Impact
A vulnerability exists in Oracle iStore’s Shopping Cart component that permits an unauthenticated attacker who can reach the service over HTTP to obtain access to critical data or all data accessible through the store. The weakness lies in improper access control, allowing unauthorized users to bypass authentication checks and read sensitive information. The impact is a loss of confidentiality, as attackers can retrieve confidential data without credentials.
Affected Systems
Oracle iStore within Oracle E‑Business Suite, specifically supported versions 12.2.3 through 12.2.15.These versions expose the Shopping Cart activity via standard HTTP interfaces and are affected by the flaw.
Risk and Exploitability
The flaw has a CVSS v3.1 base score of 7.5, indicating high severity. The EPSS score is below 1 %, suggesting that while exploitation is technically feasible, it is unlikely to be widely attempted at this time. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is HTTP traffic directed to the iStore web interface; because no authentication is required, an attacker can issue a simple request and immediately extract data.
OpenCVE Enrichment