CVE-2026-83135
moderateUser-Interaction Data Tampering Flaw in Oracle iStore Shopping Cart (EBS 12.2.3-12.2.15)
Oracle iStore, the e-commerce storefront module of Oracle E-Business Suite, contains an easily exploitable flaw in its Shopping Cart component affecting versions 12.2.3 through 12.2.15. A low-privileged, authenticated attacker with HTTP access to the iStore storefront can trigger the flaw, but successful exploitation requires a victim other than the attacker to interact with the attack (a phishing- or CSRF-style pattern), and the scope change means the impact can extend beyond iStore to additional products. A successful attack yields unauthorized creation, deletion, or modification of critical data and full read access to all data reachable through Oracle iStore. The vulnerability carries a CVSS 3.1 base score of 8.7, reflecting high confidentiality and integrity impacts with no availability impact. No public proof of concept is known and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog, so there is no indication of active exploitation at this time.
What to do: Apply the Oracle Critical Patch Update that addresses this vulnerability to every EBS 12.2 environment running iStore 12.2.3-12.2.15, and verify the storefront is included in your patching scope since optional modules are often missed. Until patched, restrict HTTP access to the iStore storefront to trusted networks or VPN ranges and train users to treat unsolicited links aimed at EBS sessions with suspicion given the required user interaction. Review audit logs for unexpected creation, deletion, or modification of iStore-accessible data to rule out prior exploitation.
| Oracle iStore (Oracle E-Business Suite, Shopping Cart component) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iStore accessible data as well as unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.