Impact
A vulnerability exists in the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. It allows an attacker who has no authentication credentials but can reach the application over HTTP to create, delete or modify critical data that the application exposes. The flaw also permits the attacker to repeatedly cause the application to hang or crash, resulting in a denial‑of‑service condition for all users accessing the system. The impact breaches both data integrity and availability by letting unauthenticated users alter important content and by interrupting normal service operation.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically version 11.4.0 of the product, is affected. No other versions are disclosed as vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 9.1 highlights a critical severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is an unauthenticated network flow over HTTP, as the description states the attacker only needs network access to the HTTP endpoint of the application. No special privileges or configuration changes are required, making the vulnerability easily exploitable in a remote scenario.
OpenCVE Enrichment