Executive brief
Oracle Commerce Platform, a suite used for managing large-scale e-commerce operations, contains a vulnerability in its Dynamo Application Framework component. An unauthenticated attacker can exploit this over the internet to view, modify, or delete sensitive business data. Additionally, the flaw can be used to disrupt the availability of the platform, potentially impacting online sales and customer service operations.
Technical details
A vulnerability exists in the Dynamo Application Framework component of Oracle Commerce Platform version 11.4.0. The flaw is categorized as easily exploitable and allows an unauthenticated attacker with network access via HTTP to compromise the platform. Successful attacks can result in unauthorized 'update, insert or delete' access to platform data, unauthorized read access to a subset of data, and the ability to cause a partial denial of service (DoS). The vulnerability has a CVSS 3.1 base score of 7.3, reflecting impacts to confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Commerce Platform 11.4.0
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD