Impact
This vulnerability allows an attacker with low privileges and network access to Oracle Commerce Guided Search / Oracle Commerce Experience Manager to compromise the system over HTTP. The exploitation requires human interaction from a user other than the attacker, and results in the ability to create, delete, or modify critical data as well as to gain unauthorized access to all product data, thereby impacting both confidentiality and integrity.
Affected Systems
Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0 are affected. The vulnerability was identified in the Experience Manager component of Oracle Commerce.
Risk and Exploitability
The CVSS base score of 8.7 indicates a high severity, but the EPSS score is not available and the vulnerability is not listed in CISA KEV, so current exploitation probability is unknown. Exploitation requires a low‑privileged attacker, network access on an HTTP interface, and user interaction from a different person, suggesting that the likelihood of successful attacks depends on network exposure and user compliance. Because the vulnerability can change the scope to affect additional products, it is considered a serious risk if the environment is accessible over the network.
OpenCVE Enrichment