Executive brief
Oracle iStore, the e-commerce component of the Oracle E-Business Suite, contains a vulnerability in its Shopping Cart module. An attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete certain shopping cart data. This could lead to unauthorized changes to customer orders or the exposure of private shopping information.
Technical details
A vulnerability in the Oracle iStore component of Oracle E-Business Suite (specifically the Shopping Cart module) allows an unauthenticated remote attacker to impact the confidentiality and integrity of the system. The flaw is exploitable via HTTP and requires human interaction from a person other than the attacker (User Interaction: Required). The vulnerability features a 'Scope Change,' meaning an exploit can impact components beyond the immediate iStore environment. Successful exploitation can result in unauthorized read, update, insert, or delete access to a subset of iStore data. Affected versions include 12.2.3 through 12.2.15.
Affected products
- Oracle iStore 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update published