Impact
The vulnerability resides in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It allows an unauthenticated attacker with network access via HTTP to compromise the system. The flaw results in unauthorized access to critical data and gives the attacker full read access to all accessible data. Attackers can also perform unauthorized inserts, updates, and deletes, thereby compromising data integrity. The weakness is categorized as improper access control (CWE‑284).
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, specifically the 11.4.0 release, is affected. No other versions or products are listed as impacted in the available data. The vendor product names are Oracle Commerce Guided Search and Oracle Commerce Experience Manager.
Risk and Exploitability
The CVSS v3.1 score of 9.3 indicates critical severity with high confidentiality impact and low integrity impact. The EPSS score of < 1% reflects a very low but nonzero chance of exploitation, yet given the easily exploitable nature and unauthenticated attack vector, the risk remains non‑negligible. The vulnerability is not listed in the CISA KEV catalog, yet it can significantly impact additional products if the scope changes as noted in the advisory. Attackers can exploit the flaw over HTTP without authentication, making remediation a priority.
OpenCVE Enrichment