Impact
A flaw in Oracle Commerce Platform’s Dynamo Application Framework is missing authentication (CWE-306). It allows an unauthenticated attacker with TCP network access to execute arbitrary code, potentially taking complete control of the platform. The impact is total loss of confidentiality, integrity and availability of the commerce environment.
Affected Systems
Oracle Corporation’s Oracle Commerce Platform version 11.4.0 is the only version identified as vulnerable.
Risk and Exploitability
The CVSS 3.1 score of 9.8 signals critical risk. Although the EPSS score is very low (<1%), the description notes that the vulnerability is easily exploitable with basic network connectivity; the lack of authentication and low attack complexity mean that remote exploitation can occur from any external IP that can reach the TCP endpoint. The vulnerability is not yet listed in the CISA Known Exploited Vulnerabilities catalog, but its severity and ease of exploitation warrant urgent attention.
OpenCVE Enrichment