Impact
The vulnerability resides in the Experience Manager component of Oracle Commerce Guided Search. An unauthenticated attacker with HTTP network access can compromise the system, but the exploit requires a second user other than the attacker to interact with a crafted request. Successful exploitation permits unauthorized reading of critical commerce data, and the attacker can also modify, insert, or delete data accessible through the application. This is a high‑severity flaw with direct confidentiality and integrity impacts as reflected by the CVSS 3.1 base score of 8.2.
Affected Systems
Oracle Corporation's Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 is affected. The vulnerability has been validated in this specific release; other versions are not reportedly impacted.
Risk and Exploitability
The CVSS score of 8.2 indicates a high likelihood of impact should the flaw be leveraged. The EPSS score is below 1%, so general exploitation activity remains low, and the vulnerability is currently not listed in CISA's KEV catalog. However, the low EPSS does not eliminate the risk of targeted attacks, particularly those that utilize social engineering to trigger the required user interaction. The scope change in the vector hints that the flaw can elevate privileges or affect services beyond the original component, meaning that a successful attack could compromise additional Oracle Commerce products connected to the same environment. Attackers must send a specially crafted HTTP request that tricks a logged‑in user into performing an authorized action; thus the path involves an HTTP request to the vulnerability endpoint combined with a second‑party user interaction.
OpenCVE Enrichment