4, 2026 at 00:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Takeover via Claim LOV in Oracle Trade Management

Thu, 30 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Takeover via Claim LOV in Oracle Trade Management

Tue, 28 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Unrestricted Access in Claim LOV Allows Low‑Privilege Attacker to Take Over Oracle Trade Management

Sun, 26 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unrestricted Access in Claim LOV Allows Low‑Privilege Attacker to Take Over Oracle Trade Management

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks of this vulnerability can result in takeover of Oracle Trade Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle trade Management
CPEs cpe:2.3:a:oracle:trade_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle trade Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Trade Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T17:41:35.786Z

Reserved: 2026-07-14T14:54:48.731Z

Link: CVE-2026-62447

cve-icon Vulnrichment

Updated: 2026-07-22T17:41:31.483Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:00:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function