Impact
A vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 allows an unauthenticated attacker who has access to the underlying infrastructure to compromise the component. The flaw is a local privilege escalation that requires the attacker to obtain user interaction from a person other than the attacker. Successful exploitation can lead to full takeover of the product, resulting in loss of confidentiality, integrity, and availability, as indicated by the CVSS 3.1 score of 7.8.
Affected Systems
The affected products are Oracle Commerce Guided Search and Oracle Commerce Experience Manager from Oracle Corporation, specifically version 11.4.0. Deployments running this version are potentially vulnerable.
Risk and Exploitability
A CVSS 3.1 base score of 7.8 indicates a high impact vulnerability. The vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) shows that the flaw is exploitable with local access to the infrastructure where Oracle Commerce Guided Search/Experience Manager runs, without requiring authentication to the application, but manual interaction from a user other than the attacker is required. EPSS is below 1%, implying a low but non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local exploitation by an attacker with infrastructure access who then persuades or coaxes a legitimate user to trigger the vulnerable code.
OpenCVE Enrichment