Impact
A vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 allows an unauthenticated attacker with network access over HTTP to retrieve confidential data. The flaw is an information exposure issue that also represents an improper access control weakness (CWE‑284). If exploited, the attacker could access any data exposed through the Content Acquisition System, effectively gaining read‑only access to the entire searchable dataset.
Affected Systems
The affected product is Oracle Commerce Guided Search / Oracle Commerce Experience Manager from Oracle Corporation, with version 11.4.0 specifically impacted. While the vulnerability is localized to this component, the impact may propagate to other Oracle Commerce products if shared data is accessed.
Risk and Exploitability
The CVSS base score of 6.8 reflects a moderate severity with a confidentiality impact. The EPSS score of less than 1 % indicates a very low, but non‑zero, likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, and it requires only a remote HTTP connection with no authentication. Although exploitation is possible, the low exploitation probability and the lack of a public exploit inventory suggest that immediate remediation will largely reduce exposure.
OpenCVE Enrichment