Executive brief
Oracle Transportation Management, a software suite used by businesses to manage global logistics and supply chain operations, contains a security vulnerability in its authentication component. An authorized user with low-level permissions could exploit this flaw to view sensitive data they are not supposed to see. While the attacker cannot modify or delete information, this could lead to the exposure of private shipping or business records.
Technical details
An authentication vulnerability exists in Oracle Transportation Management (Oracle Supply Chain) version 6.5.3. The flaw is located within the Authentication component and is classified as easily exploitable. A remote attacker with low-privileged credentials can leverage network access via HTTP to bypass intended access controls. Successful exploitation results in unauthorized read access to a subset of data managed by the application. The vulnerability has a CVSS 3.1 base score of 4.3, reflecting a partial impact on confidentiality with no impact on integrity or availability. Patch information is typically found in the Oracle Critical Patch Update (CPU) for July 2026.
Affected products
- Oracle Transportation Management 6.5.3
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle via NVD dataset.
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published.