Impact
Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 contains a flaw that permits a low‑privileged attacker with HTTP network access to bypass normal authorization controls. A successful exploitation leads to unauthorized disclosure of confidential data, full read access to all application‑managed data, and the ability to trigger a partial denial of service.
Affected Systems
The vulnerability is specific to Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager, affecting only the 11.4.0 release. No other versions are listed as impacted in the CNA advisory.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 signals high severity, with confidentiality impact rated as high and availability impact moderate. Although the EPSS score is <1%, indicating a low overall probability of exploitation, the advisory describes the flaw as easily exploitable by an attacker who has access. The vulnerability is not yet listed in the CISA KEV catalog, but the combination of remote HTTP access and low privilege requirements makes it a compelling target for adversaries.
OpenCVE Enrichment