Impact
A vulnerability exists in the Content Acquisition System of Oracle Commerce Guided Search and Oracle Commerce Experience Manager that allows an attacker to authenticate without credentials. The flaw permits the attacker to read, manipulate, or exfiltrate sensitive data, resulting in severe confidentiality impacts. The weakness is rooted in insufficient authentication and access control safeguards, as indicated by the relevant CWE identifiers.
Affected Systems
The flaw affects Oracle Commerce Guided Search and Oracle Commerce Experience Manager, specifically version 11.4.0. The vulnerability resides in the component responsible for acquiring product content from external sources and is reachable through HTTP interfaces exposed by the product.
Risk and Exploitability
The CVSS 3.1 base score of 7.5, combined with an attack vector of network access, low attack complexity, no privileges, and no user interaction, indicates a high risk of exploitation. The EPSS score is less than 1%, suggesting that while exploitation is technically straightforward, it is not frequently seen in the wild. The flaw is not listed in the CISA KEV catalog. The attack path involves sending crafted HTTP requests to endpoints that bypass authentication checks, enabling unauthorized access to all data available through the affected instance.
OpenCVE Enrichment