Impact
A flaw in Oracle Commerce Guided Search / Oracle Commerce Experience Manager’s Endeca Application Controller component allows an unauthenticated attacker to retrieve critical data via an HTTP request, resulting in full exposure of all data available through the service. The vulnerability allows bypassing access controls, enabling unauthorized access. Based on the description, it is inferred that the attack requires only network connectivity to the HTTP interface and does not rely on user credentials. The compromise impacts confidentiality by revealing sensitive information that can be used for further malicious activities. This flaw aligns with CWE-284.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 is affected. The advisory notes that attacks may also compromise additional connected Oracle Commerce components, potentially expanding the impact beyond the initial product.
Risk and Exploitability
The vulnerability receives a CVSS 3.1 base score of 8.6, classifying it as high severity. The EPSS score of < 1% indicates a low probability of exploitation, yet the unauthenticated nature and reliance on HTTP access could lead opportunistic attackers to target it. This flaw aligns with CWE-284 and results in a scope change, meaning that a successful breach could extend to other services under the same application umbrella. The product is not listed in the CISA KEV catalog, so the likelihood of widespread exploitation depends on the public availability of the vulnerability details.
OpenCVE Enrichment