Impact
The flaw in Oracle Commerce Guided Search and Oracle Commerce Experience Manager allows a low‑privileged attacker who can reach the system over HTTP to bypass authentication and authorization controls, resulting in arbitrary code execution and a complete takeover of the application. This leads to a loss of confidentiality, integrity, and availability, giving the attacker full control over the hosted site and its data.
Affected Systems
Oracle Commerce Guided Search 11.4.0 and Oracle Commerce Experience Manager 11.4.0 are the only versions listed as affected. No other product variants or versions are identified as impacted in the advisory.
Risk and Exploitability
The CVSS base score of 8.8 reflects a high impact across confidentiality, integrity, and availability. An EPSS score of < 1 % indicates the likelihood of exploitation is very low at present, and the vulnerability is not yet listed in CISA’s KEV catalog. The attack vector is network‑based via standard HTTP traffic and requires only low privileged access; any host that can reach the exposed endpoints could be compromised. The overall risk is moderate to high, with a low expected exploitation probability, so timely patching is strongly recommended.
OpenCVE Enrichment