Impact
A vulnerability resides in the Content Acquisition System of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, enabling an unauthenticated attacker with network access over HTTP to compromise the application. The flaw allows the attacker to read confidential data or, in the worst case, expose all data stored in the instance. The impact is confined to confidentiality, with no direct integrity or availability effects indicated by the CVSS vector.
Affected Systems
The affected product is Oracle Commerce Guided Search (Oracle Commerce Experience Manager) version 11.4.0.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.8, reflecting moderate severity. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request to the application, requiring only network connectivity. Because the flaw can change scope, a successful exploitation may inadvertently affect other related components within the Commerce platform. The risk level is moderate, but the potential for confidential data exposure warrants prompt attention.
OpenCVE Enrichment