Impact
The vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows a low‑privileged attacker with network access to the HTTP interface to obtain unauthorized access to critical data. A successful exploitation can result in the attacker gaining read access to all data exposed by the product, representing a high impact on confidentiality. The weakness is consistent with improper access control, enabling data exposure without authentic privileges and potentially affecting other products due to the scope change noted in the CVSS vector.
Affected Systems
Oracle Corporation’s Oracle Commerce 11.4.0 is affected. No other versions or components are listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 7.7 indicates a high severity with high confidentiality impact and a scope change. The EPSS score of less than 1% shows exploit probability is currently low, and the vulnerability is not yet listed in CISA’s KEV catalog. The apparent attack vector is network‑based via HTTP, and the attack requires only low privilege, so an adversary with remote access could potentially exploit the flaw without higher‑level credentials. This combination of high severity and low exploitation probability suggests that while the risk is significant, active exploitation is currently unlikely unless the vendor issues a patch.
OpenCVE Enrichment