Description
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle iStore accessible data as well as unauthorized read access to a subset of Oracle iStore accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published: 2026-07-21
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a broken access control weakness (CWE-284) in the Shopping Cart component of Oracle iStore. An unauthenticated attacker who can reach the system over HTTP may gain the ability to read, insert, update, or delete Oracle iStore data. Successful exploitation requires a third‑party user to trigger the action; the attacker themselves must not perform the triggering step. The flaw can also affect other Oracle E‑Business Suite products that share data sets due to a scope change. The impact is limited to the confidentiality and integrity of the affected data; availability is not directly impacted.

Affected Systems

Affected are Oracle E‑Business Suite Oracle iStore products, specifically the Shopping Cart component in release versions 12.2.3 through 12.2.15. Operators of these versions should confirm whether the site is reachable via HTTP and whether the Shopping Cart function is enabled.

Risk and Exploitability

The CVSS base score of 6.1 indicates moderate severity. An exploitable vector exists over public or internal networks through HTTP, requiring no authentication but necessitating a third‑party user to trigger the action. The EPSS score of less than 1% reflects low current exploitation probability. The vulnerability is not listed in CISA KEV. Because scope can be extended, targeted actors might use it to compromise other related Oracle products.

Generated by OpenCVE AI on August 12, 2026 at 10:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle iStore patch or upgrade to a version newer than 12.2.15.
  • Block HTTP traffic to the Shopping Cart endpoint for unauthenticated users through firewall or reverse‑proxy rules.
  • Disable or remove the Shopping Cart component if it is not required for business operations.

Generated by OpenCVE AI on August 12, 2026 at 10:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Oracle iStore Shopping Cart Data

Tue, 04 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access Control Vulnerability in Oracle iStore Shopping Cart
Weaknesses CWE-200
CWE-284

Sat, 01 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access Control Vulnerability in Oracle iStore Shopping Cart
Weaknesses CWE-200
CWE-284

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Web Access Control Vulnerability in Oracle iStore Shopping Cart
Weaknesses CWE-284

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Web Access Control Vulnerability in Oracle iStore Shopping Cart
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle iStore accessible data as well as unauthorized read access to a subset of Oracle iStore accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
First Time appeared Oracle
Oracle istore
CPEs cpe:2.3:a:oracle:istore:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle istore
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:19:18.115Z

Reserved: 2026-07-08T15:51:55.593Z

Link: CVE-2026-60815

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:19.890

Modified: 2026-07-30T17:37:20.183

Link: CVE-2026-60815

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T11:00:02Z

Weaknesses