VDB
OSA-38668894
OSA-38668894
PUBLISHED
CVSS 7.5 HIGH
Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security (Jakarta Mail)). The supported version that is affected is 25.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Retail Xstore Office accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Risk Scores
CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Timeline
- Jan 20, 2026 CVE Published