Impact
A vulnerability in the Shopping Cart component of Oracle iStore allows an attacker who already holds high‑privileged credentials to perform arbitrary actions over HTTP, potentially leading to takeover of the entire application. The flaw is classified as a high‑severity issue, with a CVSS 3.1 base score of 7.2 that impacts confidentiality, integrity, and availability. Successful exploitation would give the attacker full control over the Oracle iStore system, enabling data exfiltration, modification, or service disruption.
Affected Systems
The affected system is Oracle iStore Shopping Cart, part of Oracle E‑Business Suite. Supported versions from 12.2.3 through 12.2.15 are vulnerable. These releases are actively supported and receive security updates.
Risk and Exploitability
The CVSS score of 7.2 indicates a significant impact, but the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based HTTP request originating from an entity that has obtained high‑privileged credentials; it is inferred that the flaw is accessed over an authenticated HTTP connection. Internal attackers or compromised administrative accounts pose the greatest threat, especially in environments without strict network segmentation or restrictive access controls.
OpenCVE Enrichment