Impact
A vulnerability exists in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0, within its Content Acquisition System component, that arises from a broken access control flaw (CWE‑284). The flaw allows a low‑privileged attacker with local logon to the server to compromise the application, giving unauthorized access to critical data. No user interaction is required; only local privileges are needed, resulting in a high confidentiality impact.
Affected Systems
The affected product is Oracle Corporation:Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0, specifically the Content Acquisition System component. The weakness is a broken access control flaw (CWE‑284). Through scope changes the vulnerability may also affect other Oracle Commerce products.
Risk and Exploitability
The CVSS base score is 6.5 with a confidentiality impact rating of High. The EPSS score is below 1 % and the vulnerability is not catalogued in CISA KEV. Exploitation requires local logon and low privileges, but the ease of exploitation combined with the potential to pivot to other components increases the risk. An attacker who can authenticate locally will be able to leverage this flaw to gain unauthorized access to critical application data.
OpenCVE Enrichment