cbcvebase.

Oracle Commerce Experience Manager vulnerabilities

23 known vulnerabilities affecting oracle/commerce_experience_manager.

Total CVEs
23
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH14MEDIUM5

Vulnerabilities

Page 1 of 2
CVE-2026-61146P2CRITICALCVSS 9.9v11.4.02026-07-21
CVE-2026-61146 [CRITICAL] CWE-269 CVE-2026-61146: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Orac
nvd
CVE-2026-61145P2CRITICALCVSS 9.8v11.4.02026-07-21
CVE-2026-61145 [CRITICAL] CWE-284 CVE-2026-61145: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Ora
nvd
CVE-2026-61161P2CRITICALCVSS 9.8v11.4.02026-07-21
CVE-2026-61161 [CRITICAL] CWE-284 CVE-2026-61161: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search /
nvd
CVE-2026-61153P2CRITICALCVSS 9.1v11.4.02026-07-21
CVE-2026-61153 [CRITICAL] CWE-284 CVE-2026-61153: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Comm
nvd
CVE-2026-61149P3HIGHCVSS 8.8v11.4.02026-07-21
CVE-2026-61149 [HIGH] CWE-269 CVE-2026-61149: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce
nvd
CVE-2026-61148P3HIGHCVSS 8.8v11.4.02026-07-21
CVE-2026-61148 [HIGH] CWE-284 CVE-2026-61148: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce
nvd
CVE-2026-61163P3HIGHCVSS 8.1v11.4.02026-07-21
CVE-2026-61163 [HIGH] CWE-287 CVE-2026-61163: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience
nvd
CVE-2026-61150P3HIGHCVSS 8.1v11.4.02026-07-21
CVE-2026-61150 [HIGH] CWE-284 CVE-2026-61150: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce
nvd
CVE-2020-2604P3HIGHCVSS 8.1v11.3.22020-01-15
CVE-2020-2604 [HIGH] CWE-502 CVE-2020-2604: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embed
nvd
CVE-2021-20190P3HIGHCVSS 8.1v11.3.22021-01-19
CVE-2021-20190 [HIGH] CWE-502 CVE-2021-20190: A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between s A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2026-61160P3HIGHCVSS 8.1v11.4.02026-07-21
CVE-2026-61160 [HIGH] CWE-20 CVE-2026-61160: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce E
nvd
CVE-2026-61159P3HIGHCVSS 7.5v11.4.02026-07-21
CVE-2026-61159 [HIGH] CWE-200 CVE-2026-61159: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce
nvd
CVE-2026-61158P3HIGHCVSS 7.5v11.4.02026-07-21
CVE-2026-61158 [HIGH] CWE-284 CVE-2026-61158: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle Commerce Guided Search / Oracle Commerce
nvd
CVE-2026-61157P3HIGHCVSS 7.5v11.4.02026-07-21
CVE-2026-61157 [HIGH] CWE-284 CVE-2026-61157: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce
nvd
CVE-2026-61164P3HIGHCVSS 7.4v11.4.02026-07-21
CVE-2026-61164 [HIGH] CWE-284 CVE-2026-61164: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Commerce Guided Search / Orac
nvd
CVE-2020-14536P3HIGHCVSS 7.4≥ 11.0, < 11.3.12020-07-15
CVE-2020-14536 [HIGH] CVE-2020-14536: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Workbench). Supported versions that are affected are 11.0, 11.1, 11.2 and prior to 11.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / O
nvd
CVE-2026-61151P3HIGHCVSS 7.1v11.4.02026-07-21
CVE-2026-61151 [HIGH] CWE-284 CVE-2026-61151: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce
nvd
CVE-2026-61162P3HIGHCVSS 7.1v11.4.02026-07-21
CVE-2026-61162 [HIGH] CWE-284 CVE-2026-61162: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Co
nvd
CVE-2026-61152P4MEDIUMCVSS 5.4v11.4.02026-07-21
CVE-2026-61152 [MEDIUM] CWE-284 CVE-2026-61152: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerc
nvd
CVE-2026-61147P4MEDIUMCVSS 6.2v11.4.02026-07-21
CVE-2026-61147 [MEDIUM] CWE-400 CVE-2026-61147: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Co
nvd
Oracle Commerce Experience Manager vulnerabilities | cvebase