Security Vulnerability in Oracle iStore Shopping Cart Product by Oracle
CVE-2021-2182

8.2HIGH

Key Information:

Vendor
Oracle
Status
Vendor
CVE Published:
22 April 2021

Summary

The vulnerability in Oracle iStore within Oracle E-Business Suite allows unauthenticated access via HTTP. Attackers can exploit this weakness to gain unauthorized control over critical data by requiring human interaction from an unwitting user. This can lead to significant security risks, including the potential for unauthorized updates, deletions, or insertions of sensitive data. The impact of this vulnerability extends beyond iStore, affecting other integrated components significantly.

Affected Version(s)

iStore 12.1.1-12.1.3

iStore 12.2.3-12.2.10

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.