{"id":4909,"date":"2024-08-16T11:29:44","date_gmt":"2024-08-16T16:29:44","guid":{"rendered":"https:\/\/www.darkreading.com\/application-security\/oracle-netsuite-ecommerce-sites-expose-customer-data"},"modified":"2024-08-16T11:29:44","modified_gmt":"2024-08-16T16:29:44","slug":"thousands-of-oracle-netsuite-e-commerce-sites-expose-sensitive-customer-data","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/16\/thousands-of-oracle-netsuite-e-commerce-sites-expose-sensitive-customer-data\/","title":{"rendered":"Thousands of Oracle NetSuite E-Commerce Sites Expose Sensitive Customer Data"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt29d434bdd91399bc\/66bf7371af393a6dc6c5578e\/faucet-vincent_kondas-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/thousands-of-oracle-netsuite-e-commerce-sites-expose-sensitive-customer-data.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/thousands-of-oracle-netsuite-e-commerce-sites-expose-sensitive-customer-data.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A widespread misconfiguration in Oracle NetSuite&#8217;s SuiteCommerce enterprise resource planning (ERP) platform has left sensitive customer data exposed across thousands of websites.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security firm AppOmni <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/appomni.com\/blog\/oracle-netsuite-data-exposure-analysis\/\" rel=\"noopener\">uncovered the issue<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, describing how many businesses using NetSuite to support e-commerce have inadvertently allowed unauthorized access to customer records due to misconfigured access controls on custom record types (CRTs).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">These CRTs store critical data such as personal addresses and phone numbers, making them an attractive target for cybercriminals.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Thousands of these organizations are leaking sensitive customer data to the public through misconfigurations in their access controls,&#8221; Aaron Costello, chief of SaaS security research at AppOmni, wrote in the blog. &#8220;The sheer scale at which I found these exposures to be occurring is significant.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Widespread Oracle NetSuite Misconfiguration\">Widespread Oracle NetSuite Misconfiguration<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The issue lies not with NetSuite&#8217;s platform itself, but in the way some website admins configure their stores, allowing unauthorized users to access customer data through leaky APIs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The misconfiguration, which primarily affects externally facing stores on SuiteCommerce, essentially allows unauthorized individuals to query sensitive information without authentication, by way of URL manipulation, according to AppOmni.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Costello wrote in the report that it appears the most commonly exposed form of sensitive data is personally identifiable information (PII) of registered customers, including full addresses and mobile phone numbers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">NetSuite responded to the issue by urging customers to review their security settings and follow best practices to protect their CRTs from unauthorized access.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Costello noted that despite these efforts, many businesses may remain unaware that their sites are leaking sensitive data, or whether they&#8217;re being targeted. That&#8217;s because NetSuite does not provide easily accessible transaction logs, making it difficult for companies to detect whether they&#8217;ve been exploited.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">He added many organizations are struggling to implement and maintain a robust software-as-a-service (SaaS) security program, and said more education is needed so organizations can be better prepared to identify and tackle both known and unknown risks to their SaaS applications.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;As vendors introduce increasingly complex functionality into their products to remain competitive these risks will become even more prevalent,&#8221; according to the report. &#8220;Organizations attempting to tackle this issue will face difficulties in doing so, as it is often just through bespoke research that these avenues of attack can be uncovered.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"SaaS Cyberecurity Issues Rise\">SaaS Cyberecurity Issues Rise<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The NetSuite findings as well as recent attacks on customer accounts hosted on the Snowflake platform highlight the growing security risks in SaaS environments.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At the heart of this is the fact that SaaS platforms have significantly altered the modern attack surface, making some traditional attack steps unnecessary or easier for adversaries, according to AppOmni.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Specifically, the traditional&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.lockheedmartin.com\/en-us\/capabilities\/cyber\/cyber-kill-chain.html\" rel=\"noopener\">Lockheed Martin cyber kill chain<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;\u2014 a classic basis for <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/beyond-mitre-att-ck-the-case-for-a-new-cyber-kill-chain\" rel=\"noopener\">defending against attacks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;\u2014 identifies the steps of a successful campaign: reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives (data exfiltration, malware implantation).<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But in SaaS environments, &#8220;the kill chain from an attacker&#8217;s perspective is really centralized down to a couple of points: initial access and credential access, and collection and exfiltration,&#8221; Brandon Levene, principal product manager, threat detection, at AppOmni <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/saas-apps-present-abbreviated-kill-chain-for-attackers\" rel=\"noopener\">told Dark Reading at Black Hat<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> last week.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Accordingly, threat actors are now actively targeting enterprise data within SaaS applications; the adversaries include less sophisticated outfits as well as infamous gangs like Scattered Spider, which has <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/remote-workforce\/scattered-spider-pivots-saas-application-attacks\" rel=\"noopener\">pivoted to SaaS<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> after traditionally focusing on Microsoft cloud environments and on-premises infrastructure.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So, as organizations expand their use of SaaS applications, they must rethink their approach to the cyber kill chain and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/api-security-the-big-picture\" rel=\"noopener\">adjust their defenses<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> accordingly. For instance, in the case of e-commerce platforms, administrators should &#8220;begin assessing access controls at the field level in website forms, and identify which, if any, fields are required to be exposed,&#8221; according to AppOmni. Then, they can lock down those fields that don&#8217;t need public access.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/application-security\/oracle-netsuite-ecommerce-sites-expose-customer-data\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A widespread misconfiguration in Oracle NetSuite&#8217;s SuiteCommerce enterprise resource planning<\/p>\n","protected":false},"author":12,"featured_media":4910,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4909","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/thousands-of-oracle-netsuite-e-commerce-sites-expose-sensitive-customer-data-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/thousands-of-oracle-netsuite-e-commerce-sites-expose-sensitive-customer-data-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/thousands-of-oracle-netsuite-e-commerce-sites-expose-sensitive-customer-data-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/thousands-of-oracle-netsuite-e-commerce-sites-expose-sensitive-customer-data-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/thousands-of-oracle-netsuite-e-commerce-sites-expose-sensitive-customer-data-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/thousands-of-oracle-netsuite-e-commerce-sites-expose-sensitive-customer-data-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/thousands-of-oracle-netsuite-e-commerce-sites-expose-sensitive-customer-data-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/thousands-of-oracle-netsuite-e-commerce-sites-expose-sensitive-customer-data-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/thousands-of-oracle-netsuite-e-commerce-sites-expose-sensitive-customer-data-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/thousands-of-oracle-netsuite-e-commerce-sites-expose-sensitive-customer-data-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/thousands-of-oracle-netsuite-e-commerce-sites-expose-sensitive-customer-data-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4909","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4909"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4909\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4910"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4909"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4909"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4909"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}