Impact
A vulnerability in Oracle Commerce Guided Search and Oracle Commerce Experience Manager 11.4.0 allows an attacker with low privileges and network access via HTTP to read or modify critical data. The flaw results in confidentiality loss, with high impact on sensitive data, while integrity is affected at a low level. The CVSS score of 7.1 indicates a high severity of this permission escalation.
Affected Systems
The issue is limited to Oracle Corporation's Oracle Commerce Guided Search and Oracle Commerce Experience Manager products, specifically version 11.4.0.
Risk and Exploitability
Despite an EPSS score of less than 1%, the vulnerability is easily exploitable over a network using HTTP when the attacker has minimal privileges. The lack of a KEV designation does not reduce its potential risk; attackers could exploit the flaw to gain read, insert, or delete access to data owned by the Commerce platform. If left unpatched, the attack surface remains active for anyone who can reach the exposed HTTP interface.
OpenCVE Enrichment