Executive brief
A vulnerability exists in the Internal Operations component of Oracle Transportation Execution, a logistics management tool within the Oracle E-Business Suite. An attacker with low-level access could trick another user into performing an action that allows the attacker to view, modify, or delete certain transportation data. This could lead to unauthorized changes in logistics records or the exposure of sensitive shipping information.
Technical details
This vulnerability affects the Internal Operations component of Oracle Transportation Execution (versions 12.2.3 through 12.2.15). It is classified as a scope-changing vulnerability, likely indicating a Cross-Site Scripting (XSS) or similar web-based injection flaw, as it requires human interaction (UI:R) and results in a scope change (S:C). An attacker with low privileges (PR:L) can exploit this over the network via HTTP. Successful exploitation allows for unauthorized read, update, insert, or delete access to a subset of data within the application and potentially impacts other products within the E-Business Suite environment. Oracle addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle Corporation Oracle Transportation Execution 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed: CVE-2026-60957 was publicly disclosed.