ZeroHour

CVE-2026-83135

moderate

User-Interaction Data Tampering Flaw in Oracle iStore Shopping Cart (EBS 12.2.3-12.2.15)

CVSS 3.1
8.7 high
EPSS
Published
()
Modified
AI analysis

Oracle iStore, the e-commerce storefront module of Oracle E-Business Suite, contains an easily exploitable flaw in its Shopping Cart component affecting versions 12.2.3 through 12.2.15. A low-privileged, authenticated attacker with HTTP access to the iStore storefront can trigger the flaw, but successful exploitation requires a victim other than the attacker to interact with the attack (a phishing- or CSRF-style pattern), and the scope change means the impact can extend beyond iStore to additional products. A successful attack yields unauthorized creation, deletion, or modification of critical data and full read access to all data reachable through Oracle iStore. The vulnerability carries a CVSS 3.1 base score of 8.7, reflecting high confidentiality and integrity impacts with no availability impact. No public proof of concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so there is no indication of active exploitation at this time.

What to do: Apply the Oracle Critical Patch Update that addresses this vulnerability to every EBS 12.2 environment running iStore 12.2.3-12.2.15, and verify the storefront is included in your patching scope since optional modules are often missed. Until patched, restrict HTTP access to the iStore storefront to trusted networks or VPN ranges and train users to treat unsolicited links aimed at EBS sessions with suspicion given the required user interaction. Review audit logs for unexpected creation, deletion, or modification of iStore-accessible data to rule out prior exploitation.

Affected
Oracle iStore (Oracle E-Business Suite, Shopping Cart component)12.2.3-12.2.15
Estimated exposure
moderatelow thousands of potentially internet-facing iStore deployments (a subset of the tens of thousands of Oracle E-Business Suite installations worldwide) — Oracle EBS runs at tens of thousands of enterprises and iStore is an optional storefront module; public internet scans typically show only a few thousand exposed EBS web endpoints, and only a fraction of those run iStore.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iStore accessible data as well as unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.