Impact
An authorization flaw in Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager allows an attacker with only low privileges and network access over HTTP to perform unauthorized insert, update or delete operations on accessible data, as well as read a subset of that data. The flaw stems from insufficient enforcement of access controls, classified as CWE‑284, and is capable of compromising both the confidentiality and integrity of the system without affecting availability.
Affected Systems
Oracle Corporation’s 11.4.0 release of Oracle Commerce Guided Search / Oracle Commerce Experience Manager is impacted; no other versions or builds are listed as affected.
Risk and Exploitability
The vulnerability carries a CVSS v3.1 base score of 5.4, an EPSS score of less than 1%, and is not listed in the CISA KEV catalog, indicating a low probability of exploitation. However, because the attack requires only basic network connectivity to the application’s HTTP interface and does not demand elevated credentials, a low‑privileged attacker can easily exploit the flaw to compromise data integrity and confidentiality.
OpenCVE Enrichment