---
id: CVE-2015-0495
title: >-
  Unspecified vulnerability in the Oracle Commerce Guided Search / Oracle
  Commerce Experience Manager component in Oracle Commerce Platform 3.x and 11.x
  allows remote attackers to affect confidentiality, integrity, and availability
  via unk…
summary: >-
  Unspecified vulnerability in the Oracle Commerce Guided Search / Oracle
  Commerce Experience Manager component in Oracle Commerce Platform 3.x and 11.x
  allows remote attackers to affect confidentiality, integrity, and availability
  via unk…
severity: high
cvss: 7.5
cvssVector: 'AV:N/AC:L/Au:N/C:P/I:P/A:P'
vendor: oracle
product: commerce_experience_manager
affected:
  - commerce_experience_manager
  - commerce_guided_search
published: '2015-04-16'
updated: '2026-07-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2015-0495'
references:
  - url: 'http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html'
    label: secalert_us@oracle.com
  - url: 'http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.02028
epssPercentile: 0.79905
ingestedAt: '2026-07-24T14:29:27.293Z'
---

## Overview

Unspecified vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component in Oracle Commerce Platform 3.x and 11.x allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Workbench.

## Affected

- `commerce_experience_manager`
- `commerce_guided_search`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
