Impact
A flaw in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 allows an unauthenticated attacker to connect to the system via SOAP interfaces and bypass authentication safeguards, thereby exploiting improper authentication and improper access control. This vulnerability enables the attacker to retrieve or view critical data, resulting in a serious confidentiality compromise and possible unauthorized access to all data exposed by the guided search component.
Affected Systems
The scope of the vulnerability covers Oracle Commerce Guided Search and Oracle Commerce Experience Manager, both at version 11.4.0. It specifically targets the Forge component that processes SOAP requests.
Risk and Exploitability
The CVSS base score of 7.5 highlights high severity, especially for confidentiality. The attacker can exploit the weakness over the network using SOAP endpoints without authentication, requiring minimal effort once the endpoint is reachable. The EPSS score is < 1%, indicating a very low exploitation probability, but the vulnerability remains unmitigated and could still be exploited if discovered. The vulnerability is not listed in CISA KEV, yet the potential impact warrants prompt remediation. Exploitation requires knowledge of the specific SOAP endpoints and the opportunity to bypass authentication within the Oracle Commerce platform.
OpenCVE Enrichment