Impact
The vulnerability allows an unauthenticated attacker with network access to use HTTP requests against the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. This vulnerability is a CWE‑284 Improper Access Control flaw. By sending specially crafted requests, the attacker can create, delete, or modify critical data that the application can access, resulting in loss of data confidentiality and integrity. The problem is described as an easy-to-exploit flaw that removes the need for any form of authentication before data‑changing operations can be performed.
Affected Systems
Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 supplied by Oracle Corporation is affected. No other versions or related products are listed in the CNA information.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 indicates a severe impact on confidentiality and integrity. The EPSS score of less than 1% reflects a low probability of exploitation under current conditions, but the vulnerability’s lack of authentication and public HTTP exposure provide a straightforward attack path for anyone with network visibility. Although the statistical exploitation likelihood is small, the potential damage warrants immediate remediation, and the flaw is not listed in the CISA KEV catalog.
OpenCVE Enrichment