Impact
A flaw in the Forge component of Oracle Commerce Guided Search/Experience Manager allows a low‑privileged attacker who can reach the service over HTTP to bypass authentication checks. The vulnerability can lead to unauthorized reading of critical data, full access to all data exposed by the Commerce solution, and the ability to cause a partial denial of service by disrupting application functionality. It is a classic authentication bypass and access control weakness.
Affected Systems
Affected systems are Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. No other product variants or versions are reported by the CNA.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 classifies this issue as medium‑high risk, requiring only network access, low attack complexity, and low privileges. The EPSS score below 1% indicates that exploitation is predicted to be rare, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is through unauthenticated HTTP requests to the affected Forge component, meaning exposed instances are at significant risk if not patched.
OpenCVE Enrichment