Impact
A difficult-to-exploit flaw in Oracle Commerce Guided Search / Oracle Commerce Experience Manager allows an unauthenticated attacker with network access to the HTTP interface to compromise the application. Successful exploitation can result in unauthorized access to all data exposed by the instance and can also trigger a partial denial of service. The weakness manifests as an improper access control violation, producing Confidentiality impact at a high level and Availability impact at a low level as reflected in the CVSS vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager, version 11.4.0, is the only product and version explicitly affected as documented by the CNA. No other variants or higher versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability, and the EPSS score of less than 1% indicates a very low but nonzero likelihood of exploitation. The vulnerability is not in the CISA KEV catalog. Because the attack vector is via HTTP, unauthenticated, and requires high attack complexity, the overall exploitability is low, but the confidentiality impact is high. Organizations with exposed Oracle Commerce instances should consider this a moderate risk and prioritize remediation accordingly.
OpenCVE Enrichment