Thousands of Oracle NetSuite ERP websites found leaking private customer information

Data leak
(Image credit: Shutterstock)

Researchers have discovered a vulnerability in Oracle Netsuite’s SuiteCommerce ecommerce platform that could allow threat actors to steal sensitive data from websites.

A report from AppOmni revealed the vulnerability comes from misconfigured access controls in SuiteCommerce instances, specifically within custom record types (CRTs) – tables created by the SuiteCommerce enterprise customers.

These tables usually hold critical customer data, as well as business operation information. Crooks who manage to gain access to this data can steal customer addresses, phone numbers, order history, and more.

Working on a fix

AppOmni’s researchers said the vulnerability could put many small and medium-sized businesses at risk, since they rarely have the resources to identify and address bugs such as this one.

The good news is NetSuite has already acknowledged AppOmni’s findings, and was said to be working on a patch. It also told all SuiteCommerce users to review their security settings and apply suggested best practices, as that’s the proper way of securing CRTs against threat actors and other unauthenticated users.

“Throughout my time conducting SaaS security research, it’s becoming clear that unauthenticated data exposure via SaaS applications is among the top threats to enterprises,” Aaron Costello, chief of SaaS security research at AppOmni, wrote in his analysis. “Further, as vendors introduce increasingly complex functionality into their products to remain competitive these risks will become even more prevalent.”

It is Costello’s belief organizations will struggle to tackle these issues, since they are often discovered “just through bespoke research,” for which many firms don’t have the time, or the money.

This, he claims, is particularly true for large enterprises “that have operationalized several enterprise SaaS applications to fulfill multiple demands across their lines of business.”

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Data leak
Top collectibles site leaks personal data of nearly a million users
Data leak
Popular online bill paying site leaks data of thousands of users
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
A top online gift card store may have exposed private data on hundreds of thousands of users
Image depicting a hand on a scanner
Hackers are targeting unpatched ServiceNow instances that exploit 3 separate year-old vulnerabilities
The best free firewall
Microsoft fixes Power Pages security flaw, tells users to be on their guard
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring