Impact
Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0 is impacted by a difficult-to-exploit vulnerability that permits an unauthenticated attacker with network access via TCP to take full control of the application. Successful exploitation results in a complete takeover, compromising confidentiality, integrity, and availability of the system. The weakness can be categorized as an improper authentication flaw, allowing attackers to bypass authentication controls and gain unrestricted access.
Affected Systems
The affected product is Oracle Commerce Guided Search / Oracle Commerce Experience Manager, specifically the 11.4.0 release. No other versions or components are currently listed as affected.
Risk and Exploitability
The CVSS 3.1 base score of 8.1 signals high severity, with full disclosure of confidentiality, integrity, and availability impacts. The EPSS score of less than 1% indicates a very low but non-zero probability of exploitation at the time of analysis. The vulnerability does not appear in the CISA Known Exploited Vulnerabilities catalog. Attackers can remotely exploit this weakness over the network without authentication, making it a high-risk scenario for exposed instances.
OpenCVE Enrichment