VDB

OSA-38668894

OSA-38668894 PUBLISHED CVSS 7.5 HIGH

Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security (Jakarta Mail)). The supported version that is affected is 25.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Retail Xstore Office accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Timeline

  • Jan 20, 2026 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›