Impact
The flaw resides in the Endeca Application Controller of Oracle Commerce Guided Search and Oracle Commerce Experience Manager, an Access Control: Authorization flaw (CWE-284), that allows any unauthenticated network user to reach a publicly exposed HTTP interface. By sending crafted requests, an attacker can obtain full contents of the product’s data store or cause the application to hang or crash repeatedly, resulting in a complete loss of availability. The vulnerability incurs both confidentiality and availability impacts and is reflected in a CVSS v3.1 base score of 9.1.
Affected Systems
Oracle Commerce Guided Search and Oracle Commerce Experience Manager, version 11.4.0, are affected.
Risk and Exploitability
The CVSS score of 9.1 signals high severity. The EPSS score of < 1% indicates a very low exploitation probability in the wild, yet the vulnerability remains high risk because attackers need no credentials and only require network access to the exposed HTTP port. The flaw is not listed in CISA’s KEV catalog, but its remote exploitation route makes it a serious threat if the service is reachable.
OpenCVE Enrichment