Executive brief
Oracle Trade Management, a component of the Oracle E-Business Suite used for managing trade promotions and claims, contains a security vulnerability in its Claim List of Values (LOV) component. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the theft, deletion, or modification of critical financial and trade information, potentially disrupting business operations and compromising financial integrity.
Technical details
A vulnerability exists in the Claim LOV component of Oracle Trade Management (part of Oracle E-Business Suite). The flaw is categorized as easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation enables unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all data accessible by the Trade Management module. The vulnerability affects versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Corporation Oracle Trade Management 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Initial publication by Oracle and NVD