Vulnerability in Oracle iStore Shopping Cart of Oracle E-Business Suite
CVE-2021-2197

8.2HIGH

Key Information:

Vendor
Oracle
Status
Vendor
CVE Published:
22 April 2021

Summary

The vulnerability in Oracle iStore allows an unauthenticated attacker to exploit the component via HTTP, leading to unauthorized access to sensitive data. Although the exploit requires human interaction from a third party, successful attacks can grant attackers significant access, enabling them to view, modify, or delete critical data within Oracle iStore. This poses risks not only to the iStore itself but also to other interconnected products, emphasizing the need for immediate remediation and security measures.

Affected Version(s)

iStore 12.1.1-12.1.3

iStore 12.2.3-12.2.10

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.