Impact
A vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows an unauthenticated attacker with network access via HTTP to compromise the system. Exploitation can lead to full takeover of the application, providing the attacker with complete control. The weakness is rated as high severity with a CVSS 3.1 base score of 9.8, indicating complete loss of confidentiality, integrity, and availability.
Affected Systems
Oracle Corporation – Oracle Commerce Guided Search and Oracle Commerce Experience Manager, version 11.4.0 are impacted. No other versions or products are identified as vulnerable in the current advisory.
Risk and Exploitability
The vulnerability is remotely exploitable over standard HTTP traffic without requiring authentication or user interaction, while the EPSS score is < 1%, and the issue is not listed in CISA KEV. The high CVSS score reflects the potential for a successful attack, and organizations should treat this as an urgent threat even though no public exploit has been reported yet. The attack path requires only network reachability to the application, making the risk low‑if not mitigated but potentially catastrophic if successful.
OpenCVE Enrichment