Impact
A flaw in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0’s Forge component allows an unauthenticated attacker who can reach the system over HTTP to gain unauthorized access to critical or all stored data, and to trigger a partial denial of service. The vulnerability bypasses authentication and authorization checks, exposing sensitive information and lowering service availability. According to the CVSS vector, confidentiality is severely impacted while availability experiences a moderate downgrade.
Affected Systems
Oracle’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, version 11.4.0, are affected. Administrators should verify whether these components are deployed and exposed to external networks and confirm the installed version.
Risk and Exploitability
The CVSS Base Score of 8.2 indicates high severity, highlighting the risk of data disclosure and partial service interruption. The EPSS score of less than 1% suggests that exploitation is currently infrequent, but the absence of authentication requirements means the attack path is straightforward for an attacker with network access via HTTP. The vulnerability is not listed in the CISA KEV catalog at this time, yet its potential for remote data exposure and downtime warrants careful attention. The attacker could compromise the system entirely without credentials, making the overall risk significant for exposed deployments.
OpenCVE Enrichment