Description
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass leading to unauthorized data access
Action: Immediate patch
AI Analysis

Impact

A vulnerability exists in Oracle iStore’s Shopping Cart component that permits an unauthenticated attacker who can reach the service over HTTP to obtain access to critical data or all data accessible through the store. The weakness lies in improper access control, allowing unauthorized users to bypass authentication checks and read sensitive information. The impact is a loss of confidentiality, as attackers can retrieve confidential data without credentials.

Affected Systems

Oracle iStore within Oracle E‑Business Suite, specifically supported versions 12.2.3 through 12.2.15.These versions expose the Shopping Cart activity via standard HTTP interfaces and are affected by the flaw.

Risk and Exploitability

The flaw has a CVSS v3.1 base score of 7.5, indicating high severity. The EPSS score is below 1 %, suggesting that while exploitation is technically feasible, it is unlikely to be widely attempted at this time. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is HTTP traffic directed to the iStore web interface; because no authentication is required, an attacker can issue a simple request and immediately extract data.

Generated by OpenCVE AI on September 17, 2026 at 01:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s official patch for iStore 12.2.3–12.2.15 as soon as it is available
  • If a patch is delayed, block external HTTP access to the iStore Shopping Cart endpoints using network firewalls or web‑application firewalls
  • Ensure that the iStore web interface is protected by proper authentication by enforcing HTTPS with client‑side authentication or IP whitelisting

Generated by OpenCVE AI on September 17, 2026 at 01:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Vulnerability in Oracle iStore
Weaknesses CWE-200

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle istore
CPEs cpe:2.3:a:oracle:istore:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle istore
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-16T17:57:06.903Z

Reserved: 2026-08-31T15:40:57.342Z

Link: CVE-2026-83133

cve-icon Vulnrichment

Updated: 2026-09-16T17:52:20.924Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:23.970

Modified: 2026-09-16T19:40:00.317

Link: CVE-2026-83133

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T02:00:10Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control