CVE-2024-21136

HIGH EXPLOITED NUCLEI

Oracle Retail Xstore Office <=23.0.1 - Unauthenticated Sensitive Information Exposure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-21136 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.

Description

Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office. While the vulnerability is in Oracle Retail Xstore Office, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Retail Xstore Office accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).

Nuclei Templates (1)

Oracle Retail Xstore Suite - Pre-authenticated Path Traversal
HIGHVERIFIEDby DhiyaneshDk
Shodan: html:"xstoremgwt"

References (1)

Core 1
Core References

Scores

CVSS v3 8.6
EPSS 0.0178
EPSS Percentile 75.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

VulnCheck KEV 2025-06-08
CWE
CWE-200
Status published
Products (5)
oracle/retail_xstore_office 19.0.5
oracle/retail_xstore_office 20.0.3
oracle/retail_xstore_office 20.0.4
oracle/retail_xstore_office 22.0.0
oracle/retail_xstore_office 23.0.1
Published Jul 16, 2024
Tracked Since Feb 18, 2026