cbcvebase.

Oracle Commerce Guided Search vulnerabilities

70 known vulnerabilities affecting oracle/commerce_guided_search.

Total CVEs
70
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
3
Severity breakdown
CRITICAL6HIGH43MEDIUM20LOW1

Vulnerabilities

Page 1 of 4
CVE-2022-22947P1CRITICALCVSS 10.0KEVPoCv11.3.22022-03-03
CVE-2022-22947 [CRITICAL] CWE-94 CVE-2022-22947: In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
nvd
CVE-2021-39144P1HIGHCVSS 8.5KEVPoCv11.3.22021-08-23
CVE-2021-39144 [HIGH] CWE-94 CVE-2021-39144: XStream is a simple library to serialize objects to XML and back again. In affected versions this vu XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist lim
nvd
CVE-2021-39152P1HIGHCVSS 8.5ExploitedPoCv11.3.22021-08-23
CVE-2021-39152 [HIGH] CWE-502 CVE-2021-39152: XStream is a simple library to serialize objects to XML and back again. In affected versions this vu XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected, who followed the recommendation to
nvd
CVE-2020-13935P2HIGHCVSS 7.5PoCv11.3.22020-07-14
CVE-2020-13935 [HIGH] CWE-835 CVE-2020-13935: The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10 The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
nvd
CVE-2021-39141P2HIGHCVSS 8.5PoCv11.3.22021-08-23
CVE-2021-39141 [HIGH] CWE-434 CVE-2021-39141: XStream is a simple library to serialize objects to XML and back again. In affected versions this vu XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist li
nvd
CVE-2021-39146P2HIGHCVSS 8.5PoCv11.3.22021-08-23
CVE-2021-39146 [HIGH] CWE-434 CVE-2021-39146: XStream is a simple library to serialize objects to XML and back again. In affected versions this vu XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist li
nvd
CVE-2019-12419P2CRITICALCVSS 9.8v11.3.22019-11-06
CVE-2019-12419 [CRITICAL] CWE-863 CVE-2019-12419: Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equal to that of the supplied clientId parameter in the request. If a malicious client was able to
nvd
CVE-2026-61146P2CRITICALCVSS 9.9v11.4.02026-07-21
CVE-2026-61146 [CRITICAL] CWE-269 CVE-2026-61146: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Orac
nvd
CVE-2026-61145P2CRITICALCVSS 9.8v11.4.02026-07-21
CVE-2026-61145 [CRITICAL] CWE-284 CVE-2026-61145: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Ora
nvd
CVE-2026-61161P2CRITICALCVSS 9.8v11.4.02026-07-21
CVE-2026-61161 [CRITICAL] CWE-284 CVE-2026-61161: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search /
nvd
CVE-2026-61153P2CRITICALCVSS 9.1v11.4.02026-07-21
CVE-2026-61153 [CRITICAL] CWE-284 CVE-2026-61153: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Comm
nvd
CVE-2021-39139P2HIGHCVSS 8.8v11.3.22021-08-23
CVE-2021-39139 [HIGH] CWE-434 CVE-2021-39139: XStream is a simple library to serialize objects to XML and back again. In affected versions this vu XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. A user is only affected if using the version out of the box with JDK 1.7u21 or below. However, this scenario c
nvd
CVE-2021-39154P2HIGHCVSS 8.5v11.3.22021-08-23
CVE-2021-39154 [HIGH] CWE-434 CVE-2021-39154: XStream is a simple library to serialize objects to XML and back again. In affected versions this vu XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist li
nvd
CVE-2021-39149P2HIGHCVSS 8.5v11.3.22021-08-23
CVE-2021-39149 [HIGH] CWE-434 CVE-2021-39149: XStream is a simple library to serialize objects to XML and back again. In affected versions this vu XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist li
nvd
CVE-2021-39147P2HIGHCVSS 8.5v11.3.22021-08-23
CVE-2021-39147 [HIGH] CWE-434 CVE-2021-39147: XStream is a simple library to serialize objects to XML and back again. In affected versions this vu XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist li
nvd
CVE-2021-39151P2HIGHCVSS 8.5v11.3.22021-08-23
CVE-2021-39151 [HIGH] CWE-434 CVE-2021-39151: XStream is a simple library to serialize objects to XML and back again. In affected versions this vu XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist li
nvd
CVE-2021-39148P2HIGHCVSS 8.5v11.3.22021-08-23
CVE-2021-39148 [HIGH] CWE-434 CVE-2021-39148: XStream is a simple library to serialize objects to XML and back again. In affected versions this vu XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist li
nvd
CVE-2021-39145P3HIGHCVSS 8.5v11.3.22021-08-23
CVE-2021-39145 [HIGH] CWE-434 CVE-2021-39145: XStream is a simple library to serialize objects to XML and back again. In affected versions this vu XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist li
nvd
CVE-2021-3450P3HIGHCVSS 7.4v11.3.22021-03-25
CVE-2021-3450 [HIGH] CWE-295 CVE-2021-3450: The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check. An error in the implementation
nvd
CVE-2026-61149P3HIGHCVSS 8.8v11.4.02026-07-21
CVE-2026-61149 [HIGH] CWE-269 CVE-2026-61149: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce
nvd
Oracle Commerce Guided Search vulnerabilities | cvebase