logo

Thousands of Oracle NetSuite E-Commerce Sites Expose Sensitive Customer Data

ID: 5cd19115-8d46-550b-a456-d3ce17bdd94a

STIX ID: report--5cd19115-8d46-550b-a456-d3ce17bdd94a

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2024-08-16

Date Updated: 2026-05-05

Author: Nathan Eddy, Contributing Writer

...
...

AppOmni discovered a widespread misconfiguration in Oracle NetSuite SuiteCommerce stores that can expose customers' personally identifiable information (addresses, phone numbers) via unauthenticated API/URL access; thousands of sites may be affected, detection is difficult due to limited transactional logs, and the issue highlights broader SaaS security risks and the need for stronger field-level access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.