Impact
The vulnerability resides in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. An unauthenticated attacker with network connectivity over HTTP can exploit the flaw to compromise the application and ultimately take over the system. The flaw carries a CVSS v3.1 base score of 8.1, indicating significant impacts to confidentiality, integrity and availability.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0, is affected. No other product versions are mentioned as impacted.
Risk and Exploitability
The EPSS score of less than 1% suggests a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the high CVSS score and the ability to gain full control make it a high‑severity risk. The attack vector requires network access via HTTP and is inferred from the description; an attacker would need to send crafted requests to the impacted component to trigger the exploitation.
OpenCVE Enrichment