Impact
Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0 contain a flaw in the Forge component that, when exploited by a low‑privileged attacker with access to the host machine, permits creation, deletion or modification of critical data and can trigger a consistent denial‑of‑service by causing the component to hang or crash. The vulnerability has no effect on confidentiality but high impacts on integrity and availability.
Affected Systems
Affected systems include Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, specifically the 11.4.0 release of these products. Any deployment of this version that permits local login to the host where the component runs is potentially susceptible.
Risk and Exploitability
The CVSS v3.1 base score is 7.1 with an attack vector of local, low‑complexity, low‑privilege, no‑user‑interaction. The EPSS score is below 1 %, indicating a very low probability of current exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Nonetheless, because the attacker only needs local access, the attack vector is likely to be internal users or compromised accounts, making mitigation especially relevant for environments that allow privileged local logons.
OpenCVE Enrichment