Impact
The Oracle Commerce Platform version 11.4.0 contains a flaw in the Dynamo Application Framework that permits an unauthenticated attacker to exploit the LDAP interface over the network and bypass authentication. By sending a crafted LDAP request, the attacker can read critical data stored in the platform without any credentials. This vulnerability does not affect integrity or availability, but it results in a substantial confidentiality breach.
Affected Systems
Oracle Corporation’s Oracle Commerce Platform 11.4.0 is the only affected product. The description states that the flaw resides in the commerce framework component and requires network access to the exposed LDAP service. The input does not specify whether other Oracle products are impacted.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low to moderate likelihood of exploitation at present. The vulnerability is not currently listed in CISA’s KEV catalog, but it enables unauthenticated data exposure and therefore poses a serious threat to confidentiality. Based on the description, the likely attack vector is an external host reaching the LDAP service over the network.
OpenCVE Enrichment