Impact
The vulnerability resides in the Content Acquisition System of Oracle Commerce Guided Search and Oracle Commerce Experience Manager, allowing an unauthenticated attacker with network access via HTTP to compromise the application. The flaw is an instance of improper access control (CWE‑284). Successful exploitation can lead to a full takeover of the application, compromising confidentiality, integrity, and availability.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, version 11.4.0. No other affected versions are listed at this time.
Risk and Exploitability
The CVSS 3.1 base score of 9.0 indicates high severity, with an attack vector over the network via HTTP, high complexity, no authentication, and a change in scope that may affect additional Oracle products. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting that present exploitation is rare but the potential impact remains significant.
OpenCVE Enrichment