Impact
The vulnerability resides in the Content Acquisition System of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. An attacker who can reach the application over HTTP can bypass normal authentication and retrieve confidential data or, in the worst case, all data managed by the system. The flaw is assigned a CVSS 3.1 base score of 6.8, indicating a moderate threat to confidentiality but no direct impact on integrity or availability.
Affected Systems
Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 is the only clearly affected version listed in the CNA data. No other product releases are mentioned as vulnerable.
Risk and Exploitability
The CVSS score indicates moderate severity, and the EPSS score of <1% suggests that the probability of active exploitation is very low. The vulnerability is not currently included in the CISA KEV catalog, and there is no evidence of widespread attacks. However, the attack vector is network‑based over HTTP without any authentication, which provides a relatively straightforward entry point. A successful exploitation could compromise confidentiality and, due to the scope change flag, potentially expose adjacent Oracle Commerce components.
OpenCVE Enrichment