CVE-2026-62447: High severity Oracle Oracle E-Business Suite - Oracle Trade Management (Claim LOV) vulnerability
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: Claim LOV). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks of this vulnerability can result in takeover of Oracle Trade Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
Oracle Trade Management deployments using the Claim LOV component in supported versions 12.2.3 through 12.2.15 are affected. Exploitation is possible remotely over HTTP.
What does an attacker need to exploit this issue?
An attacker needs network access via HTTP and a low-privileged account. No user interaction is required, and the attack complexity is low.
What is the potential impact of successful exploitation?
A successful attack can result in takeover of Oracle Trade Management, with high impact to confidentiality, integrity, and availability.