Impact
A flaw in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component “Forge” enables an attacker to gain unauthorized access to application data and to exploit configuration flaws that allow data alteration or deletion. Successful exploitation can lead to the disclosure of confidential information, the tampering of searchable content, or the triggering of application hangs and crashes, causing a complete denial of service to legitimate users.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 is known to be vulnerable. No other versions or editions appear to be affected at this time.
Risk and Exploitability
The vulnerability requires the attacker to be connected to the same physical communication segment as the server hosting the component, indicating a local‑segment attack vector; this inference is made because the description specifies "unauthenticated attacker with access to the physical communication segment." The EPSS score is below 1%, suggesting a low probability of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. Nevertheless, the CVSS base score of 7.1, coupled with the potential for both confidentiality and availability compromise, demands that the flaw be treated as a moderate‑to‑high priority. Defenses should focus on preventing local network access and monitoring for signs of unauthorized activity.
OpenCVE Enrichment