Impact
The vulnerability resides in the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. An unauthenticated attacker who can reach the system over HTTPS may create, delete, modify, or otherwise access critical data. This can result in full compromise of all accessible data, affecting confidentiality and integrity, while availability is not impacted. The CVSS base score of 7.4 reflects these impacts.
Affected Systems
Oracle Corporation’s product, Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0, is the only affected release cited. No other vendors or product variants are listed.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity, yet the EPSS score is below 1%, suggesting a low probability of widespread exploitation at present. The attack vector is inferred to be network based over HTTPS, exploiting the lack of authentication. Although not present in CISA’s KEV catalog, the vulnerability remains actionable and warrants patching before any active exploitation is evident.
OpenCVE Enrichment