Impact
This vulnerability exists in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 and is an access‑control flaw (CWE‑284) that allows a low‑privileged attacker with network access over HTTP to create, delete, or modify critical data and read data that should not be available. The ability to manipulate or read protected data undermines the integrity and confidentiality of the application’s information. The description explicitly states that the flaw is *easily exploitable* by an attacker with low privileges and HTTP access, indicating that no additional permissions are required beyond the initial network reach.
Affected Systems
Oracle Corporation – Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0. The scope change noted in the advisory means that other Oracle Commerce components could also be affected by this access‑control abuse.
Risk and Exploitability
The CVSS base score of 8.5 denotes high severity, while the EPSS score of less than 1 % suggests that exploitation is currently rare or unlikely. Because the attack requires only publicly reachable HTTP access and low privileges, it can be launched from either internal or external networks that can contact the Commerce instance. Despite the low probability of exploitation, the potential impact on confidentiality and integrity is significant enough that the vulnerability is a serious concern. The advisory notes that the issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment