Impact
The vulnerability resides in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 and allows an unauthenticated attacker with network access via HTTP to gain unauthorized update, insert, delete, or read operations on data that the product exposes. This leads to confidentiality and integrity impacts as stated in the CVSS 3.1 vector, while availability is not affected.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, specifically version 11.4.0. No other versions or products are listed as impacted in the current data.
Risk and Exploitability
The CVSS base score of 6.1 describes moderate severity. EPSS score of 0.00181 (<1%) indicates a very low exploitation probability, and the vulnerability is not yet listed in CISA KEV. Based on the description, the likely attack vector is an unauthenticated HTTP request; successful exploitation also requires a human interaction from a person other than the attacker, and the scope change indicates that additional related products could be affected by a successful exploit.
OpenCVE Enrichment