Impact
The Oracle Commerce Guided Search / Oracle Commerce Experience Manager component Endeca Application Controller contains an access control flaw (CWE-284) that permits an attacker who can reach the service over HTTP to read sensitive data and execute unauthorized updates, inserts, or deletions, breaching confidentiality and damaging integrity of the hosted data.
Affected Systems
Oracle Commerce Guided Search and Oracle Commerce Experience Manager, specifically version 11.4.0 of the Endeca Application Controller, are affected. No other product versions are listed as vulnerable.
Risk and Exploitability
The CVSS v3.1 base score is 7.6, indicating high severity. Attackers need only network access over HTTP and low‑privilege credentials, though the exploit requires a secondary user interaction, which reduces practical likelihood. The EPSS score is below 1% and the flaw is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet. The scope change in the vector indicates that successful exploitation could affect a broader data set than originally authorized.
OpenCVE Enrichment