Impact
The Endeca Application Controller within Oracle Commerce Guided Search / Experience Manager contains an improper access control flaw that, when combined with weak local authentication controls (CWE‑269), enables an attacker with local access to the infrastructure to gain full control of the application. The vulnerability can lead to loss of confidentiality, integrity, and availability of the Commerce Guided Search component. However, successful exploitation requires an additional user interaction from someone other than the attacker, indicating that complete takeover cannot occur solely from remote access.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search / Oracle Commerce Experience Manager product, version 11.4.0, is affected. No other versions were identified in the advisory. The defect resides in the Endeca Application Controller module that is part of the Guided Search environment.
Risk and Exploitability
The CVSS 3.1 Base Score of 7.8 signals significant confidentiality, integrity, and availability impact. Its local attack vector reduces the likelihood compared to remote exploits, and an EPSS score of less than 1% combined with the absence from the CISA KEV catalog suggests that exploitation is currently unlikely. Nonetheless, once an attacker gains local infrastructure access and obtains a second user’s cooperation, the risk of full takeover is high, making timely patching the most effective mitigation.
OpenCVE Enrichment