Impact
This vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows a low‑privileged attacker with network access over HTTP to create, delete, or modify critical data and to read all data stored in the application. The impact includes both confidentiality and integrity loss, as the attacker can gain unauthorized access to sensitive information and alter business data. The weakness involves inadequate access control that permits an attacker to perform actions beyond the intended authorization limits.
Affected Systems
The only affected product is Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, version 11.4.0. No other products or versions are listed as vulnerable.
Risk and Exploitability
The vulnerability has a CVSS v3.1 base score of 8.1, indicating high severity. It is exploitable over a network via HTTP, requiring only low privileges and no user interaction, which lowers the barrier for attackers. The EPSS score of less than 1% suggests that it is not frequently exploited, but the ease of exploitation combined with the sensitive data at risk keeps the threat significant. The vulnerability is not listed in the CISA KEV catalog, yet its potential for data compromise warrants prompt attention.
OpenCVE Enrichment