cbcvebase.

Oracle Istore vulnerabilities

42 known vulnerabilities affecting oracle/istore.

Total CVEs
42
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH32MEDIUM10

Vulnerabilities

Page 2 of 3
CVE-2021-2182P3HIGHCVSS 8.2≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.102021-04-22
CVE-2021-2182 [HIGH] CVE-2021-2182: Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Su Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other th
nvd
CVE-2021-2185P3HIGHCVSS 8.2≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.102021-04-22
CVE-2021-2185 [HIGH] CVE-2021-2185: Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Su Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other th
nvd
CVE-2021-2150P3HIGHCVSS 8.2≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.102021-04-22
CVE-2021-2150 [HIGH] CVE-2021-2150: Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Su Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other th
nvd
CVE-2021-2184P3HIGHCVSS 8.2≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.102021-04-22
CVE-2021-2184 [HIGH] CVE-2021-2184: Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Su Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other th
nvd
CVE-2021-2187P3HIGHCVSS 8.2≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.102021-04-22
CVE-2021-2187 [HIGH] CVE-2021-2187: Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Su Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other th
nvd
CVE-2021-2199P3HIGHCVSS 8.2≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.102021-04-22
CVE-2021-2199 [HIGH] CVE-2021-2199: Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Su Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other th
nvd
CVE-2021-2186P3HIGHCVSS 8.2≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.102021-04-22
CVE-2021-2186 [HIGH] CVE-2021-2186: Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Su Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other th
nvd
CVE-2017-10112P3HIGHCVSS 8.2v12.1.1v12.1.2+5 more2017-08-08
CVE-2017-10112 [HIGH] CVE-2017-10112: Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: User Registra Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: User Registration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require huma
nvd
CVE-2020-2582P3HIGHCVSS 8.2≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.92020-01-15
CVE-2020-2582 [HIGH] CVE-2020-2582: Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Su Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle iStore. Successful attacks require human interaction from a person other th
nvd
CVE-2019-2990P3HIGHCVSS 8.2≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.92019-10-16
CVE-2019-2990 [HIGH] CVE-2019-2990: Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Order Tracker). Su Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Order Tracker). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other tha
nvd
CVE-2020-14596P3HIGHCVSS 8.2≥ 12.1.1, ≤ 12.1.32020-07-15
CVE-2020-14596 [HIGH] CWE-79 CVE-2020-14596: Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Address Book). Sup Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Address Book). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the atta
nvd
CVE-2017-10130P3HIGHCVSS 7.6v12.1.1v12.1.2+5 more2017-08-08
CVE-2017-10130 [HIGH] CVE-2017-10130: Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: User Manageme Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: User Management). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human i
nvd
CVE-2018-2994P4MEDIUMCVSS 5.3v12.1.1v12.1.2+6 more2018-07-18
CVE-2018-2994 [MEDIUM] CVE-2018-2994: Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: Shopping Cart Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: Shopping Cart). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this
nvd
CVE-2017-10192P4MEDIUMCVSS 5.3v12.1.1v12.1.2+5 more2017-08-08
CVE-2017-10192 [MEDIUM] CVE-2017-10192: Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: Shopping Cart Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: Shopping Cart). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulner
nvd
CVE-2017-10186P4MEDIUMCVSS 5.3v12.1.1v12.1.2+5 more2017-08-08
CVE-2017-10186 [MEDIUM] CVE-2017-10186: Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: User and Comp Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: User and Company Profile). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of
nvd
CVE-2025-53041P4MEDIUMCVSS 6.1≥ 12.2.5, ≤ 12.2.142025-10-21
CVE-2025-53041 [MEDIUM] CWE-284 CVE-2025-53041: Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). S Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.5-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the
nvd
CVE-2024-21143P4MEDIUMCVSS 5.3≥ 12.2.3, ≤ 12.2.132024-07-16
CVE-2024-21143 [MEDIUM] CWE-125 CVE-2024-21143: Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: User Management). Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: User Management). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthorized read
nvd
CVE-2025-30746P4MEDIUMCVSS 6.1≥ 12.2.3, ≤ 12.2.142025-07-15
CVE-2025-30746 [MEDIUM] CWE-79 CVE-2025-30746: Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). S Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the a
nvd
CVE-2021-2059P4MEDIUMCVSS 5.3≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.102021-01-20
CVE-2021-2059 [MEDIUM] CVE-2021-2059: Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Web interface). Su Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Web interface). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2024-20938P4MEDIUMCVSS 6.1≥ 12.2.3, ≤ 12.2.132024-01-16
CVE-2024-20938 [MEDIUM] CWE-284 CVE-2024-20938: Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: ECC). Supported v Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: ECC). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks require human interaction from a person other than the attacker a
nvd
Oracle Istore vulnerabilities | cvebase