Impact
A flaw in the Experience Manager component of Oracle Commerce Guided Search enables an unauthenticated attacker to call a Remote Method Invocation interface without proper authentication or access control. By exploiting this vulnerability, a remote adversary can read confidential data or gain unrestricted access to all content managed by the application, representing a substantial confidentiality breach. The underlying weakness corresponds to improper authentication or access control defects.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 is affected. No other product variants or versions are listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 classifies this as high severity with a severe impact on confidentiality. The EPSS score indicates a low probability of exploitation in the wild (< 1%), and the vulnerability is not currently listed in CISA’s KEV catalog. The likely attack vector is a direct network connection to the exposed RMI interface. Successful exploitation requires no credentials but does need network reachability to the RMI port, allowing the attacker to retrieve sensitive data or compromise the application entirely.
OpenCVE Enrichment