Impact
A flaw exists in the Forge component of Oracle Commerce Guided Search and Oracle Commerce Experience Manager (version 11.4.0). The vulnerability permits an attacker who can log onto the server hosting the application with low privileges to take advantage of improper privilege management. Exploiting the flaw results in loss of confidentiality, integrity, and availability, potentially allowing full takeover of the application.
Affected Systems
The affected products are Oracle Commerce Guided Search and Oracle Commerce Experience Manager from Oracle Corporation, specifically version 11.4.0.
Risk and Exploitability
The CVSS v3.1 base score of 7.8 reflects a high impact to confidentiality, integrity, and availability, with a local access requirement, high attack complexity, low privileges, no user interaction, and a scope change that could affect other Oracle products. The EPSS score is less than 1%, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is a local environment compromise with low privileges, from which the attacker can manipulate the vulnerable component to subvert application access controls.
OpenCVE Enrichment