Impact
The vulnerability is an authentication bypass that allows an attacker who can reach the application over HTTP to perform unauthorized insert, update, delete, and read operations on data exposed by Oracle Commerce Guided Search and Oracle Commerce Experience Manager. In addition, the flaw permits the attacker to cause a partial denial of service by disrupting normal application operation. This vulnerability is classified as a missing access control weakness and is assigned a CVSS 3.1 base score of 7.3, indicating high impact on confidentiality, integrity and availability.
Affected Systems
Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0 are affected. The vulnerability resides in the Experience Manager component of these products.
Risk and Exploitability
The EPSS score of less than 1 % indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the flaw can be exercised by sending a crafted HTTP request from any network location that can reach the server, without authentication or user interaction. Successful exploitation would allow unauthorized data tampering and a partial loss of availability, which could impact e‑commerce operations. This vulnerability is classified as a missing access control weakness and is assigned a CVSS 3.1 base score of 7.3. The CVSS vector (network access, low attack complexity, no privileges, no user interaction) shows the attacker’s path is straightforward.
OpenCVE Enrichment