Impact
Oracle Commerce Guided Search Platform Services 11.4.0 contains an unauthenticated vulnerability in the Forge component that permits attackers to create, delete, or modify critical data and read all data exposed by the service over HTTPS. The flaw directly compromises confidentiality and integrity, classifying it as a high‑impact access control weakness (CWE‑284).
Affected Systems
Systems that run Oracle Commerce Guided Search Platform Services version 11.4.0 and expose the service over HTTPS are affected. No other versions or products are currently known to be impacted.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 marks the vulnerability as Critical, while the EPSS score of less than 1% and the absence from the CISA KEV catalog indicate a low current exploitation probability. An external attacker can exploit the flaw simply by sending unauthenticated HTTPS requests to the exposed service, bypassing all authentication checks and executing arbitrary data manipulation or exfiltration requests.
OpenCVE Enrichment