Impact
The vulnerability in Oracle Commerce Guided Search 11.4.0 allows an unauthenticated attacker with network access through HTTP to gain unauthorized control over critical data. Successful exploitation permits the creation, deletion or modification of data and grants full read access to all data managed by the product. The flaw resides in improper access control, exposing the system to confidentiality and integrity loss while the availability impact is negligible.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, version 11.4.0.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 indicates a high severity level, with confidentiality and integrity impacts. The EPSS score of < 1% denotes a low probability of exploitation in the current threat landscape, and the product is not listed in CISA’s KEV catalog. Nevertheless, the vulnerability permits unauthenticated discovery and exploitation over HTTP, so based on the description, it is inferred that systems exposed to the network face moderate potential for attack if no network segmentation or mitigations are in place.
OpenCVE Enrichment