Thousands of Oracle NetSuite Sites at Risk of Exposing Customer Information

Share:

Cybersecurity researchers are warning about the discovery of thousands of externally-facing Oracle NetSuite e-commerce sites that have been found susceptible to leaking sensitive customer information.

“A potential issue in NetSuite’s SuiteCommerce platform could allow attackers to access sensitive data due to misconfigured access controls on custom record types (CRTs),” AppOmni’s Aaron Costello said.

It’s worth emphasizing here that the issue is not a security weakness in the NetSuite product, but rather a customer misconfiguration that can lead to leakage of confidential data. The information exposed includes full addresses and mobile phone numbers of registered customers of the e-commerce sites.

The attack scenario detailed by AppOmni exploits CRTs that employ table-level access controls with the “No Permission Required” access type, which grants unauthenticated users access to data by making use of NetSuite’s record and search APIs.

That said, for this attack to succeed, there are a number of prerequisites, the foremost being need for the attacker to know the name of CRTs in use.

To mitigate the risk, it’s recommended that site administrators tighten access controls on CRTs, set sensitive fields to “None” for public access, and consider temporarily taking impacted sites offline to prevent data exposure.

“The easiest solution from a security standpoint may involve changing the Access Type of the record type definition to either ‘Require Custom Record Entries Permission’ or ‘Use Permission List,'” Costello said.

The disclosure comes as Cymulate detailed a way to manipulate the credential validation process in Microsoft Entra ID (formerly Azure Active Directory) and circumvent authentication in hybrid identity infrastructures, allowing attackers to sign in with high privileges inside the tenant and establish persistence.

The attack, however, requires an adversary to have admin access on a server hosting a Pass-Through Authentication (PTA) agent, a module that allows users to sign in to both on-premises and cloud-based applications using Entra ID. The issue is rooted in Entra ID when syncing multiple on-premises domains to a single Azure tenant.

“This issue arises when authentication requests are mishandled by pass-through authentication (PTA) agents for different on-prem domains, leading to potential unauthorized access,” security researchers Ilan Kalendarov and Elad Beber said.

“This vulnerability effectively turns the PTA agent into a double agent, allowing attackers to log in as any synced AD user without knowing their actual password; this could potentially grant access to a global admin user if such privileges were assigned.”

Ravie Lakshmanan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
9:59 am, Feb 3, 2025
weather icon 5°C
L: 3° | H: 6°
overcast clouds
Humidity: 90 %
Pressure: 1025 mb
Wind: 3 mph
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:35 am
Sunset: 4:53 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
3° | 6°°C 0 mm 0% 8 mph 95 % 1025 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
5° | 10°°C 0 mm 0% 14 mph 95 % 1027 mb 0 mm/h
Wed Feb 05 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 8 mph 85 % 1045 mb 0 mm/h
Thu Feb 06 9:00 pm
weather icon
2° | 8°°C 0 mm 0% 9 mph 84 % 1046 mb 0 mm/h
Fri Feb 07 9:00 pm
weather icon
2° | 7°°C 0 mm 0% 10 mph 94 % 1040 mb 0 mm/h
Today 12:00 pm
weather icon
6° | 7°°C 0 mm 0% 4 mph 86 % 1025 mb 0 mm/h
Today 3:00 pm
weather icon
7° | 8°°C 0 mm 0% 8 mph 92 % 1024 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 6°°C 0 mm 0% 5 mph 94 % 1024 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 5°°C 0 mm 0% 5 mph 95 % 1024 mb 0 mm/h
Tomorrow 12:00 am
weather icon
5° | 5°°C 0 mm 0% 6 mph 95 % 1024 mb 0 mm/h
Tomorrow 3:00 am
weather icon
7° | 7°°C 0 mm 0% 8 mph 83 % 1023 mb 0 mm/h
Tomorrow 6:00 am
weather icon
6° | 6°°C 0 mm 0% 8 mph 94 % 1023 mb 0 mm/h
Tomorrow 9:00 am
weather icon
6° | 6°°C 0 mm 0% 10 mph 93 % 1023 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€93,259.47
-4.21%
Ethereum(ETH)
€2,516.74
-17.12%
Tether(USDT)
€0.98
0.12%
XRP(XRP)
€2.33
-17.84%
Solana(SOL)
€189.90
-9.04%
USDC(USDC)
€0.98
-0.01%
Dogecoin(DOGE)
€0.244887
-16.95%
Shiba Inu(SHIB)
€0.000014
-17.75%
Pepe(PEPE)
€0.000010
-20.87%
Scroll to Top