Impact
The Oracle Commerce Guided Search / Oracle Commerce Experience Manager product version 11.4.0 contains an access‑control flaw that allows an attacker who can reach the instance over HTTP to retrieve any data exposed by the web application without authentication. This flaw is a confidentiality‑breaking vulnerability; it does not affect integrity or availability but permits an attacker to view the full data set accessible through the application. The vulnerability is mitigated in later releases, so the primary impact is the potential loss of sensitive information to unauthorized parties.
Affected Systems
All installations of Oracle Commerce Guided Search / Oracle Commerce Experience Manager produced by Oracle, specifically those running the 11.4.0 release, are affected.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 places the flaw in the high severity range. Publicly available exploitation is possible from any network host with HTTP connectivity to the instance, and no authentication or special user privileges are required. The EPSS score is reported as less than 1%, indicating a low probability of exploitation at present, and the flaw is not listed in CISA’s KEV catalog. Because the flaw permits full data disclosure, organizations that expose the product to untrusted networks face a serious confidentiality risk if the vulnerability is exploited.
OpenCVE Enrichment