Impact
A critical vulnerability exists in Oracle Commerce Guided Search Platform Services 11.4.0 (Forge component). An unauthenticated attacker with network access over HTTP can exploit this flaw to compromise the service, potentially resulting in full takeover. The weakness involves authentication bypass and privilege escalation (CWE-269, CWE-287, CWE-306). The CVSS score of 9.8 reflects severe confidentiality, integrity, and availability impact, underscoring the critical nature of the flaw.
Affected Systems
Affected systems are Oracle Corporation's Oracle Commerce Guided Search Platform Services version 11.4.0. No other versions are listed as impacted.
Risk and Exploitability
The CVSS Base Score of 9.8 classifies this issue as critical, and the EPSS score of less than 1% indicates a low but non‑zero probability of exploitation. The flaw is not listed in the CISA KEV catalog, but it remains a high‑priority risk given the ability to compromise the service without authentication. The attack vector is inferred to be remote over HTTP, requiring no special credentials, making the vulnerability easily exploitable.
OpenCVE Enrichment