Unauthorized Access Vulnerability in Oracle E-Business Suite's Shopping Cart
CVE-2021-2187

8.2HIGH

Key Information:

Vendor
Oracle
Status
Vendor
CVE Published:
22 April 2021

Summary

A vulnerability exists in Oracle iStore within the Oracle E-Business Suite, specifically in the Shopping Cart component. It allows an unauthenticated attacker with network access via HTTP to cause significant security issues. Successful exploitation of this vulnerability requires human interaction from a user other than the attacker. While the vulnerability is specific to Oracle iStore, the implications can extend to other connected products, potentially leading to unauthorized access to sensitive data and capabilities such as altering, inserting, or deleting data within iStore. Organizations using affected versions of Oracle iStore must act promptly to mitigate risks associated with this vulnerability.

Affected Version(s)

iStore 12.1.1-12.1.3

iStore 12.2.3-12.2.10

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.