Impact
Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 contains an authentication bypass that allows an unauthenticated attacker with network access via HTTP to update, insert, delete, or read data exposed by the product. The attack requires a human participant other than the attacker, and the vulnerability can potentially alter the scope to impact additional components of the Commerce platform. Successful exploitation directly compromises data confidentiality and integrity by enabling unauthorized tampering and disclosure of sensitive information.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0, is the only product affected by this vulnerability according to the advisory.
Risk and Exploitability
The CVSS base score of 6.1 indicates medium severity, with confidentiality and integrity impacts and no availability loss. The EPSS score of < 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a network‑based request over HTTP exploiting the lack of authentication. Because the flaw requires human interaction, the overall threat is reduced compared to purely remote exploitation, but the potential for data corruption or disclosure remains significant for environments exposed to external traffic.
OpenCVE Enrichment