Impact
The flaw resides in the Forge component of Oracle Commerce Guided Search/Experience Manager version 11.4.0. An unauthenticated attacker can send crafted HTTP requests that cause the application to hang or crash, resulting in a complete denial of service. At the same time the request pattern allows the attacker to read a subset of data that the component exposes, exposing sensitive information.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, specifically the 11.4.0 release. No other product versions are indicated in the advisory.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 denotes high availability impact and low confidentiality impact. The EPSS score of less than 1 % indicates a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires only network access over HTTP and no authentication, so the attack vector is straightforward and the condition for exploitation is minimal.
OpenCVE Enrichment