Impact
A vulnerability in Oracle Commerce Guided Search Platform Services allows an unauthenticated attacker with network access via HTTP to obtain unauthorized access to critical data and to cause a denial‑of‑service condition. The flaw provides high confidentiality impact and complete availability loss, as reflected by the CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H. The weakness can be classified as improper access control and information exposure.
Affected Systems
Oracle Commerce Guided Search Platform Services version 11.4.0
Risk and Exploitability
The CVSS base score of 9.1 indicates critical severity, while the EPSS score of less than 1% suggests that exploitation is unlikely in the current landscape but the flaw remains highly dangerous if discovered. The vulnerability is not currently listed in CISA’s Known Exploited Vulnerabilities catalog, but the attack vector is an unauthenticated HTTP request, making it simple for a remote actor to attempt exploitation.
OpenCVE Enrichment