Description
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-07-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is found in the Shopping Cart component of Oracle iStore. The flaw allows a low‑privileged attacker who can reach the system over HTTP to read data that should be restricted, potentially exposing confidential business information. The CVE’s vector indicates a confidentiality impact only, with no demonstrated effects on integrity or availability. Based on the description, it is inferred that the weakness is an Access Control Failure.

Affected Systems

Oracle iStore versions from 12.2.3 to 12.2.15, inclusive, are vulnerable. These releases include the Shopping Cart component of Oracle E‑Business Suite. No other products or components are listed as affected in the CVE data.

Risk and Exploitability

The CVSS 3.1 base score of 5.3 denotes moderate severity, but the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. The attack vector is most likely network‑based via HTTP from a low‑privileged host, exploiting inadequate access‑control checks within the application.

Generated by OpenCVE AI on August 4, 2026 at 02:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply all available Oracle iStore updates that address the access‑control flaw, including upgrades to versions beyond 12.2.15.
  • Restrict HTTP access to the iStore application by configuring firewalls or web‑application firewall rules to limit traffic to trusted hosts only.
  • Enforce strict user privileges so that low‑privileged accounts cannot read sensitive data exposed by the Shopping Cart component.

Generated by OpenCVE AI on August 4, 2026 at 02:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthorized data access via HTTP in Oracle iStore Shopping Cart
Weaknesses CWE-284

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Exposure in Oracle iStore Shopping Cart
Weaknesses CWE-284

Fri, 24 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Exposure in Oracle iStore Shopping Cart
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle istore
CPEs cpe:2.3:a:oracle:istore:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle istore
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:19:11.680Z

Reserved: 2026-07-08T15:51:55.593Z

Link: CVE-2026-60816

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:20.003

Modified: 2026-07-30T17:37:30.050

Link: CVE-2026-60816

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:45:02Z

Weaknesses