Impact
A flaw in the Endeca Application Controller component of Oracle Commerce Guided Search allows an attacker who can send HTTP requests to compromise the platform with high impact on confidentiality and integrity. The vulnerability is easily exploitable and lets an unauthenticated user create, delete, or modify critical data, or gain full read access to all data exposed by the application.
Affected Systems
Oracle Corporation's Oracle Commerce Guided Search and Oracle Commerce Experience Manager, version 11.4.0, are affected.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 indicates critical severity, with no exploitation restrictions noted. The EPSS score is < 1%, and the vulnerability has not yet been listed in CISA’s KEV catalog. Because the flaw is reachable through HTTP and does not require authentication, attackers with network access can exploit it without additional privileges. The existing attack path permits full data compromise, making the risk high for any environment that hosts the vulnerable component.
OpenCVE Enrichment