Impact
The vulnerability in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows a local attacker with existing logon credentials to compromise the application. A successful exploitation permits the attacker to read or obtain all data accessible through the application, effectively breaching confidentiality. Based on the description, it is inferred that improper access control enables reading of protected data without proper authorization.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, specifically version 11.4.0, are affected. No other versions or products were identified, and this applies only to installations where the Endeca Application Controller is present.
Risk and Exploitability
The vulnerability receives a CVSS base score of 5.5, indicating moderate severity, with local access required and low privileges sufficient for exploitation. EPSS indicates a very low exploitation probability (<1%), and the vulnerability is not listed in CISA’s KEV catalog, suggesting no current evidence of widespread exploitation. The attack would need a user or process on the same host to interact with the application controller, but once achieved, the attacker can read critical data exposed by the application.
OpenCVE Enrichment