Executive brief
A vulnerability exists in the Shopping Cart component of Oracle iStore, an e-commerce platform within the Oracle E-Business Suite. An attacker with basic user access could potentially gain unauthorized access to sensitive business data or customer information. While the attack is difficult to perform, a successful exploit could lead to a significant breach of confidential data stored within the system.
Technical details
This vulnerability affects the Shopping Cart component of Oracle iStore within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as a confidentiality-impacting bug that allows a low-privileged attacker with network access via HTTP to compromise the system. The attack complexity is rated as high, suggesting specific conditions or configurations must be met for successful exploitation. If exploited, an attacker can achieve unauthorized access to critical data or complete access to all data accessible by the iStore component. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle iStore 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory