Impact
This flaw is within a component that acquires content for Oracle Commerce Guided Search. An attacker who can reach the application over the network, without authentication, can trigger the flaw. The effect is twofold: the system can be repeatedly crashed, causing a complete denial of service, and the attacker can execute update, insert or delete operations against data that should be protected. The vulnerability impacts integrity and availability, as reflected in the CVSS vector of AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H.
Affected Systems
Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0 are affected. No other product or version information is listed.
Risk and Exploitability
The CVSS base score of 8.2 indicates a high severity. Exploitation requires only unauthenticated HTTP access, implying that any host exposed to the network is at risk. Attackers do not need privileges on the appliance and can achieve a DoS or modify data. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. Given the high impact and low effort needed to exploit, monitoring and patching are critical.
OpenCVE Enrichment