Impact
The vulnerability allows an unauthenticated user who can reach the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component over HTTP to update, insert, delete or read data. By bypassing normal access controls, the attacker can alter configuration or product information, potentially disrupting business operations or exposing sensitive data. The weakness is an access control deficiency without proper authentication or authorization checks.
Affected Systems
Affected are Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0, specifically the Endeca Application Controller component. The flaw is known to affect this version, and because the vulnerability changes scope, it may also impact other components of Oracle Commerce products.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 indicates a high impact on confidentiality and integrity with affected values C:L, I:L. The EPSS score is below 1 %, suggesting a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Compromise is achievable through network access over HTTP without authentication, making exploitation straightforward for an external actor, but the low EPSS indicates that such attacks are rare at present. Nevertheless, the potential for data modification or disclosure warrants immediate remediation.
OpenCVE Enrichment