Impact
This vulnerability resides in the Workbench component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. A low‑privileged attacker with network access to the HTTP interface can exploit an improper access control flaw (CWE‑284) that, together with user interaction from a third party, permits unauthorized reading of all data exposed by the Workbench and allows update, insert or delete operations on that data. The impact is a compromise of confidentiality and integrity of critical data, reflected in a CVSS 3.1 score of 7.6.
Affected Systems
Vendors: Oracle Corporation. Product: Oracle Commerce Guided Search / Oracle Commerce Experience Manager, affected version 11.4.0.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity risk. EPSS score of <1% shows a low but non‑zero likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via the Workbench HTTP endpoint; the requirement for human interaction suggests that social engineering or other user‑facilitated actions are sufficient to trigger the exploitation. The risk remains significant because the attacker can gain partial or full access to the data exposed by the component if the user grants cooperation.
OpenCVE Enrichment