Impact
Oracle Commerce Guided Search and Oracle Commerce Experience Manager incorporate a flaw in the Endeca Application Controller that, when accessed over HTTP without authentication, allows an attacker to directly compromise the application. The issue results from improper access control and missing authentication mechanisms, classified as CWE-284 and CWE-306. Successful exploitation can lead to full takeover of the application, compromising confidentiality, integrity, and availability.
Affected Systems
The affected vendors are Oracle Corporation. The product line impacted is Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically the 11.4.0 release. No other versions or products are noted as affected in the data.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 base score of 9.8, indicating critical severity and the potential for complete control over the system. The EPSS score is reported as less than 1 %, implying a low but non‑zero likelihood of exploitation in the current period. The issue is not listed in CISA's KEV catalog. Attackers can exploit the flaw by making unauthenticated HTTP requests to the exposed Endeca Application Controller endpoint, which does not enforce authentication or access control, enabling remote takeover of the application.
OpenCVE Enrichment