Impact
The vulnerability resides in the Content Acquisition System component of Oracle Commerce Guided Search/Experience Manager. A low‑privileged attacker with network access over HTTP can exploit the flaw to gain unauthorized access to all data that the product can retrieve. The vulnerability permits disclosure of confidential information without any user interaction and represents a classic case of improper authorization (CWE‑284).
Affected Systems
Affected product is Oracle Commerce Guided Search / Oracle Commerce Experience Manager from Oracle Corporation, version 11.4.0. No other versions are listed as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 7.7 reflects a high‑severity risk with confidentiality impact only. The attack vector is via network and requires low privileges; there is no user interaction. The EPSS score is less than 1%, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Given the ease of exploitation from a remote HTTP connection, an attacker that can reach the target network could potentially compromise the product, and the known scope change means additional products in the environment may be vulnerable as well.
OpenCVE Enrichment