Impact
Vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 allows an unauthenticated attacker to send HTTP requests to the Content Acquisition System and gain read access to all data stored within the platform. The flaw is an access‑control weakness (CWE‑284) that directly compromises confidentiality, enabling an attacker to view customer information, product catalogs, or any proprietary content. The vulnerability does not affect integrity or availability, but its high confidentiality impact amplifies the risk of data exposure.
Affected Systems
Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 is affected. No other versions are reported as vulnerable by Oracle.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a high severity risk. EPSS is below 1 %, suggesting a low but non‑zero probability of exploitation in the wild, and the issue is not listed in CISA KEV catalog. The path of exploitation is a plain HTTP request to the Content Acquisition System endpoint, requiring no authentication. Given the lack of network restrictions, attackers with network reach can directly target the service and extract sensitive data.
OpenCVE Enrichment