Impact
The vulnerability lies in the Shopping Cart component of Oracle iStore. An attacker who is only low‑privileged and can reach the system over HTTP can exploit a flaw that allows the creation, deletion, or modification of data that the attacker should not have access to. Successful exploitation leads to unauthorized access to critical data or total control over all data accessible through Oracle iStore, causing severe confidentiality and integrity compromise.
Affected Systems
The affected product is Oracle iStore, part of Oracle E‑Business Suite. Oracle Corporation offers this as the Shopping Cart component. Versions 12.2.3 through 12.2.15 are reported to be vulnerable. No other versions are listed as affected.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 indicates a high severity vulnerability, scoring confidentiality and integrity impacts but not availability. The EPSS score of less than 1% suggests that, at present, the exploitation rate is low, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw can be triggered from the network over an unauthenticated HTTP channel by a low‑privileged attacker, the potential impact remains high. Attackers likely emerge from remote hosts that can reach the iStore service and are able to take advantage of an authorization bypass or improper access control within the Shopping Cart functionality. Because the vector does not require elevated privileges, the risk escalates if the service is exposed to untrusted networks.
OpenCVE Enrichment