Impact
The vulnerability is present in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It allows an attacker who possesses low privileges and network access over HTTP to compromise the Experience Manager component. The failure permits the attacker to obtain all data exposed by the component, whether critical or non‑critical, and to trigger a partial denial‑of‑service that reduces the component’s availability. The weakness is categorized as CWE‑284, indicating improper access control that enables unauthorized data access. The CVSS v3.1 score of 7.1 reflects medium‑high severity; the low attack complexity and low privileges required make exploitation straightforward for any network‑visible attacker.
Affected Systems
Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0, delivered by Oracle Corporation, is the single affected product. Systems that expose the Experience Manager component to HTTP traffic are vulnerable; no other Oracle products are impacted. Administrator guidance: verify that the installed version matches the affected version list and that the Experience Manager service is reachable from untrusted zones.
Risk and Exploitability
The EPSS score of < 1% indicates a low probability of exploitation in the wild, yet the text explicitly states the vulnerability is easily exploitable via network traffic. The CVSS base score of 7.1 shows medium‑to‑high risk when combined with the fact that the attack vector is local network and requires only low privileges. As the vulnerability is not listed in the CISA KEV catalog, no widespread exploitation has been reported to date, but the potential for confidential data exposure or service degradation remains significant.
OpenCVE Enrichment