Impact
A vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows an unauthenticated attacker to send specially crafted HTTP requests that bypass authentication and authorization checks, enabling the attacker to create, delete, or modify critical data. The flaw results in severe confidentiality and integrity effects and can lead to total access to all data within the application.
Affected Systems
Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0 are affected. No other versions or components of the product are listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 9.3 classifies the flaw as critical. Exploitation requires network access via HTTP and user interaction from a person other than the attacker, indicating that the attack is user‑interaction dependent but still feasible when the application is exposed to the internet. The EPSS score is less than 1%, indicating a very low but non-zero exploitation probability, and the vulnerability is not listed in CISA KEV. Given its high severity and the lack of mitigation, the risk of exploitation is significant for environments that expose the Commerce application externally.
OpenCVE Enrichment