Impact
The vulnerability exists in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically version 11.4.0. An attacker can exploit the flaw over HTTP without authentication to gain unauthorized access to sensitive data or to carry out insert, update, or delete operations on that data. This leads to confidentiality compromise and potential integrity violations for the application's content and configuration. The weakness is categorized as an improper access control problem, allowing privileged operations to be performed by unauthenticated users.
Affected Systems
Vulnerable systems are Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0. No other versions were identified as affected; the patch or newer release should be applied to remediated deployments.
Risk and Exploitability
The CVSS v3.1 base score of 8.2 reflects a high impact with moderate difficulty. The EPSS score of 0.003 (0.3%) indicates a very low yet non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploitation at this time. The attack likely proceeds over an exposed HTTP interface, requiring network access but no local privileges. Successful exploitation demands human interaction from a user other than the attacker, which may involve social engineering or legitimate user participation. The reported scope change means that a compromised instance of Oracle Commerce Guided Search / Oracle Commerce Experience Manager could affect additional Oracle products that interact with it, further amplifying the potential damage.
OpenCVE Enrichment