Impact
The vulnerability in Oracle Commerce Guided Search 11.4.0 exposes an improper privilege management weakness (CWE‑269) and improper access control (CWE‑284), allowing an unauthenticated attacker to silently create, delete, or modify critical data. The flaw enables the attacker to read any data managed by the product, resulting in confidentiality and integrity loss. The attack is delivered over HTTP without authentication or UI interaction, and the impact applies to both the Guided Search and Experience Manager components of Oracle Commerce.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 indicates a high severity level with deep confidentiality and integrity impacts. The EPSS score of < 1% suggests a low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, an unauthenticated attacker with network access to the HTTP interface can exploit the flaw, making it a significant risk for exposed systems.
OpenCVE Enrichment