Impact
The vulnerability resides in the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. An unauthenticated attacker with network access via HTTP can exploit the flaw to create, delete or modify critical data, and to force the application to hang or crash repeatedly, causing a denial of service. The vulnerability results in severe integrity and availability impacts as reflected in the CVSS 3.1 base score of 9.1. Based on the description, it is inferred that authentication is not required for exploitation.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, version 11.4.0, are affected. The flaw is in the Content Acquisition System component of these products.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 highlights a severe risk to integrity and availability. The EPSS score is less than 1 %, indicating a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is over HTTP with no authentication required, allowing remote exploitation of the application. Once exploited, the attacker can alter critical data and disrupt operations by inducing application hangs or crashes.
OpenCVE Enrichment