Impact
The vulnerability resides in the Endeca Application Controller component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager. An attacker who can reach the exposed HTTP endpoint without authentication can create, delete, or modify critical data or gain full access to all accessible data, thereby breaching confidentiality and integrity.
Affected Systems
Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0, specifically the Endeca Application Controller component.
Risk and Exploitability
The flaw is easily exploitable because it requires only network access to an unauthenticated HTTP endpoint. The CVSS 3.1 base score of 9.1 indicates a high severity, while the EPSS score of <1% suggests a low probability of immediate exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the issue over the network to alter or access critical data, potentially causing significant business impact.
OpenCVE Enrichment