Executive brief
Oracle Commerce Guided Search and Experience Manager are tools used to manage product search and shopping experiences in e-commerce platforms. An unauthenticated attacker can exploit a cross-site request forgery vulnerability via a malicious web link to modify or delete product data and read sensitive information, but only if a logged-in administrator clicks the link. Successful exploitation could compromise product catalogs, customer data visibility, and platform integrity.
Technical details
The vulnerability is a cross-site request forgery (CSRF) flaw in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It is easily exploitable over the network via HTTP without authentication, but requires user interaction (UI:R) from an administrator or authorized user. The scope is changed, indicating the vulnerability can impact additional products beyond the directly affected component. A successful attack grants an unauthenticated attacker unauthorized read access to subset of accessible data and update/insert/delete access to some accessible data. Patches or workarounds have not been publicly confirmed at this time.
Affected products
- Oracle Commerce Guided Search 11.4.0
- Oracle Commerce Experience Manager 11.4.0
Timeline
- 2026-08-18: disclosed