Impact
This vulnerability allows an unauthenticated attacker who has already obtained a login to the same infrastructure where Oracle Commerce Guided Search performs to trigger a complete lack of availability. By exploiting a flaw in the Content Acquisition System component, the attacker can cause the application to hang or repeatedly crash. The result is a denial of service for all users interacting with the commerce platform, without any compromise of data confidentiality or integrity.
Affected Systems
Oracle’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, version 11.4.0, are affected. No other versions or product families are listed as impacted in the available data.
Risk and Exploitability
The CVSS 3.1 base score of 6.2 reflects a moderate to high availability impact. The vector AV:L indicates the attacker must have local access, but no elevated privileges are required (PR:N). The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not currently listed in CISA’s KEV catalog. Nevertheless, because it permits a straightforward denial of service once the attacker gains local access, organizations should consider applying an official patch or otherwise mitigating exposure.
OpenCVE Enrichment