Impact
The vulnerability lies in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. An unauthenticated attacker who can reach the application over HTTP may exploit a flaw that bypasses access controls, allowing unauthorized read access to critical data and, because the vulnerability changes the scope, unauthorized update, insert, or delete operations. The weakness is an improper access control issue (CWE‑284) that primarily threatens confidentiality and to a lesser extent integrity.
Affected Systems
Only Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 is listed as affected in this CVE. No other product versions or components are mentioned. The vulnerability is specific to the Endeca Application Controller within that version, but the scope‑changing nature could bring other Oracle products into risk if they share the same environment.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 classifies this as high severity, with high confidentiality impact and low integrity impact; availability is unaffected. The EPSS score is reported as less than 1 %, indicating a very low but nonzero probability of exploitation at the time of analysis, and the item is not listed in the CISA KEV catalog. Attackers can exercise this flaw over the network using standard HTTP traffic, but successful exploitation requires a separate user to interact with the application, which limits the ease of remote compromise. Despite the low EPSS, the high CVSS and the corporate significance of Oracle Commerce warrant rapid remediation.
OpenCVE Enrichment