Impact
Oracle Commerce Platform version 11.4.0 contains a Cross‑Site Request Forgery flaw in the Dynamo Application Framework. The flaw allows a low‑privileged attacker who can reach the web interface over HTTP to send forged requests that an unrelated user is compelled to perform. Successfully exploiting the flaw can give the attacker read access to sensitive data with a high confidentiality impact and the ability to modify or delete some data, resulting in integrity loss. The weakness is a classic CSRF issue (CWE‑352).
Affected Systems
Vulnerable systems are Oracle Commerce Platform 11.4.0 deployed by Oracle Corporation. The advisory notes that the flaw may also affect other products within the Oracle ecosystem through scope changes, but the primary impact is on this version.
Risk and Exploitability
The CVSS base score of 7.6 classifies this as high severity. The EPSS score of less than 1% indicates a low probability of exploitation, but the vulnerability is not in CISA’s KEV catalog. Attackers would need network access to the HTTP interface, low privilege, and an unsuspecting user to trigger the forged request, typically through social engineering or phishing. Without a patch, exposed systems that allow HTTP traffic can be compromised, posing significant confidentiality risks and some integrity breach. The scope change suggests that attackers might also affect other Oracle products if the same framework component is reused.
OpenCVE Enrichment