Impact
A vulnerability in the Experience Manager component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager allows an unauthenticated attacker who can reach the system over HTTP to read critical data or all data available through the product and to cause a hang or a repeatable crash, resulting in denial of service. The flaw enables remote access without credentials, leading to high confidentiality damage and complete availability loss. The weakness is rooted in improper access control, as the system fails to enforce authentication or authorization before processing user requests.
Affected Systems
The exploitation applies to Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. Only this specific release is documented as affected; earlier or later patches are not mentioned.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 signals a severe risk, with the vector indicating network accessibility, low attack complexity, and no user interaction. The EPSS score of less than 1% indicates that, as of the latest data, the probability of exploitation is low, yet the high severity underscores the potential damage. The vulnerability is not listed in CISA’s KEV catalog, but an unauthenticated attacker can still access sensitive data and cause a full system‑wide denial of service by sending crafted requests over HTTP.
OpenCVE Enrichment