Impact
The vulnerability resides in the Content Acquisition System component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager. An unauthenticated attacker who can reach the application via HTTP can send specially crafted requests that are processed without proper authentication or authorization. When exploited, the attacker can create, modify or delete critical data, compromising data integrity, and can repeatedly crash or hang the application, resulting in a denial of service.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0. No other versions are listed as affected.
Risk and Exploitability
Risk is severe with a CVSS v3.1 Base Score of 9.1, indicating significant impact on integrity and availability. The EPSS score is <1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack requires only unauthenticated network access over HTTP, so any exposed instance can potentially be compromised. Despite the low EPSS, the flaw allows unauthorized data manipulation and a complete denial of service, so the impact remains severe.
OpenCVE Enrichment