Impact
Oracle Commerce Guided Search / Oracle Commerce Experience Manager suffers an access control flaw (CWE-284) that enables a low‑privileged attacker who can reach the system over HTTP to create, delete, or modify critical data. Successful exploitation provides full read access to all data available through the product, resulting in loss of confidentiality and integrity.
Affected Systems
The affected product is Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically version 11.4.0. No other versions are currently known to be vulnerable.
Risk and Exploitability
With a CVSS base score of 8.1 the vulnerability is rated high severity. The EPSS score of less than 1% indicates that current real‑world exploitation is low, and the issue is not listed in the CISA KEV catalog. Despite this, the flaw can be triggered by anyone with network access to the HTTP interface and only requires a low‑privileged account, making the risk significant for publicly exposed deployments.
OpenCVE Enrichment