Executive brief
A vulnerability exists in the Collaboration History component of the Oracle Supply Chain Trading Connector, a tool used for managing business-to-business communications in supply chains. An attacker with basic user credentials can remotely access the system to view, modify, or delete sensitive trading data. This could lead to unauthorized changes in supply chain records or a partial disruption of the service.
Technical details
This vulnerability affects the Collaboration History component of Oracle Supply Chain Trading Connector (versions 12.2.3 through 12.2.15). It is classified as an easily exploitable flaw that requires network access via HTTP and low-level user privileges. An attacker can exploit this to gain unauthorized read, update, insert, or delete access to a subset of the application's data. Additionally, the exploit can be used to trigger a partial denial of service (DoS). The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Supply Chain Trading Connector 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory