Impact
Vulnerability exists in the Oracle Commerce Platform 11.4.0 component Dynamo Application Framework. An attacker with low privileges who can reach the system over HTTP could exploit the flaw to create, delete or modify critical data, affecting confidentiality and integrity of the platform.
Affected Systems
The affected product is Oracle Commerce Platform version 11.4.0. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 6.8 reflects moderate severity. Exploitation is considered difficult and the EPSS score is below 1%, indicating a low probability of real‑world attacks. The vulnerability is not listed in CISA’s KEV catalog. Attack would likely be performed over a network from a low‑privileged account using HTTP, with no user interaction required.
OpenCVE Enrichment