Impact
The vulnerability permits an unauthenticated attacker with network access over HTTP to compromise the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component. Successful exploitation results in unauthorized access to critical data, effectively allowing an attacker to read all data accessible through the Experience Manager. The weakness resides in a missing authentication or improper authorization check and is rated with a high confidentiality impact.
Affected Systems
Affected product is Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The CVSS 3.1 base score is 7.5, indicating a high severity due to confidentiality impact. The EPSS score is less than 1%, suggesting low expected exploitation prevalence, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The attack vector is likely via HTTP traffic to the Experience Manager endpoint; no authentication is required for exploitation, making the vulnerability easily exploitable by any network attacker.
OpenCVE Enrichment