Impact
Oracle Commerce Guided Search and Oracle Commerce Experience Manager version 11.4.0 contain a vulnerability in the Forge component that allows an unauthenticated attacker to gain control of the application through the HTTP interface. Successful exploitation can result in full takeover, compromising the confidentiality, integrity, and availability of all data processed by the Commerce Guided Search.
Affected Systems
The vulnerability affects Oracle Commerce Guided Search and Oracle Commerce Experience Manager, specifically the 11.4.0 release. This includes installations that expose the HTTP service of the Guided Search component.
Risk and Exploitability
The vulnerability has a CVSS 3.1 base score of 8.1, indicating high severity. The EPSS score is less than 1%, suggesting low to moderate likelihood of widespread exploitation, and it is not listed in CISA’s KEV catalog. Attackers can reach the vulnerable interface via network HTTP access without authentication, sending crafted requests to the Forge component to gain control of the system. No special privileges are required beyond open network connectivity.
OpenCVE Enrichment