Impact
The flaw resides in the Content Acquisition System of Oracle Commerce Guided Search, exposing an access control weakness. An attacker who does not need credentials can create, delete, or alter critical data, or force the system to hang or crash. The vulnerability has a CVSS 3.1 base score of 9.1, indicating severe integrity and availability impact.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, version 11.4.0, are affected. No other versions or products are mentioned.
Risk and Exploitability
The attack vector is purely network‑based, requiring only HTTP access without authentication, so any exposed instance is vulnerable. The EPSS score of less than 1 % indicates low current exploitation likelihood, but the high CVSS and the absence of a CISA KEV listing still demand rapid remediation. Exploitation would allow an unauthenticated actor to compromise data integrity and disrupt service availability.
OpenCVE Enrichment