Impact
The flaw resides in Oracle Commerce Guided Search Platform Services version 11.4.0 and permits an attacker with low privileged network access via HTTP to exploit it. The exploitation can make the service hang or crash, creating a complete loss of availability for the business component, and also allows reading a restricted subset of data, breaching confidentiality. The weakness corresponds to information‑exposure (CWE‑200) and a denial‑of‑service condition (CWE‑400).
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search Platform Services, version 11.4.0, is the only product variant listed as vulnerable. Other versions or deployments are not currently identified as vulnerable in the available data.
Risk and Exploitability
The CVSS v3.1 base score is 7.1, indicating high severity for availability and moderate confidentiality impact. The EPSS score is reported as less than 1%, suggesting exploitation is currently unlikely, and the vulnerability is not in CISA’s KEV catalog. Based on the description, the likely attack vector is unauthenticated HTTP traffic from a network host, requiring no special privileges and relying on crafted requests to trigger the crash or data leakage.
OpenCVE Enrichment