Impact
The Oracle Commerce Platform contains a flaw in the Dynamo Application Framework component that permits an unauthenticated attacker who can reach the platform over HTTP to create, delete, or modify critical data. This unauthorized manipulation of data results in both confidentiality and integrity compromise of all Oracle Commerce Platform accessible data, as the attacker can effectively alter or erase legitimate information without authentication. Based on the description, it is inferred that the vulnerability does not provide code execution but offers full control over business data within the platform.
Affected Systems
Affected systems are Oracle Corporation’s Oracle Commerce Platform, specifically version 11.4.0. The flaw affects the Dynamo Application Framework subsystem of the platform. No other versions are listed as vulnerable in the current CNA data, so organizations running 11.4.0 should verify whether any security releases that address this issue have been applied.
Risk and Exploitability
The CVSS 3.1 base score of 7.4 denotes high severity with high impact on confidentiality and integrity, but the EPSS score is below 1 % and the vulnerability is not listed in CISA's KEV catalog, indicating limited public exploitation data. The attack vector is network‑based over HTTP, requiring no authentication. An attacker who succeeds can fully ingest, modify, or delete critical data within the platform, effectively disrupting business operations. While exploitation is described as difficult, the potential business damage warrants prompt attention.
OpenCVE Enrichment