Junglewise Threat Intelligence

CVE-2026-60875: Oracle Trade Management unauthorized data access in Claim LOV

CVE-2026-60875 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Trade Management. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in Oracle Trade Management, a component of the Oracle E-Business Suite used by organizations to manage trade promotions and claims. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the unauthorized viewing, modification, or deletion of critical financial and trade records, potentially disrupting business operations and compromising data integrity.

Technical details

This vulnerability affects the Claim LOV (List of Values) component within Oracle Trade Management. It is classified as an unauthorized data access and modification flaw that can be exploited by a low-privileged attacker via the HTTP protocol. The attack vector is network-based and requires no user interaction, making it easily exploitable once an attacker has authenticated to the E-Business Suite environment. Successful exploitation allows for high impact to both confidentiality and integrity, enabling the attacker to read, create, or delete records within the Trade Management module. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Trade Management (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the security alert as part of the July 2026 CPU.
  • 2026-07-21: disclosed

References

Related threats