Impact
The vulnerability is a Role‑based Access Control flaw (CWE‑284) in the Xstore Mobile component of Oracle Retail Xstore Point of Service. A low‑privileged user who can log on to the infrastructure where the application runs can exploit the weakness. A successful exploit yields read access to a subset of the application’s data, compromising confidentiality but not integrity or availability.
Affected Systems
Oracle Corporation’s Oracle Retail Xstore Point of Service, version 21.0.3, is the only affected release. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 score of 3.3 indicates the threat is low. The EPSS value of less than 1% shows that exploitation is unlikely in the wild. The vulnerability is not listed in CISA’s KEV catalog. Attack requires physical or local network access to the host and a non‑privileged account; once access is achieved, the attacker can read protected data.
OpenCVE Enrichment