Executive brief
Oracle Commerce Guided Search and Experience Manager are components used by e-commerce businesses to power product search and customer experience features. This vulnerability allows a low-privileged attacker with network access to steal customer data and product information, as well as temporarily disrupt the search and experience functionality for end users.
Technical details
This is an information disclosure and partial denial-of-service vulnerability in Oracle Commerce Guided Search / Experience Manager that can be exploited over HTTP by an attacker with low privileges. The vulnerability requires network access but no user interaction. A successful exploit allows unauthorized access to critical data stored in the application and the ability to cause partial unavailability of the service. The vulnerability affects Oracle Commerce version 11.4.0. Patch availability and specific technical root cause details are not currently available from the provided advisory.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed