Impact
The vulnerability in Oracle Commerce Guided Search and Oracle Commerce Experience Manager allows an unauthenticated attacker with network access over HTTP to influence data operations. By exploiting a coding flaw, the attacker can insert, update, delete, or read data that the Experience Manager exposes, compromising both confidentiality and integrity. The flaw, identified as a combination of improper access control and information disclosure weaknesses, still requires human interaction to trigger the exploit, but once activated it provides the attacker with direct, unauthorized manipulation of application data.
Affected Systems
Version 11.4.0 of Oracle Commerce Guided Search / Oracle Commerce Experience Manager is affected. The product family includes all components collectively referred to as Experience Manager under the Oracle Commerce Guided Search umbrella.
Risk and Exploitability
The CVSS 3.1 base score of 6.1 classifies this vulnerability as moderate severity, with network access, low attack complexity, but requiring user interaction. The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated attacker sending crafted HTTP requests to the Experience Manager, relying on a cooperating human user to complete the interaction. Overall, while the risk is not critical, the potential for unauthorized data manipulation warrants prompt attention.
OpenCVE Enrichment