Impact
The flaw is in the Experience Manager component of Oracle Commerce Guided Search, representing a CWE‑284 authorization violation that allows an unauthenticated attacker with network access via HTTP to create, delete, modify, or read critical data. This results in both confidentiality and integrity compromise of all accessible data within the affected system.
Affected Systems
Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0, used by organizations deploying Oracle’s e‑commerce platform.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 marks this as a high‑severity vulnerability. Although the EPSS score is below 1% and the issue is not currently listed in the CISA KEV catalog, the fact that it can be exploited remotely over HTTP without any authentication means that a determined adversary could cause significant data loss. The attack vector is likely to involve simple HTTP requests sent directly to the exposed service, making it easily exploitable from anywhere on the network.
OpenCVE Enrichment