Executive brief
A vulnerability exists in Oracle Transportation Management, a software suite used by businesses to manage global logistics and supply chain operations. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive shipping and logistics data. This could lead to the theft of proprietary information, unauthorized modification of records, or disruptions to transportation management services.
Technical details
A vulnerability in the CSV Management component of Oracle Transportation Management (version 6.5.3) allows for unauthorized data access and manipulation. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables an attacker to read all accessible data, perform unauthorized updates, inserts, or deletes on certain records, and trigger a partial denial of service (DoS). The vulnerability is tracked as CVE-2026-60584 and was addressed in the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle Transportation Management 6.5.3
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory