Impact
An unauthenticated attacker with network access over TCP can take control of Oracle Commerce Guided Search / Oracle Commerce Experience Manager by exploiting a vulnerability in the Forge component. The flaw, classified as a difficult-to-exploit weakness, grants full confidentiality, integrity, and availability compromise, allowing the attacker to take over the application entirely.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, specifically the component named Forge, are affected. The only documented impacted release is version 11.4.0.
Risk and Exploitability
The vulnerability scores 8.1 on the CVSS 3.1 scale, indicating high severity. The EPSS score is below 1 %, indicating that exploitation is unlikely but still possible at present. It is not yet listed in the CISA KEV catalog. The likely attack vector is unauthenticated network access over TCP to the Forge service, which could allow compromise if the service is exposed.
OpenCVE Enrichment