Impact
In Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0, the Experience Manager component contains an access‑control flaw that permits low‑privileged users who can reach the HTTP interface to perform privileged operations. Successful exploitation allows an attacker to take complete control of the application, resulting in confidentiality, integrity, and availability impacts. This flaw is classified as improperly controlled access to privileged functions (CWE‑284).
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager products, specifically version 11.4.0, are affected.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates high severity, while the EPSS score of less than 1 % suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers only require network connectivity to the HTTP interface and a low‑privileged account. Once exploited, they can gain full application control, potentially exposing sensitive business data and disrupting commerce operations.
OpenCVE Enrichment