Impact
A flaw in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows an attacker who can log on to the underlying infrastructure – but is otherwise unauthenticated against the application – to compromise the application. The vulnerability requires a human user other than the attacker to interact with the compromised component, after which attacker-controlled code can be executed, leading to a complete takeover. The flaw exposes the application to simultaneous confidentiality, integrity, and availability disruptions, with the stated CVSS vector indicating high impact on all three submetrics.
Affected Systems
Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0, is the only identified affected build. No other Oracle Commerce versions are listed as impacted.
Risk and Exploitability
The CVSS base score of 7.8 classifies this issue as high risk. The EPSS score of less than 1% implies a low likelihood of industrial exploitation at present, and it is not featured in the CISA KEV catalog. However, because successful exploitation still requires a person outside the attacker to interact with the system, an attacker who can compromise the underlying infrastructure—e.g., via a compromised administrator account—could leverage this weakness. Organizations operating at least version 11.4.0 should treat this as a high-priority vulnerability and consider it in their overall risk posture.
OpenCVE Enrichment