Impact
A local flaw exists in the Content Acquisition System component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0. This Authorization Bypass (CWE‑284) flaw allows an unauthenticated user who can log into the underlying infrastructure to read all data handled by the application, thereby causing unauthorized disclosure of critical information. The vulnerability does not rely on privileged credentials, but it does require a human‑initiated action performed by someone other than the attacker.
Affected Systems
The affected product is Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. No other versions or products are listed as impacted in the CNA data, although the impact scope may potentially affect additional components within the same environment.
Risk and Exploitability
The CVSS score of 6.3 indicates a medium‑severity issue. Because the attack vector is local (AV:L) and requires user interaction (UI:R), the likelihood of exploitation is less than for purely remote flaws. The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting that no public exploits are known. Nevertheless, environments running the affected version should treat the flaw as a risk to data confidentiality and address it promptly.
OpenCVE Enrichment