cbcvebase.

Oracle Commerce Guided Search vulnerabilities

70 known vulnerabilities affecting oracle/commerce_guided_search.

Total CVEs
70
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
3
Severity breakdown
CRITICAL6HIGH43MEDIUM20LOW1

Vulnerabilities

Page 2 of 4
CVE-2026-61148P3HIGHCVSS 8.8v11.4.02026-07-21
CVE-2026-61148 [HIGH] CWE-284 CVE-2026-61148: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce
nvd
CVE-2020-28052P3HIGHCVSS 8.1v11.3.22020-12-18
CVE-2020-28052 [HIGH] CVE-2020-28052: An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.chec An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
nvd
CVE-2021-39150P3HIGHCVSS 8.5v11.3.22021-08-23
CVE-2021-39150 [HIGH] CWE-502 CVE-2021-39150: XStream is a simple library to serialize objects to XML and back again. In affected versions this vu XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected, who followed the recommendation to
nvd
CVE-2026-61163P3HIGHCVSS 8.1v11.4.02026-07-21
CVE-2026-61163 [HIGH] CWE-287 CVE-2026-61163: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience
nvd
CVE-2026-61150P3HIGHCVSS 8.1v11.4.02026-07-21
CVE-2026-61150 [HIGH] CWE-284 CVE-2026-61150: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce
nvd
CVE-2020-2604P3HIGHCVSS 8.1v11.3.22020-01-15
CVE-2020-2604 [HIGH] CWE-502 CVE-2020-2604: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embed
nvd
CVE-2021-20190P3HIGHCVSS 8.1v11.3.22021-01-19
CVE-2021-20190 [HIGH] CWE-502 CVE-2021-20190: A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between s A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2026-61160P3HIGHCVSS 8.1v11.4.02026-07-21
CVE-2026-61160 [HIGH] CWE-20 CVE-2026-61160: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce E
nvd
CVE-2021-40690P3HIGHCVSS 7.5v11.3.22021-09-19
CVE-2021-40690 [HIGH] CWE-200 CVE-2021-40690: All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
nvd
CVE-2026-61159P3HIGHCVSS 7.5v11.4.02026-07-21
CVE-2026-61159 [HIGH] CWE-200 CVE-2026-61159: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce
nvd
CVE-2026-61158P3HIGHCVSS 7.5v11.4.02026-07-21
CVE-2026-61158 [HIGH] CWE-284 CVE-2026-61158: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle Commerce Guided Search / Oracle Commerce
nvd
CVE-2026-61157P3HIGHCVSS 7.5v11.4.02026-07-21
CVE-2026-61157 [HIGH] CWE-284 CVE-2026-61157: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce
nvd
CVE-2026-61164P3HIGHCVSS 7.4v11.4.02026-07-21
CVE-2026-61164 [HIGH] CWE-284 CVE-2026-61164: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Content Acquisition System). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Commerce Guided Search / Orac
nvd
CVE-2021-35515P3HIGHCVSS 7.5v11.3.22021-07-13
CVE-2021-35515 [HIGH] CWE-834 CVE-2021-35515: When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
nvd
CVE-2021-22946P3HIGHCVSS 7.5v11.3.22021-09-29
CVE-2021-22946 [HIGH] CWE-325 CVE-2021-22946: A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLUSESSL_ALL` withlibcurl). This requirement could be bypassed if the server would return a properly crafted but perfectly legitimate re
nvd
CVE-2022-21466P3HIGHCVSS 7.5v11.3.22022-04-19
CVE-2022-21466 [HIGH] CVE-2022-21466: Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Tools and Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Tools and Frameworks). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2021-43859P3HIGHCVSS 7.5v11.3.22022-02-01
CVE-2021-43859 [HIGH] CWE-400 CVE-2021-43859: XStream is an open source java library to serialize objects to XML and back again. Versions prior to XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors an
nvd
CVE-2020-14536P3HIGHCVSS 7.4≥ 11.0, < 11.3.12020-07-15
CVE-2020-14536 [HIGH] CVE-2020-14536: Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of O Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Workbench). Supported versions that are affected are 11.0, 11.1, 11.2 and prior to 11.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / O
nvd
CVE-2021-36090P3HIGHCVSS 7.5v11.3.22021-07-13
CVE-2021-36090 [HIGH] CWE-130 CVE-2021-36090: When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memo When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.
nvd
CVE-2021-35516P3HIGHCVSS 7.5v11.3.22021-07-13
CVE-2021-35516 [HIGH] CWE-130 CVE-2021-35516: When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memor When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
nvd