Executive brief
Oracle iStore is an e-commerce component of Oracle E-Business Suite used to manage online shopping and transactions. An unauthenticated attacker can exploit a vulnerability in the Shopping Cart module over the network to gain unauthorized access to sensitive business data without requiring authentication or user interaction. Successful exploitation could lead to complete data exposure or account compromise for all customers and transactions managed through the iStore platform.
Technical details
This is an unauthenticated information disclosure vulnerability in the Shopping Cart component of Oracle iStore (versions 12.2.3–12.2.15). The vulnerability can be exploited remotely over HTTP without requiring authentication, credentials, or any special privileges. An attacker can access sensitive data including customer information, transaction records, and critical business data accessible through the iStore application. The attack has no user interaction requirement and is easily exploitable due to a logical flaw in access controls. Oracle has published a security advisory addressing this issue, and patches should be obtained from Oracle's security updates.
Affected products
- Oracle E-Business Suite iStore 12.2.3 through 12.2.15
Timeline
- 2026-09-15: disclosed