Impact
A flaw in the Experience Manager component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows an attacker with low network privileges to interact with a public HTTP endpoint and retrieve data that should be restricted. The vulnerability falls under the category of unauthorized access, meaning that an attacker can read confidential configuration or customer information. Successful exploitation could grant visibility into all data that is available through the guided search interface, exposing sensitive business information without needing to authenticate beyond basic network permissions.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0. No other versions are listed as affected.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates a medium severity with a high confidentiality impact, but the EPSS score of less than 1% reflects a very low likelihood of being exploited by adversaries. The vulnerability is not included in CISA’s KEV catalog, suggesting limited public exploitation. The likely attack vector is over the network via standard HTTP traffic to the exposed endpoint and requires only low privileges; no user interaction or elevated rights are necessary. An attacker who succeeds would obtain read access to all data exposed through the guided search feature.
OpenCVE Enrichment