Impact
The vulnerability in Oracle Retail Xstore Point of Service 21.0.3 allows an attacker with low privileges and network connectivity via HTTP to read a limited set of data that should be protected. This occurs due to improper access control, resulting in a confidentiality compromise. The risk of exploitation is moderate, as the required attack vector is openly reachable over HTTP and does not require authentication or elevated privileges.
Affected Systems
Affected system is Oracle Retail Xstore Point of Service (Xstore Mobile) version 21.0.3. The vulnerability is present in the mobile component of the point‑of‑sale application.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate confidentiality impact, and the EPSS score of less than 1% suggests a low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the open HTTP interface from within the network; no additional privileges are required beyond low privileged access, making local network compromise a likely scenario.
OpenCVE Enrichment