Impact
A flaw exists in the Oracle Commerce Platform component known as the Dynamo Application Framework. The vulnerability permits an attacker without authentication to send specially crafted HTTP requests that grant access to critical data stored by the platform and also allow the attacker to trigger a hang or crash, causing a full denial of service. The weakness originates from improper access control (CWE-284) and missing authentication (CWE-306), leading to a high confidentiality impact and a complete availability loss, with no impact on integrity. The CVSS v3.1 base score of 9.1 reflects a severe risk for exposed systems.
Affected Systems
The affected product is the Oracle Commerce Platform version 11.4.0, as produced by Oracle Corporation. No other version or product is listed as impacted in the available data.
Risk and Exploitability
The exploit is considered easily achievable, requiring only network access over HTTP and no prior authentication. The EPSS score of less than 1% indicates the probability of real-world exploitation is low. The CVSS score of 9.1 places the issue in the critical severity range. The vulnerability is not listed in the CISA KEV catalog, so no known widespread exploitation campaigns have been reported. Nonetheless, the high impact combined with the simple attack surface warrants immediate attention.
OpenCVE Enrichment