Impact
The vulnerability exists in Oracle Commerce Platform 11.4.0, within the Dynamo Application Framework component. An attacker who does not need to authenticate but can reach the physical network segment where the platform runs can exploit the flaw and compromise the platform, granting full control over the application and loss of confidentiality, integrity, and availability.
Affected Systems
Affected vendor is Oracle Corporation; the impacted product is the Oracle Commerce Platform version 11.4.0. No other product versions are known to be vulnerable according to the current advisory.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a high severity with impact on confidentiality, integrity, and availability. The exploit requires physical proximity to the network segment but does not require administrative or user credentials, making it a local network attack. While the attack is considered difficult to execute, the potential for complete platform takeover warrants significant attention. The vulnerability is not listed in the CISA KEV catalog, and the EPSS score is <1%, indicating a very low exploitation probability.
OpenCVE Enrichment