Thousands of Oracle NetSuite ERP websites found leaking private customer information



Researchers have discovered a vulnerability in Oracle Netsuite’s SuiteCommerce ecommerce platform that could allow threat actors to steal sensitive data from websites.

A report from AppOmni revealed the vulnerability comes from misconfigured access controls in SuiteCommerce instances, specifically within custom record types (CRTs) – tables created by the SuiteCommerce enterprise customers.

https://cdn.mos.cms.futurecdn.net/GcQXTy4NBXKeoop4V5WQnQ-1200-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img