Impact
The flaw in Oracle iStore’s Shopping Cart allows a low‑privileged attacker with network access to issue HTTP requests that can create, delete, or modify critical data. The vulnerability is an access‑control weakness (CWE‑284) that exposes the system to unauthorized data modification. The description indicates that the attack requires a human interaction from a person other than the attacker; this requirement is inferred from the wording and is not explicitly stated in the data.
Affected Systems
Oracle Corporation’s Oracle iStore, component Shopping Cart in Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 that accept HTTP traffic. The issue is confined to the Shopping Cart service, but the CVSS vector notes a scope change, meaning compromise of the Shopping Cart could allow lateral movement into other parts of the suite.
Risk and Exploitability
With a CVSS 3.1 base score of 8.7, the vulnerability is high severity. The EPSS score of less than 1% indicates a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require the attacker to reach the HTTP endpoint, possess low‑privilege credentials, and persuade or trick a user to interact with the system. If successful, the attacker can alter or delete critical data, compromising confidentiality and integrity broadly across the Oracle iStore environment.
OpenCVE Enrichment