Impact
The vulnerability exists in the Content Acquisition System component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0. It permits a low‑privileged attacker who can send HTTP traffic over the network to trigger code execution on the server, effectively giving the attacker full control over the application and compromising confidentiality, integrity and availability. The CVSS 3.1 Base Score of 9.9 and the scope change flag indicate a critical impact that can extend beyond the directly affected component.
Affected Systems
Oracle Commerce Guided Search and Oracle Commerce Experience Manager running release 11.4.0 are listed as vulnerable. The advisory notes that because the vulnerability changes scope, additional Oracle Commerce products may also be affected, although only this version is explicitly identified.
Risk and Exploitability
The EPSS score of less than 1 % indicates that exploit attempts are statistically rare, but the very high CVSS score means a single successful attack would be devastating. The flaw is not reported in CISA’s KEV catalog. Attackers only need network access over HTTP; no special privileges or credentials are required beyond being a low‑privileged user with the ability to craft the HTTP request.
OpenCVE Enrichment