Impact
The vulnerability resides in the Forge component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It allows a low‑privileged attacker who can reach the application over HTTP to obtain unauthorized access to critical or all accessible data and to cause a partial denial of service. The flaw is an access control weakness that impacts confidentiality and availability, as reflected by a CVSS 3.1 base score of 7.1 with high confidentiality impact and low availability impact.
Affected Systems
Oracle Corporation’s Oracle Commerce Guided Search and Oracle Commerce Experience Manager running version 11.4.0 are the impacted delivery mechanisms. The flaw affects installations that expose the Forge component to the network.
Risk and Exploitability
The EPSS score of less than 1% suggests a low probability of exploitation, yet the CVSS base score of 7.1 indicates a high severity posture. The vulnerability can be exploited remotely via HTTP by an attacker with low privileges to read or modify data and to reduce service availability. The flaw is not listed in the CISA KEV catalog, but its potential impact warrants attention. Based on the description, it is inferred that the attack does not require user interaction.
OpenCVE Enrichment