Impact
The Oracle Commerce Guided Search / Oracle Commerce Experience Manager product contains a vulnerability that, when triggered by a high‑privileged attacker with network access via HTTP, can result in unauthorized access to critical data or complete access to all data managed by the product. The flaw is easily exploitable and is categorized as a privilege‑rights escalation issue. Successful exploitation would compromise confidentiality, allowing an attacker who gains authenticated network access to read protected data.
Affected Systems
Affected systems are Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. The product is distributed by Oracle Corporation and is deployed on the Oracle Commerce platform.
Risk and Exploitability
The CVSS v3.1 base score of 6.8 indicates a moderate severity level, but the vulnerability includes a scope change which means compromise can lead to a full breach of the system. The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over the network via HTTP, and an attacker with appropriate credentials could exploit the flaw to read or exfiltrate protected data.
OpenCVE Enrichment