Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html |
|
Fri, 24 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Jul 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authentication Bypass Grants Unauthorized Data Access in Oracle Transportation Management | |
| Weaknesses | CWE-269 CWE-287 |
Tue, 21 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication). The supported version that is affected is 6.5.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Transportation Management accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). | |
| First Time appeared |
Oracle
Oracle transportation Management |
|
| CPEs | cpe:2.3:a:oracle:transportation_management:6.5.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle transportation Management |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-07-24T14:26:33.321Z
Reserved: 2026-07-08T15:51:40.536Z
Link: CVE-2026-60434
Updated: 2026-07-24T14:26:25.586Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-24T00:15:03Z