Impact
The vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager lets an attacker with limited local privileges and network connectivity manipulate HTTP requests to access or modify critical data without authorization and can cause the service to crash or hang. The exploit can lead to exposure of confidential information or full denial of service to legitimate clients, affecting both confidentiality and availability but not integrity directly.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 is affected. No other product versions or vendor products are listed in the CNA data.
Risk and Exploitability
The CVSS base score of 8.1 indicates a high severity vulnerability. With an AV:N and low attack complexity, an attacker can reach the target over HTTP from an external network. However, the EPSS score of less than 1% suggests that current exploitation attempts are rare. The vulnerability is not in CISA’s KEV catalog. Successful exploitation requires only low privileges and no user interaction, making it potentially easy to achieve in a suitable environment.
OpenCVE Enrichment