Impact
This vulnerability allows attackers without authentication to send HTTP requests to the Oracle Commerce Platform 11.4.0, specifically the Dynamo Application Framework component, and to perform unauthorized update, insert or delete operations on data, read restricted data, or deliver a partial denial of service. The weakness is a flaw in the platform’s access control, classified as CWE‑284. Successful exploitation results in moderate confidentiality, integrity and availability impacts, as reflected by the CVSS 3.1 Base Score of 7.3.
Affected Systems
Affected is Oracle Corporation’s Oracle Commerce Platform, version 11.4.0. The issue resides in the Dynamo Application Framework component. No other versions or products are listed as impacted.
Risk and Exploitability
The EPSS score is indicated as < 1 %, meaning exploitation is considered unlikely but not impossible. The CVSS score of 7.3 signals moderate severity, and the vulnerability is not listed in CISA KEV, so there are no known active exploits. Attackers can trigger the vulnerability over an unauthenticated HTTP connection, eliminating the need for user credentials. Deploying the official patch or restricting HTTP traffic to trusted sources mitigates the risk.
OpenCVE Enrichment