Description
Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Third Party Data Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trading Community. While the vulnerability is in Oracle Trading Community, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Trading Community accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Trading Community, part of Oracle E‑Business Suite, contains a flaw in its Third Party Data Integration component that allows an unauthenticated attacker with network access to HTTP to obtain unauthorized access to critical data or, in the worst case, all data exposed through the product. The vulnerability is easily exploitable and grants the attacker full control over confidentiality of data, with no impact on integrity or availability. The flaw is an authentication bypass combined with improper authorization.

Affected Systems

Affected versions are Oracle Trading Community 12.2.3 through 12.2.15. The vendor is Oracle Corporation. No platforms or operating system details are specified beyond the product identifier.

Risk and Exploitability

The CVSS v3.1 score is 8.6, indicating high severity. The vector indicates a network‑based, low‑complexity attack requiring no privileges, no user interaction, and a changed scope, meaning exploitation may affect other components. The EPSS score is 0.00398 (<1 %) and the vulnerability is not listed in the CISA KEV catalog, indicating a very low exploitation probability but high impact, which warrants close attention. An attacker can trigger the flaw by sending a crafted HTTP request to the affected component, potentially leading to unauthorized data disclosure.

Generated by OpenCVE AI on August 21, 2026 at 11:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch for Oracle Trading Community 12.2.3–12.2.15 as soon as it becomes available.
  • Restrict network access to the Oracle Trading Community application by configuring firewalls and access control lists to allow traffic only from trusted internal hosts or VPNs.
  • Enable and review audit logs for anomalous login or data‑access activity, and set up alerts for unexpected data reads from the affected component.

Generated by OpenCVE AI on August 21, 2026 at 11:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Attack Enables Data Compromise in Oracle Trading Community
Weaknesses CWE-284
CWE-287

Fri, 21 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access Vulnerability via HTTP in Oracle Trading Community
Weaknesses CWE-200
CWE-285
CWE-287

Wed, 19 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access Vulnerability via HTTP in Oracle Trading Community
Weaknesses CWE-200
CWE-285
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Third Party Data Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trading Community. While the vulnerability is in Oracle Trading Community, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Trading Community accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle trading Community
CPEs cpe:2.3:a:oracle:trading_community:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle trading Community
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Trading Community
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T15:25:24.299Z

Reserved: 2026-07-14T14:54:48.744Z

Link: CVE-2026-62599

cve-icon Vulnrichment

Updated: 2026-08-26T13:52:40.636Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:12.197

Modified: 2026-08-31T15:08:52.347

Link: CVE-2026-62599

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T11:30:04Z

Weaknesses