Impact
A flaw within the internal operations component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows an unauthenticated attacker with network access via HTTP to gain unauthorized write and read permissions to restricted data. The vulnerability is tied to improper authorization controls, enabling updates, insertions, or deletions of data and the disclosure of sensitive information. This role‑bypass weakness can be triggered through an HTTP request that necessitates human interaction from a user other than the attacker but does not require any existing credentials.
Affected Systems
The affected product is Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0, distributed by Oracle Corporation. No other product versions or vendors are reported to be impacted.
Risk and Exploitability
The CVSS 3.1 score of 6.1 classifies the risk as medium, with confidentiality and integrity impacts but no availability impact. The EPSS score of less than 1 % indicates a very low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because exploitation requires a user to interact with the HTTP interface, the likelihood of widespread automated attacks is limited, yet the potential for human‑initiated compromise remains. The scope change indicates that other integrated products could also be affected if they rely on this component.
OpenCVE Enrichment