Impact
A flaw in Oracle Commerce Platform 11.4.0’s Dynamo Application Framework permits an unauthenticated attacker to compromise the platform over HTTP. The vulnerability is a classic authentication bypass (CWE-287 and CWE-306) that allows an attacker with network reachability to gain full control of the Commerce Platform, exposing all stored data and services. The CVSS 3.1 base score of 8.1 reflects severe confidentiality, integrity, and availability impacts.
Affected Systems
Oracle Corporation’s Oracle Commerce Platform 11.4.0 is affected. This product uses the Dynamo Application Framework for application logic and is deployed to deliver e‑commerce services. No other version or product is listed as impacted.
Risk and Exploitability
While the high CVSS score signals significant potential damage, the EPSS score of less than 1 % indicates that exploitation is currently rare and no public campaigns have been documented. The vulnerability can be triggered over an open network connection to the HTTP interface without any credentials, making it a straightforward remote attack. Since the issue is not listed in CISA’s KEV catalog, there is no confirmed exploitation evidence, yet the possibility of a complete platform takeover warrants prompt action.
OpenCVE Enrichment