Impact
The vulnerability is found in the Shopping Cart component of Oracle iStore. The flaw allows a low‑privileged attacker who can reach the system over HTTP to read data that should be restricted, potentially exposing confidential business information. The CVE’s vector indicates a confidentiality impact only, with no demonstrated effects on integrity or availability. Based on the description, it is inferred that the weakness is an Access Control Failure.
Affected Systems
Oracle iStore versions from 12.2.3 to 12.2.15, inclusive, are vulnerable. These releases include the Shopping Cart component of Oracle E‑Business Suite. No other products or components are listed as affected in the CVE data.
Risk and Exploitability
The CVSS 3.1 base score of 5.3 denotes moderate severity, but the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. The attack vector is most likely network‑based via HTTP from a low‑privileged host, exploiting inadequate access‑control checks within the application.
OpenCVE Enrichment