Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 16, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 16, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 16, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 16, 2025

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025

      Minecraft licensing robbed us of this controversial NFL schedule release video

      May 16, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The power of generators

      May 16, 2025
      Recent

      The power of generators

      May 16, 2025

      Simplify Factory Associations with Laravel’s UseFactory Attribute

      May 16, 2025

      This Week in Laravel: React Native, PhpStorm Junie, and more

      May 16, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025
      Recent

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Potential Data Exposure Issue Discovered in NetSuite’s SuiteCommerce Platform

    Potential Data Exposure Issue Discovered in NetSuite’s SuiteCommerce Platform

    August 16, 2024

    Oracle’s NetSuite, a popular Enterprise Resource Planning (ERP) platform, has a feature that allows businesses to deploy an external-facing store using SuiteCommerce or SiteBuilder. This feature enables e-commerce operations and back-office processes within a unified platform, streamlining and automating order processing, fulfillment, and inventory management.

    However, a recent investigation has uncovered a potential issue in the SuiteCommerce platform that could allow attackers to access sensitive data due to misconfigured access controls on custom record types (CRTs).

    Addressing Potential Risk in NetSuite’s SuiteCommerce

    According to Aaron Costello, Chief of SaaS Security Research at AppOmni, the issue could potentially affect thousands of live public SuiteCommerce websites. He explains that the problem often arises when organizations deploying NetSuite are unaware that a default stock website has been publicly exposed, even if they had no intention of setting up an e-commerce store.

    Source: AppOmni

    The most commonly exposed data appears to be personally identifiable information (PII) of registered customers, including full addresses and mobile phone numbers,” Costello said.

    It’s important to note that this is not a security vulnerability in the NetSuite product itself. Rather, it is a potential issue that can arise from how customers configure the access controls within their NetSuite environments.

    NetSuite uses a multi-layered access control system to protect sensitive data. There are two types of access controls: table-level and field-level.

    Table-level access controls determine who can see the entire table of data.
    Field-level access controls determine who can see specific fields within a table.

    The security risk lies in the way NetSuite’s online store feature interacts with the database. When a customer tries to access sensitive information, NetSuite checks the access controls to see if they have permission to view it. If the access controls are not properly set up, hackers can exploit this vulnerability and gain access to sensitive information.

    Mitigating the NetSuite Vulnerability

    To protect sensitive information, businesses should ensure that table-level access controls are set to “Require Custom Record Entries Permission” and field-level access controls are set to “None” for public access. To address this risk, the team recommends that NetSuite administrators take a few additional steps:

    Review access controls on custom record types (CRTs): Ensure the “Access Type” is not set to allow public access without authentication.
    Restrict access to sensitive fields: Even if table-level access is limited, administrators should review field-level permissions and set sensitive information to have “None” access for unauthenticated users.
    Consider temporarily taking impacted sites offline: As a temporary measure, organizations may want to take any public-facing SuiteCommerce sites offline until the access controls can be properly configured.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCopy2Pwn Vulnerability Bypasses Windows Protections
    Next Article Weekly Vulnerability Report: Cyble Urges Fixes in SAP, Ivanti, AMD and More

    Related Posts

    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 17, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-40906 – MongoDB BSON Serialization BSON::XS Multiple Vulnerabilities

    May 17, 2025
    Leave A Reply Cancel Reply

    Hostinger

    Continue Reading

    TensorOpera Unveils Fox Foundation Model: A Unique Step in Small Language Models Enhancing Scalability and Efficiency for Cloud and Edge Computing

    Development

    CVE-2025-4548 – Campcodes Online Food Ordering System SQL Injection

    Common Vulnerabilities and Exposures (CVEs)

    Social Media Policy

    Development

    CVE-2025-43000 – Apache Struts Information Disclosure Vulnerability

    Common Vulnerabilities and Exposures (CVEs)
    GetResponse

    Highlights

    The 5 Linux AppImages I depend on daily – and how to add them to your desktop menu

    April 21, 2025

    AppImages have come a long way in recent years. Here’s why you should check them…

    What To Expect When Migrating Your Site To A New Platform

    February 26, 2025

    How to Use a PHP Meta Tag Property Class to Fix Issues to Rank Better on Google Searches

    May 27, 2024

    7 Best AI Interview Tools 2024

    June 8, 2024
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.