Junglewise Threat Intelligence

CVE-2026-62447: Oracle Trade Management compromise in Claim LOV

CVE-2026-62447 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Trade Management. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Trade Management, a component of the Oracle E-Business Suite used by organizations to manage marketing funds and claims. An attacker with basic user access can exploit this flaw to take full control of the Trade Management system. This could lead to the unauthorized access, modification, or deletion of sensitive financial and trade data, potentially disrupting business operations and financial reporting.

Technical details

This vulnerability affects the Claim LOV (List of Values) component within Oracle Trade Management. It is classified as an easily exploitable flaw that requires only low-privileged authentication and network access via HTTP. While the specific CWE is not detailed in the advisory, the impact is rated for full Confidentiality, Integrity, and Availability loss (takeover). The vulnerability exists in versions 12.2.3 through 12.2.15 of the Oracle E-Business Suite. Organizations are advised to apply the relevant patches from the Oracle Critical Patch Update (CPU) for July 2026.

Affected products

  • Oracle Trade Management 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats