Impact
A vulnerability exists in Oracle Commerce Guided Search / Oracle Commerce Experience Manager that can be triggered by an unauthenticated attacker with network access to the application via HTTP. The flaw is an access control weakness that allows unauthorized actions. Successful exploitation requires human interaction from a person other than the attacker, yet a successful attack can result in complete takeover of the Commerce application, affecting confidentiality, integrity, and availability.
Affected Systems
Oracle Corporation’s Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 is affected. No other versions are explicitly listed as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a high severity, yet the EPSS score of less than 1 % suggests that exploitation may not be widespread or easily automated. The vulnerability is not listed in CISA’s KEV catalog, implying no known large‑scale exploitation reports. The likely attack vector is through a basic network HTTP request from an unauthenticated client, though the need for human interaction reduces the feasibility for automated attacks. Consequently, the overall risk is moderate but significant for environments where the affected product is exposed to the internet or an untrusted network.
OpenCVE Enrichment