Impact
The vulnerability resides in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0, allowing an attacker who can reach the application over HTTP to compromise the system without authentication. Successful exploitation can lead to reading critical data, unauthorized insert, update or delete operations on accessible data, and the ability to induce a partial denial of service affecting application availability. The CVSS 3.1 base score of 7.0 reflects significant impacts on confidentiality and potential disruptions in availability. This vulnerability is a collection of weaknesses including lack of authentication (CWE-306).
Affected Systems
Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0 is the sole affected version listed; no other product versions are indicated.
Risk and Exploitability
With a CVSS score of 7.0 the severity is medium‑high, while the EPSS score is less than 1 % indicating a low probability of exploitation in the wild. The vulnerability is not included in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request to the component, requiring no special privileges but still presenting a higher barrier for attackers who can reach the service on the network. Though exploitation is described as difficult, the potential for data exposure and service interruption warrants prompt remediation.
OpenCVE Enrichment