cbcvebase.

Oracle Commerce Platform vulnerabilities

41 known vulnerabilities affecting oracle/commerce_platform.

Total CVEs
41
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL6HIGH21MEDIUM13LOW1

Vulnerabilities

Page 2 of 3
CVE-2020-36187P3HIGHCVSS 8.1≥ 11.3.0, ≤ 11.3.2v11.2.02021-01-06
CVE-2020-36187 [HIGH] CWE-502 CVE-2020-36187: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.
nvd
CVE-2020-36180P3HIGHCVSS 8.1≥ 11.3.0, ≤ 11.3.2v11.2.02021-01-07
CVE-2020-36180 [HIGH] CWE-502 CVE-2020-36180: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
nvd
CVE-2020-36182P3HIGHCVSS 8.1≥ 11.3.0, ≤ 11.3.2v11.2.02021-01-07
CVE-2020-36182 [HIGH] CWE-502 CVE-2020-36182: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
nvd
CVE-2020-36181P3HIGHCVSS 8.1≥ 11.3.0, ≤ 11.3.2v11.2.02021-01-06
CVE-2020-36181 [HIGH] CWE-502 CVE-2020-36181: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.
nvd
CVE-2020-36189P3HIGHCVSS 8.1≥ 11.3.0, ≤ 11.3.2v11.2.02021-01-06
CVE-2020-36189 [HIGH] CWE-502 CVE-2020-36189: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.
nvd
CVE-2026-61132P3HIGHCVSS 7.6v11.4.02026-07-21
CVE-2026-61132 [HIGH] CWE-352 CVE-2026-61132: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Applicat Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human interaction from a pe
nvd
CVE-2026-61134P3MEDIUMCVSS 6.8v11.4.02026-07-21
CVE-2026-61134 [MEDIUM] CWE-284 CVE-2026-61134: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Applicat Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can resul
nvd
CVE-2020-36518P3HIGHCVSS 7.5v11.3.0v11.3.1+1 more2022-03-11
CVE-2020-36518 [HIGH] CWE-787 CVE-2020-36518: jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a lar jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
nvd
CVE-2015-2653P4MEDIUMCVSS 6.4v3.1.1v3.1.2+2 more2015-07-16
CVE-2015-2653 [MEDIUM] CVE-2015-2653: Unspecified vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager Unspecified vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component in Oracle Commerce Platform 3.1.1, 3.1.2, 11.0, and 11.1 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Content Acquisition System.
nvd
CVE-2022-21387P4MEDIUMCVSS 5.3v11.3.0v11.3.1+1 more2022-01-19
CVE-2022-21387 [MEDIUM] CVE-2022-21387: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Applicat Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1≥ 11.3.0, ≤ 11.3.22019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2025-21576P4MEDIUMCVSS 5.4v11.3.0v11.3.1+1 more2025-04-15
CVE-2025-21576 [MEDIUM] CWE-352 CVE-2025-21576: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Personal Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Personalization Server). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human
nvd
CVE-2019-2712P4MEDIUMCVSS 6.1v11.2.0.3v11.3.12019-04-23
CVE-2019-2712 [MEDIUM] CVE-2019-2712: Vulnerability in the Oracle Commerce Platform component of Oracle Commerce (subcomponent: Dynamo App Vulnerability in the Oracle Commerce Platform component of Oracle Commerce (subcomponent: Dynamo Application Framework). Supported versions that are affected are 11.2.0.3 and 11.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human interaction
nvd
CVE-2019-2659P4MEDIUMCVSS 6.1v11.2.0.32019-04-23
CVE-2019-2659 [MEDIUM] CVE-2019-2659: Vulnerability in the Oracle Commerce Platform component of Oracle Commerce (subcomponent: Dynamo App Vulnerability in the Oracle Commerce Platform component of Oracle Commerce (subcomponent: Dynamo Application Framework). The supported version that is affected is 11.2.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human interaction from a pe
nvd
CVE-2015-2607P4MEDIUMCVSS 5.0v3.0.2v3.1.1+3 more2015-07-16
CVE-2015-2607 [MEDIUM] CVE-2015-2607: Unspecified vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager Unspecified vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component in Oracle Commerce Platform 3.0.2, 3.1.1, 3.1.2, 11.0, and 11.1 allows remote attackers to affect confidentiality via unknown vectors related to Content Acquisition System.
nvd
CVE-2022-21559P4MEDIUMCVSS 5.5v11.3.0v11.3.1+1 more2022-07-19
CVE-2022-21559 [MEDIUM] CVE-2022-21559: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Applicat Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Platform executes to compromise Oracle Commerce Platform
nvd
CVE-2020-14532P4MEDIUMCVSS 4.7≥ 11.1, < 11.3.12020-07-15
CVE-2020-14532 [MEDIUM] CVE-2020-14532: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Applicat Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported versions that are affected are 11.1, 11.2 and prior to 11.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human int
nvd
CVE-2015-0510P4MEDIUMCVSS 4.3v9.4v10.0+1 more2015-04-16
CVE-2015-0510 [MEDIUM] CVE-2015-0510: Unspecified vulnerability in the Oracle Commerce Platform component in Oracle Commerce Platform 9.4, Unspecified vulnerability in the Oracle Commerce Platform component in Oracle Commerce Platform 9.4, 10.0, and 10.2 allows remote attackers to affect integrity via vectors related to Dynamo Application Framework - HTML Admin User Interface.
nvd
CVE-2017-3296P4MEDIUMCVSS 4.3v10.0.3.5v10.2.0.5+1 more2017-01-27
CVE-2017-3296 [MEDIUM] CWE-200 CVE-2017-3296: Vulnerability in the Oracle Commerce Platform component of Oracle Commerce (subcomponent: Dynamo App Vulnerability in the Oracle Commerce Platform component of Oracle Commerce (subcomponent: Dynamo Application Framework). Supported versions that are affected are 10.0.3.5, 10.2.0.5 and 11.2.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks requi
nvd
CVE-2024-21100P4MEDIUMCVSS 4.0v11.3.0v11.3.1+1 more2024-04-16
CVE-2024-21100 [MEDIUM] CVE-2024-21100: Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Platform). Sup Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Platform). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. While the vulnerability is in Oracle Commerce Platform, atta
nvd
Oracle Commerce Platform vulnerabilities | cvebase