Impact
This vulnerability results from a failure to enforce proper authentication in the ATG Portals component of Oracle Commerce Platform, enabling an unauthenticated attacker that can reach the system over HTTP to take over the application. The flaw provides complete confidentiality, integrity, and availability compromise, effectively allowing a remote attacker to control the platform. The weakness corresponds to improper authentication (CWE-287) and missing authentication for a critical function (CWE-306).
Affected Systems
Oracle Commerce Platform version 11.4.0, as identified by the vendor, is the sole affected release. The vulnerability is tied specifically to the ATG Portals component of that platform.
Risk and Exploitability
With an EPSS score of less than 1% the likelihood of exploitation in the wild is low, but the CVSS base score of 9.8 denotes severe confidentiality, integrity and availability impacts. The vulnerability is not listed in the CISA KEV catalog, and the required attacker is only an unauthenticated user who can reach the service over HTTP. Thus, a network‑level attacker can exploit the flaw without prior credentials, giving remote takeover of the platform.
OpenCVE Enrichment