Impact
A difficult-to-exploit vulnerability exists in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component named Forge. Based on the description, it is inferred that this weakness is an improper privilege management flaw (CWE-269). An attacker who is low privileged and can reach the application over HTTP may successfully compromise the entire Guided Search / Experience Manager instance, leading to full compromise of confidentiality, integrity, and availability of the application.
Affected Systems
The vulnerability affects Oracle Commerce Guided Search and Oracle Commerce Experience Manager versions 11.4.0. Only this version is listed as supported and affected.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 indicates high severity, but the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires network access via HTTP and low privileges, meaning a remote attacker with unauthenticated or minimal authenticated access may gain full control over the application.
OpenCVE Enrichment