Impact
In Oracle Commerce version 11.4.0, the Forge component of the Guided Search/Experience Manager is vulnerable to an easily exploitable flaw that allows an attacker with low privileges and network access over HTTP to bypass authentication controls and read critical data or all data stored in the application. The flaw can also trigger a partial denial‑of‑service effect, reducing the availability of the service for legitimate users.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, version 11.4.0. Only this specific version is documented as affected by the advisory.
Risk and Exploitability
The flaw has a CVSS 3.1 base score of 7.1, indicating significant confidentiality impact and moderate availability impact. An EPSS score of less than 1 percent suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an HTTP request from a low‑privileged network user, where the attacker can gain unauthorized data read access and cause a partial denial of service. No higher privilege escalation is disclosed by the existing data.
OpenCVE Enrichment