Impact
A flaw in the Endeca Application Controller of Oracle Commerce Guided Search allows a low‑privileged attacker who can log onto the underlying host to compromise the application. Successful exploitation results in a full takeover, granting the attacker complete control and affecting the confidentiality, integrity, and availability of the system. The CVSS 3.1 Base Score of 7.0 reflects a local attack with high complexity, low privileges and no user interaction.
Affected Systems
The vulnerability is present only in Oracle Commerce Guided Search (also referred to as Oracle Commerce Experience Manager) version 11.4.0. No other versions in the supplied data are affected.
Risk and Exploitability
The EPSS score is below 1 %, indicating a very low probability of exploitation at the moment, and the flaw is not listed in the CISA KEV catalog. Nevertheless, the moderate‑to‑high CVSS score classifies it as a significant risk. Exploitation requires a local attacker with system access, making the danger greatest in environments where the application runs on shared or untrusted hosts. Consequently, timely patching and strict access controls are essential to mitigate the threat.
OpenCVE Enrichment