Executive brief
Oracle iStore, a component of the Oracle E-Business Suite used for managing online storefronts and shopping carts, contains a vulnerability that could allow an authorized user with high-level privileges to take full control of the application. An attacker could exploit this to access sensitive customer data, modify store configurations, or disrupt online sales operations. This issue affects versions 12.2.3 through 12.2.15 of the software.
Technical details
A vulnerability in the Shopping Cart component of Oracle iStore (part of Oracle E-Business Suite) allows for a complete compromise of the application. The flaw is easily exploitable by a high-privileged attacker with network access via HTTP. Successful exploitation results in a total loss of confidentiality, integrity, and availability (takeover of the iStore instance). The vulnerability affects supported versions 12.2.3 through 12.2.15. While the specific CWE is not detailed in the advisory, the impact is categorized as a full application takeover. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle iStore 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication