Impact
The Oracle Commerce Platform’s Dynamo Application Framework contains a flaw (CWE-306) that can be triggered by unauthenticated HTTP requests. When exploited successfully, the vulnerability permits an attacker to gain complete control of the platform, compromising confidentiality, integrity, and availability of the application and potentially the underlying system.
Affected Systems
Oracle Corporation’s Oracle Commerce Platform, version 11.4.0, is the only version identified as affected. The platform is exposed to the network via HTTP and processes requests from untrusted hosts.
Risk and Exploitability
The CVSS base score of 9.8 classifies the issue as critical, and the vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) confirms that an unauthenticated network attacker can exercise the flaw with minimal effort. The EPSS score is below 1 %, and the vulnerability is not listed in the CISA KEV catalog, indicating that, while exploitation is possible, the broader threat landscape shows limited current usage. Nevertheless, the high severity and lack of protective controls mandate immediate attention.
OpenCVE Enrichment