Executive brief
Oracle iStore, a component of the Oracle E-Business Suite used for managing online storefronts, contains a vulnerability in its user interface. An attacker can exploit this to gain unauthorized access to sensitive business data or modify existing records. This attack requires a legitimate user to interact with a malicious link or page, and the impact can extend beyond iStore to other connected Oracle products.
Technical details
This vulnerability exists in the User Interface subcomponent of Oracle iStore within Oracle E-Business Suite. It is an unauthenticated, network-based attack (HTTP) that requires human interaction from a victim (UI:R) and results in a Scope change (S:C), indicating the attack can impact components beyond the immediate iStore environment. While the specific vulnerability class is not detailed in the advisory (NVD-CWE-noinfo), the CVSS vector suggests a Cross-Site Scripting (XSS) or similar injection-style flaw that allows an attacker to gain high confidentiality access and low integrity impact. Affected versions include 12.1.1 through 12.2.6. Oracle released patches for this issue in the January 2017 Critical Patch Update.
Affected products
- Oracle iStore 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Oracle January 2017 Critical Patch Update released