Description
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iStore accessible data as well as unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Data Integrity and Confidentiality Compromise
Action: Monitor
AI Analysis

Impact

The flaw in Oracle iStore’s Shopping Cart allows a low‑privileged attacker with network access to issue HTTP requests that can create, delete, or modify critical data. The vulnerability is an access‑control weakness (CWE‑284) that exposes the system to unauthorized data modification. The description indicates that the attack requires a human interaction from a person other than the attacker; this requirement is inferred from the wording and is not explicitly stated in the data.

Affected Systems

Oracle Corporation’s Oracle iStore, component Shopping Cart in Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 that accept HTTP traffic. The issue is confined to the Shopping Cart service, but the CVSS vector notes a scope change, meaning compromise of the Shopping Cart could allow lateral movement into other parts of the suite.

Risk and Exploitability

With a CVSS 3.1 base score of 8.7, the vulnerability is high severity. The EPSS score of less than 1% indicates a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require the attacker to reach the HTTP endpoint, possess low‑privilege credentials, and persuade or trick a user to interact with the system. If successful, the attacker can alter or delete critical data, compromising confidentiality and integrity broadly across the Oracle iStore environment.

Generated by OpenCVE AI on September 20, 2026 at 10:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check Oracle’s security alerts page for any updated patches or interim mitigations for the 12.2.3‑12.2.15 releases and apply them as soon as they become available.
  • Restrict direct HTTP access to the Shopping Cart service by limiting traffic to trusted internal networks or enforcing VPN access, effectively reducing the attack surface.
  • Review and tighten access controls so that only accounts with the minimum required privileges can interact with the Shopping Cart, and audit user activity for unexpected data modification patterns.

Generated by OpenCVE AI on September 20, 2026 at 10:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle iStore Shopping Cart

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle iStore Shopping Cart

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iStore accessible data as well as unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle istore
CPEs cpe:2.3:a:oracle:istore:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle istore
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:18:30.978Z

Reserved: 2026-08-31T15:40:57.342Z

Link: CVE-2026-83135

cve-icon Vulnrichment

Updated: 2026-09-17T14:58:46.391Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T20:18:24.190

Modified: 2026-09-17T16:18:04.423

Link: CVE-2026-83135

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T10:30:17Z

Weaknesses