Impact
A flaw in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 enables an unauthorized attacker to connect over HTTP without authentication and retrieve confidential data. The weakness is an improper access control (CWE‑284) that permits unauthenticated network requests to extract sensitive information, thereby directly compromising confidentiality while leaving integrity and availability untouched.
Affected Systems
Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0 from Oracle Corporation. No other versions are listed as affected in the CNA data.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 indicates high severity for confidentiality impact. The EPSS score is less than 1 %, suggesting a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based HTTP request from an external, unauthenticated attacker that exploits the missing access control to extract sensitive data from the application.
OpenCVE Enrichment