Executive brief
Oracle iStore is a shopping cart component within Oracle E-Business Suite used for online transactions. A vulnerability in versions 12.2.3 through 12.2.15 allows low-privileged attackers with network access to bypass access controls and view sensitive business data, potentially exposing customer information, order details, and other critical e-commerce data stored within the system.
Technical details
This is an authorization bypass vulnerability in the Shopping Cart component of Oracle iStore that allows low-privileged attackers to access restricted data. The vulnerability is exploitable over HTTP with network access and does not require user interaction. An attacker with low privileges can escalate access to view critical data or complete datasets accessible by iStore, and the scope of impact extends beyond iStore to other connected E-Business Suite components. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N) indicates the vulnerability is easily exploitable with low attack complexity and has high confidentiality impact.
Affected products
- Oracle E-Business Suite iStore 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed