Known Vulnerabilities for Commerce Guided Search by Oracle
Listed below are 10 of the newest known vulnerabilities associated with "Commerce Guided Search" by "Oracle".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-22029 json | Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Workbench). The supported version... | 6.1 - MEDIUM | 2023-10-17 | 2023-10-23 |
| CVE-2022-22947 json | In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the... | 10 - CRITICAL | 2022-03-03 | 2023-07-24 |
| CVE-2022-22946 json | In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trust... | 5.5 - MEDIUM | 2022-03-04 | 2023-02-22 |
| CVE-2022-21466 json | Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Tools and Frameworks). The supporte... | 7.5 - HIGH | 2022-04-19 | 2022-04-28 |
| CVE-2021-43859 json | XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remot... | 7.5 - HIGH | 2022-02-01 | 2023-11-07 |
| CVE-2021-41165 json | CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML pro... | 5.4 - MEDIUM | 2021-11-17 | 2022-10-05 |
| CVE-2021-41164 json | CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Con... | 5.4 - MEDIUM | 2021-11-17 | 2023-11-07 |
| CVE-2021-40690 json | All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secur... | 7.5 - HIGH | 2021-09-19 | 2023-11-07 |
| CVE-2021-39154 json | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a r... | 8.5 - HIGH | 2021-08-23 | 2023-11-07 |
| CVE-2021-39152 json | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a r... | 8.5 - HIGH | 2021-08-23 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Commerce Guided Search | 6.5.2 | |||
| Application | Oracle | Commerce Guided Search | 6.5.1 | |||
| Application | Oracle | Commerce Guided Search | 6.5.0 | |||
| Application | Oracle | Commerce Guided Search | 6.4.1.2 | |||
| Application | Oracle | Commerce Guided Search | 6.3.0 | |||
| Application | Oracle | Commerce Guided Search | 6.2.2 | |||
| Application | Oracle | Commerce Guided Search | 11.3.1 | |||
| Application | Oracle | Commerce Guided Search | 11.2 | |||
| Application | Oracle | Commerce Guided Search | 11.1 | |||
| Application | Oracle | Commerce Guided Search | 11.0 |