PT-2025-29598 · Oracle · Oracle Istore

Published

2025-07-15

·

Updated

2025-10-09

·

CVE-2025-30746

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle iStore versions 12.2.3 through 12.2.14
Description A flaw exists in the Shopping Cart component of the Oracle iStore product, which is part of Oracle E-Business Suite. This issue stems from insufficient input validation. A remote, unauthenticated attacker with network access via HTTP can exploit this to compromise Oracle iStore. Successful exploitation requires interaction from an individual other than the attacker, and may impact other products. Successful attacks can lead to unauthorized modification, insertion, or deletion of Oracle iStore data, as well as unauthorized read access to a subset of that data.
Recommendations For versions 12.2.3 through 12.2.14, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-08721
CVE-2025-30746

Affected Products

Oracle Istore