Impact
Oracle Commerce Guided Search and Oracle Commerce Experience Manager allow an unauthenticated attacker, via HTTP, to read sensitive information and to perform update, insert or delete operations on selective data. The flaw results in a loss of confidentiality and a breach of data integrity, as the attacker can tamper with or remove critical Commerce data. This weakness is a classic example of improper access control combined with insufficient authentication.
Affected Systems
Affected vendor is Oracle Corporation. The product at risk is Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. No other versions or components are currently listed as vulnerable.
Risk and Exploitability
The CVSS base score of 8.2 marks this vulnerability as high severity, and the EPSS score indicates a very low exploitation probability (<1%). It is not currently listed in the CISA KEV catalog. The likely attack vector is an unauthenticated, network‑level HTTP request to the exposed service, requiring no prior credentials. Because the vulnerability is straightforward to exploit from any network with HTTP access, the overall risk remains significant, especially if the service is exposed to external networks.
OpenCVE Enrichment