Impact
A local privilege escalation flaw exists in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. An attacker who can log on to the underlying host can exploit this flaw to create, delete, or modify application data, and to read all data accessible through the application. This jeopardizes the confidentiality and integrity of critical business information without requiring any user interaction.
Affected Systems
The affected vendor is Oracle Corporation, specifically the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product version 11.4.0. No other versions are listed as vulnerable in the current advisory.
Risk and Exploitability
According to the advisory the CVSS v3.1 base score is 7.1, with a local, low‑privilege attack vector and no user interaction, indicating a significant risk to confidentiality and integrity. The EPSS indicates under 1 % exploit probability, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires that the attacker possess valid credentials or otherwise be able to log on to the host that runs the application, but no elevated privilege or network access is required.
OpenCVE Enrichment