Impact
The vulnerability resides in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. An unauthenticated attacker who can reach the component over HTTP can cause unauthorized update, insert or delete operations on data the component exposes, and can also read data that is otherwise restricted, granting the attacker both integrity and confidentiality violations as documented by the CVSS vector. This flaw involves weaknesses classified under CWE-284 and CWE-287.
Affected Systems
Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0 is the only explicitly listed affected product; the advisory warns that attacks may also impact other Oracle Commerce products, implying that the vulnerability may have a broader scope than the Guided Search component alone.
Risk and Exploitability
Oracle's advisory lists a CVSS v3.1 base score of 7.2, indicating a high severity with impacts on confidentiality and integrity. The EPSS score is < 1 %, so the probability of exploitation in the wild is low but not negligible, and the vulnerability is not yet flagged in the CISA KEV catalog. The vector (S:C) indicates a scope change, meaning a successful exploit can potentially affect components beyond the Endeca Application Controller or other Oracle Commerce products. Attackers only need unsecured HTTP access from a networkable host; no authentication is required, making the attack path simple and network‑level.
OpenCVE Enrichment