Impact
This vulnerability allows an unauthenticated attacker with access to the system over HTTP to perform unauthorized update, insert, delete and read operations against data exposed by Oracle Commerce Guided Search / Oracle Commerce Experience Manager. The weakness is a failure of proper access control, which results in a confidential and integrity impact reflected in a base CVSS score of 6.1.
Affected Systems
The flaw exists in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce, version 11.4.0. All installations of this specific version are vulnerable until the vendor releases a mitigated patch.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, with an attacker able to reach the target over the network, though no authentication is required. The EPSS score is less than 1%, indicating a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an HTTP request to the exposed application endpoint, where the attacker can exploit the missing access control through a human‑mediated interaction to gain unauthorized data modification or disclosure. While the risk is moderate, the potential for data confidentiality and integrity compromise warrants attention.
OpenCVE Enrichment