Impact
This vulnerability resides in the Endeca Application Controller component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager. An unauthenticated attacker who can reach the product over HTTP can exploit the flaw to update, insert, or delete records and read a subset of accessible data. The flaw requires a human user who is not the attacker to interact with the system, so fully automated exploitation is unlikely, but the impact on data integrity and confidentiality is significant if successful.
Affected Systems
Affected vendors and products include Oracle Corporation's Oracle Commerce Guided Search and Oracle Commerce Experience Manager, specifically version 11.4.0. The issue is scoped to this version, though it may also affect other components that rely on the same data services, potentially expanding its impact beyond the initial product.
Risk and Exploitability
The CVSS v3.1 base score of 6.1 indicates moderate severity, with impacts to confidentiality and integrity. The attack vector is network-based over HTTP, and the requirement for a human to interact with the system reduces the feasibility of fully automated exploitation. The EPSS score is below 1%, suggesting a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Because the flaw allows unauthorized data modification and disclosure, it remains a meaningful risk, especially in environments where sensitive product data is exposed or integrated with other critical services.
OpenCVE Enrichment