Executive brief
A vulnerability exists in the Shopping Cart component of Oracle iStore, an e-commerce platform within the Oracle E-Business Suite. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the theft, deletion, or modification of critical customer and order information, potentially disrupting sales operations and compromising data integrity.
Technical details
This vulnerability affects the Shopping Cart component of Oracle iStore versions 12.2.3 through 12.2.15. It is classified as an improper access control or authorization flaw that can be exploited by a low-privileged attacker with network access via HTTP. The exploit does not require user interaction and has a high impact on both confidentiality and integrity, though it does not impact availability. Attackers can successfully read, modify, or delete any data accessible to the iStore application. Organizations should refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle iStore 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD