Impact
The vulnerability is a broken access control weakness (CWE-284) in the Shopping Cart component of Oracle iStore. An unauthenticated attacker who can reach the system over HTTP may gain the ability to read, insert, update, or delete Oracle iStore data. Successful exploitation requires a third‑party user to trigger the action; the attacker themselves must not perform the triggering step. The flaw can also affect other Oracle E‑Business Suite products that share data sets due to a scope change. The impact is limited to the confidentiality and integrity of the affected data; availability is not directly impacted.
Affected Systems
Affected are Oracle E‑Business Suite Oracle iStore products, specifically the Shopping Cart component in release versions 12.2.3 through 12.2.15. Operators of these versions should confirm whether the site is reachable via HTTP and whether the Shopping Cart function is enabled.
Risk and Exploitability
The CVSS base score of 6.1 indicates moderate severity. An exploitable vector exists over public or internal networks through HTTP, requiring no authentication but necessitating a third‑party user to trigger the action. The EPSS score of less than 1% reflects low current exploitation probability. The vulnerability is not listed in CISA KEV. Because scope can be extended, targeted actors might use it to compromise other related Oracle products.
OpenCVE Enrichment