Impact
The vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager (version 11.4.0) permits an unauthenticated network attacker to perform unauthorized updates, inserts, deletes, and reads of data exposed by the application. The flaw resides in the Endeca Application Controller component and requires human interaction from a user other than the attacker to complete the attack sequence.
Affected Systems
Affected products are Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically version 11.4.0. The vulnerability is listed in the vendor advisory and no other versions or related products are currently identified as impacted.
Risk and Exploitability
The CVSS 3.1 base score is 6.1, indicating medium severity with confidentiality and integrity impacts. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network-based via HTTP, unauthenticated, though human interaction from a person other than the attacker is required. Once the initial exploit is successful, the attacker can alter or delete data and gain read access to sensitive information, presenting a moderate but tangible risk.
OpenCVE Enrichment