Impact
An unauthenticated attacker with network access via HTTP can exploit an access control weakness in Oracle Commerce Service Center to insert, update, or delete data that should be protected, as well as read restricted information. The flaw requires the attacker to engage a user who is not the attacker himself, limiting the ease of immediate compromise but still allowing an intruder to alter the integrity and confidentiality of the data store if they can create or manipulate user sessions. The vulnerability is a classic insufficient authorization error (CWE‑284).
Affected Systems
Oracle Commerce Service Center version 11.4.0, distributed by Oracle Corporation, is the only version verified to be vulnerable. The product is typically accessed via an HTTP endpoint.
Risk and Exploitability
The CVSS score of 6.1 classifies the issue as moderate. An EPSS score of less than 1 % indicates that widespread exploitation is unlikely, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, attackers must succeed in establishing HTTP connectivity to the vulnerable service and then persuade a non‑attacker user to carry out an action that triggers the flaw. Remote network access over the HTTP interface is the primary entry point, but the necessity of human interaction makes immediate exploitation more difficult.
OpenCVE Enrichment