Impact
An unauthenticated attacker with network access via HTTP can exploit a flaw in Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0, enabling full compromise of the application. The vulnerability delivers confidentiality, integrity, and availability impact, allowing the attacker to take over the product and potentially disrupt or exfiltrate sensitive data.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0. This version is the only one affected, as specified by the vendor and Oracle’s advisory.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 classifies the flaw as high severity, with no attacker privileges required and no user interaction necessary. The EPSS score of less than 1% indicates a low real‑world exploitation probability at the time of this analysis, though the vulnerability remains in potential danger. Because the flaw is not listed in CISA’s KEV catalog, there is no confirmed exploitation yet, but the network‑based attack vector and complete takeover potential warrant immediate mitigation.
OpenCVE Enrichment