cbcvebase.

Oracle Commerce Platform vulnerabilities

41 known vulnerabilities affecting oracle/commerce_platform.

Total CVEs
41
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL6HIGH21MEDIUM13LOW1

Vulnerabilities

Page 1 of 3
CVE-2020-2555P1CRITICALCVSS 9.8KEVPoC≥ 11.3.0, ≤ 11.3.2v11.0.0+2 more2020-01-15
CVE-2020-2555 [CRITICAL] CWE-502 CVE-2020-2555: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheS Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks o
nvd
CVE-2022-22965P1CRITICALCVSS 9.8KEVPoCRansomwarev11.3.22022-04-01
CVE-2022-22965 [CRITICAL] CWE-94 CVE-2022-22965: A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execut A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature
nvd
CVE-2026-61129P2CRITICALCVSS 9.8v11.4.02026-07-21
CVE-2026-61129 [CRITICAL] CWE-287 CVE-2026-61129: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: ATG Portals). Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: ATG Portals). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in takeover of O
nvd
CVE-2026-61131P2CRITICALCVSS 9.8v11.4.02026-07-21
CVE-2026-61131 [CRITICAL] CWE-284 CVE-2026-61131: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Applicat Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can resu
nvd
CVE-2021-2463P2CRITICALCVSS 9.8≥ 11.3.0, ≤ 11.3.2v11.0.0+2 more2021-07-21
CVE-2021-2463 [CRITICAL] CVE-2021-2463: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Applicat Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported versions that are affected are 11.0.0, 11.1.0, 11.2.0 and 11.3.0-11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this
nvd
CVE-2026-61130P2CRITICALCVSS 9.1v11.4.02026-07-21
CVE-2026-61130 [CRITICAL] CWE-284 CVE-2026-61130: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Applicat Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can resu
nvd
CVE-2020-36179P3HIGHCVSS 8.1≥ 11.3.0, ≤ 11.3.2v11.2.02021-01-07
CVE-2020-36179 [HIGH] CWE-502 CVE-2020-36179: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
nvd
CVE-2020-25649P3HIGHCVSS 7.5≥ 11.3.0, ≤ 11.3.2v11.2.02020-12-03
CVE-2020-25649 [HIGH] CWE-611 CVE-2020-25649: A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured prope A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
nvd
CVE-2020-35728P3HIGHCVSS 8.1≥ 11.3.0, ≤ 11.3.2v11.2.02020-12-27
CVE-2020-35728 [HIGH] CWE-502 CVE-2020-35728: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).
nvd
CVE-2026-61137P3HIGHCVSS 8.1v11.4.02026-07-21
CVE-2026-61137 [HIGH] CWE-287 CVE-2026-61137: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Applicat Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result
nvd
CVE-2026-61133P3HIGHCVSS 7.5v11.4.02026-07-21
CVE-2026-61133 [HIGH] CWE-200 CVE-2026-61133: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Applicat Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result i
nvd
CVE-2021-40690P3HIGHCVSS 7.5v11.3.22021-09-19
CVE-2021-40690 [HIGH] CWE-200 CVE-2021-40690: All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract any local .xml files in a RetrievalMethod element.
nvd
CVE-2020-36188P3HIGHCVSS 8.1≥ 11.3.0, ≤ 11.3.2v11.2.02021-01-06
CVE-2020-36188 [HIGH] CWE-502 CVE-2020-36188: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.
nvd
CVE-2026-61135P3HIGHCVSS 7.4v11.4.02026-07-21
CVE-2026-61135 [HIGH] CWE-284 CVE-2026-61135: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Applicat Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result
nvd
CVE-2020-36184P3HIGHCVSS 8.1≥ 11.3.0, ≤ 11.3.2v11.2.02021-01-06
CVE-2020-36184 [HIGH] CWE-502 CVE-2020-36184: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.
nvd
CVE-2020-36183P3HIGHCVSS 8.1≥ 11.3.0, ≤ 11.3.2v11.2.02021-01-07
CVE-2020-36183 [HIGH] CWE-502 CVE-2020-36183: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.
nvd
CVE-2026-61136P3HIGHCVSS 7.3v11.4.02026-07-21
CVE-2026-61136 [HIGH] CWE-284 CVE-2026-61136: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Applicat Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result i
nvd
CVE-2021-2351P3HIGHCVSS 7.5v11.3.0v11.3.1+1 more2021-07-21
CVE-2021-2351 [HIGH] CWE-327 CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a perso
nvd
CVE-2020-36186P3HIGHCVSS 8.1≥ 11.3.0, ≤ 11.3.2v11.2.02021-01-06
CVE-2020-36186 [HIGH] CWE-502 CVE-2020-36186: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.
nvd
CVE-2020-36185P3HIGHCVSS 8.1≥ 11.3.0, ≤ 11.3.2v11.2.02021-01-06
CVE-2020-36185 [HIGH] CWE-502 CVE-2020-36185: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource.
nvd
Oracle Commerce Platform vulnerabilities | cvebase