Impact
A vulnerability exists in Oracle Commerce Guided Search / Oracle Commerce Experience Manager’s Content Acquisition System that allows an unauthenticated attacker, with network access via HTTP, to compromise the application. Successful exploitation leads to unauthorized access to critical data or full access to all accessible data, affecting confidentiality. The CVSS 3.1 Base Score is 7.5, indicating high confidentiality impact.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0, is directly impacted.
Risk and Exploitability
The vulnerability’s CVSS score of 7.5 places it in the high severity range, and with an EPSS score of < 1%, the CVE is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. Attackers require network-level access and can exploit this flaw without authentication or special privileges, making it highly feasible for an adversary with internal or external network reach to leverage the HTTP endpoint for data exfiltration or complete system compromise.
OpenCVE Enrichment