Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Third Party Data Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trading Community. While the vulnerability is in Oracle Trading Community, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Trading Community accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Wed, 26 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated HTTP Attack Enables Data Compromise in Oracle Trading Community | |
| Weaknesses | CWE-284 CWE-287 |
Fri, 21 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Access Vulnerability via HTTP in Oracle Trading Community | |
| Weaknesses | CWE-200 CWE-285 CWE-287 |
Wed, 19 Aug 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Access Vulnerability via HTTP in Oracle Trading Community | |
| Weaknesses | CWE-200 CWE-285 CWE-287 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Third Party Data Integration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trading Community. While the vulnerability is in Oracle Trading Community, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Trading Community accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N). | |
| First Time appeared |
Oracle
Oracle trading Community |
|
| CPEs | cpe:2.3:a:oracle:trading_community:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle trading Community |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T21:00:41.078Z
Updated: 2026-08-26T15:25:24.299Z
Reserved: 2026-07-14T14:54:48.744Z
Link: CVE-2026-62599
Updated: 2026-08-26T13:52:40.636Z
Status : Awaiting Analysis
Published: 2026-08-18T21:17:12.197
Modified: 2026-08-26T16:16:33.947
Link: CVE-2026-62599
No data.