Impact
The vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows a low‑privileged attacker, who has network access via HTTP, to gain unauthorized access to critical data. The exploit enables the attacker to read or exfiltrate sensitive information across the system. CVSS 3.1 scores a 7.7 Base score with a high confidentiality impact and a scope change from local to potentially global. This escalation gives the attacker effectively more control than the original low privilege level, leading to full disclosure of accessible data.
Affected Systems
Oracle Corporation’s Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. No other vendors or products are listed as affected in the CNA data.
Risk and Exploitability
The attack vector is likely over the web through standard HTTP. A low‑privileged user can trigger the flaw remotely, so a simple network connection is sufficient. The EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation in the wild. The CVSS score of 7.7 classifies it as high severity, yet it is not present in the CISA KEV catalog, suggesting no known widespread exploitation at this time.
OpenCVE Enrichment