Sensitive Customer Data Exposed on Thousands of Oracle NetSuite E-Commerce Sites

Published:

spot_img

Oracle NetSuite’s SuiteCommerce ERP Platform Exposes Sensitive Customer Data

A widespread misconfiguration in Oracle NetSuite’s SuiteCommerce enterprise resource planning (ERP) platform has put sensitive customer data at risk on thousands of websites, according to security firm AppOmni. The issue arises from misconfigured access controls on custom record types (CRTs), allowing unauthorized access to customer records containing personal addresses and phone numbers.

AppOmni’s chief of SaaS security research, Aaron Costello, highlighted the significant scale of businesses leaking such sensitive data due to misconfigurations. The problem primarily affects externally facing stores on NetSuite’s SuiteCommerce platform, enabling unauthorized individuals to query sensitive information without authentication through URL manipulation.

While NetSuite has urged customers to review and enhance their security settings, many businesses may be unaware of their sites leaking data or being targeted. Costello emphasized the need for more education on implementing robust SaaS security programs to tackle both known and unknown risks.

The incident underscores a broader trend of rising cybersecurity challenges in SaaS environments, with recent attacks on customer accounts hosted on platforms like Snowflake. Traditional defense strategies, such as the Lockheed Martin cyber kill chain, are being reevaluated in light of the altered attack surface in SaaS.

As threat actors target enterprise data within SaaS applications, organizations must adapt their defenses and assess access controls at a granular level to protect sensitive information. With the growing complexity of SaaS functionality, addressing these risks requires a proactive and informed approach to cybersecurity.

spot_img

Related articles

Recent articles

Dark Web Contest Awards $10,000 for Technical Writing on Vulnerability Exploitation

Dark Web Contest Awards $10,000 for Technical Writing on Vulnerability Exploitation In a notable shift within the underground cyber landscape, the TierOne forum has announced...

Kaspersky Report Reveals 1 Million Banking Accounts Compromised as E-Commerce Scams Surge to 85% of Financial Phishing in the Middle East

Kaspersky Report Reveals 1 Million Banking Accounts Compromised as E-Commerce Scams Surge to 85% of Financial Phishing in the Middle East In a significant shift...

The Strategic Framework Strengthening Security in Hospitality by 2026

The Strategic Framework Strengthening Security in Hospitality by 2026 The hospitality industry is evolving into a complex ecosystem where security plays a pivotal role in...

Hackers Exploit Kali Forms Vulnerability to Achieve Remote Code Execution on WordPress Sites

Hackers Exploit Kali Forms Vulnerability to Achieve Remote Code Execution on WordPress Sites A newly uncovered vulnerability in the Kali Forms plugin, a popular drag-and-drop...