San Francisco, August 20, 2024 –A misconfiguration in Oracle NetSuite’s SuiteCommerce platform exposes sensitive customer data on thousands of e-commerce sites. Urgent action is required to secure these systems.
In a startling revelation, cybersecurity researchers have uncovered a critical misconfiguration in Oracle NetSuite’s SuiteCommerce platform that could potentially expose sensitive customer data across thousands of e-commerce sites.
This flaw, which stems from improper access controls on custom record types (CRTs), could allow unauthorized access to confidential customer information, including full addresses and mobile phone numbers.
According to AppOmni, the vulnerability arises from CRTs configured with the No Permission Required” access type, enabling unauthenticated users to exploit NetSuite’s record and search APIs. Aaron Costello, a cybersecurity expert at AppOmni explains:
This issue is not a flaw in the NetSuite product itself, but rather a result of misconfigured customer settings that leave sensitive data exposed.
The potential impact is massive, with thousands of externally facing e-commerce sites at risk. The situation is exacerbated by the fact that the exploitation of this flaw requires minimal technical knowledge—hackers need only to identify the names of the CRTs in use to gain unauthorized access.
To mitigate this risk, administrators must tighten access controls on CRTs immediately,” Costello adds. Setting sensitive fields to ‘None’ for public access or changing the access type to ‘Require Custom Record Entries Permission’ is crucial to prevent data breaches.”
The discovery has sent shockwaves through the cybersecurity community, prompting urgent calls for e-commerce sites using NetSuite to review and secure their configurations. With data breaches becoming increasingly common, this vulnerability highlights the critical need for robust security practices in digital commerce.
Other News At VPNRanks
- EU Cyber Laws to Double Data Breach Reports Overnight
- New PGMem Malware Hijacks PostgreSQL for Monero Mining
- Jenkins Flaw Exploited—Ransomware Surge Triggers CISA Alert
- Uber Hit with Record €290M Fine for GDPR Breach
- Microsoft Patch Foils North Korea’s Lazarus Group in Cyber Attack
- Google Scrambles to Remove Hidden App Exposing Pixel Phones
Hey, wait!
Stay informed on the latest privacy updates, cybersecurity insights, and internet freedom news by following VPNRanks news daily! As your primary resource for critical updates in online security, we ensure you’re always in the know. Make VPNRanks your go-to guide for safeguarding your digital life!
