Impact
The vulnerability, found in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component, allows an attacker with high privileges but only network access via HTTP to take control of the application. Successful exploitation can lead to unauthorized access to critical data or full access to all data managed by the product. The vulnerability is considered easily exploitable and is identified by CVSS 3.1 with an AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N score of 6.8.
Affected Systems
Affected systems include Oracle Corporation's Oracle Commerce Guided Search and Oracle Commerce Experience Manager 11.4.0. No other product versions are listed as impacted, but the description indicates that attacks may change scope to affect additional products.
Risk and Exploitability
The CVSS base score of 6.8 reflects a moderate severity with a confidentiality impact. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in CISA's KEV catalog. Due to the network-based attack vector over HTTP and the requirement of high-level privileges, the risk is moderate; however, the potential for scope change increases the threat if an attacker can leverage the vulnerability to move laterally within the organization.
OpenCVE Enrichment