Impact
The vulnerability resides in the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. An unauthenticated attacker with network access to the HTTP endpoint can exploit the flaw, leading to full takeover of the application and loss of confidentiality, integrity and availability, as reflected by a CVSS 9.8 score.
Affected Systems
Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0 from Oracle Corporation are affected; the services are exposed over HTTP on web servers.
Risk and Exploitability
The CVSS base score of 9.8 marks this as a critical vulnerability, while an EPSS score of less than 1% suggests a low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. Exploitation requires only unauthenticated network access to the HTTP interface, with no credentials or privileged actions needed, making the attack path straightforward for attackers seeking full compromise.
OpenCVE Enrichment