Impact
This vulnerability resides in the Content Acquisition System of Oracle Commerce Guided Search / Oracle Commerce Experience Manager and allows an attacker to create, delete, or modify critical data without authentication. The underlying flaw is a type of improper authorization (CWE-284). The result is compromise of data confidentiality and integrity, potentially giving the attacker full access to all data exposed by the product.
Affected Systems
Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0 from Oracle Corporation. No other versions are listed as affected.
Risk and Exploitability
The CVSS score of 9.1 indicates a severe risk, and the vector shows that the attack can be performed over the network via HTTP with no user interaction or privileged access. The EPSS score of < 1% indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, but the high base score, the unauthenticated network attack vector, and the possibility of complete data compromise call for immediate attention. The likely attack vector is an unauthenticated network attack via HTTP to the exposed interfaces of the product.
OpenCVE Enrichment