Impact
A flaw in the Oracle Commerce Platform (Dynamo Application Framework) allows an unauthenticated network attacker to exploit the platform over HTTP, leading to a full compromise of the affected system. This vulnerability results in loss of confidentiality, integrity, and availability, enabling complete takeover of the Oracle Commerce Platform.
Affected Systems
The vulnerability affects Oracle Corporation's Oracle Commerce Platform, specifically version 11.4.0.
Risk and Exploitability
The CVSS of 9.8 indicates a critical severity. Although the EPSS score is below 1%, the low probability does not diminish the high potential impact. The flaw is not currently listed in CISA’s KEV catalog. The attack requires only network access to the HTTP interface and no authentication, making the threat surface wide for any publicly exposed instance of the platform.
OpenCVE Enrichment