Record summary

CVE-2024-21136 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.

Description

Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office. While the vulnerability is in Oracle Retail Xstore Office, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Retail Xstore Office accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).

Description source: GitHub Advisory

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 8, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 17, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE List19.0.5affected
20.0.3affected
20.0.4affected
22.0.0affected
23.0.1affected

Nuclei templates

1
ProjectDiscoveryHIGHOracle Retail Xstore Suite - Pre-authenticated Path TraversalCVSS 8.6

Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office. While the vulnerability is in Oracle Retail Xstore Office, attacks may significantly impact additional products (scope change).

Impact

Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Retail Xstore Office accessible data.

Remediation

Apply the latest security patches and updates from the vendor to address this vulnerability.

AuthorsDhiyaneshDk
Template tagscvecve2024oraclexstorelfivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CPE: cpe:2.3:a:oracle:retail_xstore_office:19.0.5:*:*:*:*:*:*:*
Shodan: html:"xstoremgwt"

Source: ProjectDiscovery

References

2