Impact
This vulnerability resides in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. An unauthenticated attacker with network access over TCP can exploit a flaw that allows the attacker to compromise the service, leading to a takeover of the application and exposure of confidential, integral, and available data. The impact is broad: an attacker gains full control over the instance, potentially accessing customer data, modifying content, or disrupting service availability. The weakness is an improper access control issue where authentication and authorization checks are insufficient, allowing unrestricted exploitation.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager, version 11.4.0, are affected. No other version information is provided. The platform is indexed under the CPE for Oracle Commerce Guided Search/Oracle Commerce Experience Manager 11.4.0 and is a web‑based commerce platform typically deployed on an application server accessible over TCP.
Risk and Exploitability
The vulnerability is exploitable from any network position with TCP access to the application, and the attacker does not need valid credentials, making the attack vector 'Network' with no user interaction. The CVSS score of 8.1 indicates high severity, while the EPSS of less than 1% signifies a low current probability of exploitation, yet the potential damage remains substantial. It is not listed in CISA’s KEV catalog, so no known active exploits are reported at this time. Nonetheless, the full compromise path means organizations should prioritize patching or applying mitigations immediately to prevent potential takeover.
OpenCVE Enrichment