Impact
The Oracle Commerce Guided Search and Experience Manager product contains a flaw that allows an unauthenticated attacker to send HTTP requests to the server and create, delete, or modify critical data. This unauthorized data manipulation compromises confidentiality and integrity of all data exposed by the application, while availability remains largely unaffected. The flaw is identified as an Access Control weakness and scores 7.4 on the CVSS v3.1 scale.
Affected Systems
Only Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0 is affected.
Risk and Exploitability
The attack vector is network‑based HTTP access that requires no authentication or privileged user context. Because the CVSS score is 7.4, the vulnerability carries a moderate‑to‑high security impact. The EPSS score is less than 1% indicating a very low exploitation probability, but the absence of a KEV listing does not preclude potential abuse. Organizations exposing this software should treat it as a high‑priority risk and plan remediation promptly.
OpenCVE Enrichment