Impact
The vulnerability in Oracle Commerce Guided Search and Oracle Commerce Experience Manager allows a low‑privileged attacker with network access over HTTP to exploit a flaw in the Endeca Application Controller, granting unauthorized read or full access to all data exposed by the product, and permitting updates or deletions of that data. The flaw therefore directly compromises confidentiality and integrity of Commerce data.
Affected Systems
The affected systems are Oracle's Commerce Guided Search and Oracle Commerce Experience Manager, version 11.4.0, as identified in the Oracle security advisory.
Risk and Exploitability
The attack requires network connectivity to the HTTP interface, a low‑privileged account, and a user interaction from someone other than the attacker. The CVSS v3.1 base score is 7.6, indicating high severity. Because the EPSS score is 0.00204, the exploitation probability is very low; the vulnerability is not yet listed in CISA KEV, but the need for a user action suggests moderate effort. The scope change noted in the vector indicates that a successful exploitation could potentially affect other Oracle Commerce components beyond the immediate product.
OpenCVE Enrichment