Impact
The vulnerability is in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component Forge and allows an unauthenticated attacker with network access over TLS to compromise the system. A successful attack can cause a hang or repeated crash, resulting in a complete denial of service, and also grants unauthorized read access to a subset of the application data. The weakness is an unauthorized disclosure of information and a lack of protection against denial‑of‑service attacks.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, version 11.4.0, are the affected products. No other versions are listed as impacted, but upgrades beyond 11.4.0 should be verified to ensure no residual vulnerability exists.
Risk and Exploitability
The CVSS v3.1 baseline score of 6.5 places this vulnerability in the medium range, reflecting moderate confidentiality impact and high availability impact. The EPSS score is below 1 %, indicating that real‑world exploitation is considered unlikely. The vulnerability is not listed in the CISA KEV catalog. The attack vector is network access over TLS and the description notes the exploitation as difficult, suggesting that while the potential damage is significant, the likelihood of successful attack remains modest.
OpenCVE Enrichment