Sensitive Customer Data Exposed on Thousands of Oracle NetSuite E-Commerce Sites

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Oracle NetSuite’s SuiteCommerce ERP Platform Exposes Sensitive Customer Data

A widespread misconfiguration in Oracle NetSuite’s SuiteCommerce enterprise resource planning (ERP) platform has put sensitive customer data at risk on thousands of websites, according to security firm AppOmni. The issue arises from misconfigured access controls on custom record types (CRTs), allowing unauthorized access to customer records containing personal addresses and phone numbers.

AppOmni’s chief of SaaS security research, Aaron Costello, highlighted the significant scale of businesses leaking such sensitive data due to misconfigurations. The problem primarily affects externally facing stores on NetSuite’s SuiteCommerce platform, enabling unauthorized individuals to query sensitive information without authentication through URL manipulation.

While NetSuite has urged customers to review and enhance their security settings, many businesses may be unaware of their sites leaking data or being targeted. Costello emphasized the need for more education on implementing robust SaaS security programs to tackle both known and unknown risks.

The incident underscores a broader trend of rising cybersecurity challenges in SaaS environments, with recent attacks on customer accounts hosted on platforms like Snowflake. Traditional defense strategies, such as the Lockheed Martin cyber kill chain, are being reevaluated in light of the altered attack surface in SaaS.

As threat actors target enterprise data within SaaS applications, organizations must adapt their defenses and assess access controls at a granular level to protect sensitive information. With the growing complexity of SaaS functionality, addressing these risks requires a proactive and informed approach to cybersecurity.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Unit 42 Warns Frontier AI Models Have Shifted Cybersecurity Power to Attackers

Unit 42, the threat intelligence arm of Palo Alto Networks, has raised alarms about the impact of frontier AI models on cybersecurity, suggesting a...

Invespy Launches Broker Hub to Transform Dubai’s Real Estate Ecosystem

Invespy Launches Broker Hub to Transform Dubai's Real Estate Ecosystem The Invespy Broker Hub has officially launched in Dubai, aiming to revolutionize the real estate...

Major Cyber Breaches Reported: Latvia, Sakura Internet, and SickKids Among Affected

In a week marked by significant cybersecurity incidents, the latest Threat Intelligence Bulletin from Check Point Research highlights major breaches affecting organizations across Europe...

Two Alleged TeamPCP Hackers Arrested in Australia for Software Supply Chain Attacks

Authorities in Australia have arrested two men believed to be members of TeamPCP, a cybercrime group implicated in a series of software supply chain...