Impact
The vulnerability resides in the Forge component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager, which is exposed to the public internet via HTTP. It is an unauthenticated flaw that, if exploited, allows an attacker to take full control of the application. The weakness corresponds to CWE‑269 Improper Privilege Management, permitting unauthenticated users to perform privileged operations.
Affected Systems
Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0 are affected. The issue is reported in the Forge module used by these products and only applies to the 11.4.0 release.
Risk and Exploitability
The CVSS base score is 8.1, which reflects full confidentiality, integrity, and availability compromise. The EPSS score is less than 1 %, indicating a low probability of widespread exploitation at present, and the vulnerability is not in the CISA KEV catalog. Nevertheless, because the flaw requires no credentials and is reachable via a network request, it remains a straightforward remote exploitation vector for any host exposed to the public network.
OpenCVE Enrichment