CVE-2020-14536Corporation Commerce Guided Search Oracle Commerce Experience Manager vulnerability

4 documents4 sources
Severity
7.4HIGHNVD
EPSS
1.5%
top 19.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateMay 24

Description

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Workbench). Supported versions that are affected are 11.0, 11.1, 11.2 and prior to 11.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification a

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2

Affected Packages3 packages

🔴Vulnerability Details

2
GHSA
GHSA-wxvf-3cjv-fx8w: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Workbench)2022-05-24
CVEList
CVE-2020-14536: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Workbench)2020-07-15

📋Vendor Advisories

1
Oracle
Oracle Oracle Commerce Risk Matrix: Workbench — CVE-2020-145362020-07-15
CVE-2020-14536 — HIGH severity | cvebase