Impact
The Oracle Commerce Guided Search / Oracle Commerce Experience Manager product contains a vulnerability in the Experience Manager component that allows an unauthenticated attacker with network access over HTTP to bypass authentication controls and retrieve critical data. The flaw is an improper access control weakness (CWE-200) that can lead to a confidentiality breach, exposing sensitive information without requiring credentials or other privileges.
Affected Systems
Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 is affected. No other versions are listed in the CVE data, indicating the issue is specific to this release.
Risk and Exploitability
The CVSS v3.1 score of 7.5 shows a high confidentiality impact, while the EPSS score of less than 1 % suggests a low current exploitation likelihood. The vulnerability is not yet listed in the CISA KEV catalog. Attackers can exploit the flaw easily over HTTP with no authentication required, meaning anyone who can reach the service from the network can potentially access all data exposed by the application. The straightforward attack path and lack of interface restrictions make this a low cost vector for data compromise.
OpenCVE Enrichment