Known Vulnerabilities for Commerce Platform by Oracle
Listed below are 10 of the newest known vulnerabilities associated with "Commerce Platform" by "Oracle".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-22965 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data bindin... | 9.8 - CRITICAL | 2022-04-01 | 2023-02-09 |
| CVE-2022-21559 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported... | 5.5 - MEDIUM | 2022-07-19 | 2022-07-26 |
| CVE-2022-21387 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported... | 5.3 - MEDIUM | 2022-01-19 | 2022-01-25 |
| CVE-2021-40690 | All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secur... | 7.5 - HIGH | 2021-09-19 | 2023-11-07 |
| CVE-2021-2463 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported... | 9.8 - CRITICAL | 2021-07-21 | 2021-07-21 |
| CVE-2021-2351 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are... | 8.3 - HIGH | 2021-07-21 | 2023-10-23 |
| CVE-2020-25649 | A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vul... | 7.5 - HIGH | 2020-12-03 | 2023-11-07 |
| CVE-2020-14533 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported... | 3.5 - LOW | 2020-07-15 | 2020-07-20 |
| CVE-2020-14532 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported... | 4.7 - MEDIUM | 2020-07-15 | 2020-07-20 |
| CVE-2020-2555 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Support... | 9.8 - CRITICAL | 2020-01-15 | 2022-10-25 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Commerce Platform | 9.4 | All | All | All |
| Application | Oracle | Commerce Platform | 3.1.2 | All | All | All |
| Application | Oracle | Commerce Platform | 3.1.1 | All | All | All |
| Application | Oracle | Commerce Platform | 3.0.2 | All | All | All |
| Application | Oracle | Commerce Platform | 11.3.1 | All | All | All |
| Application | Oracle | Commerce Platform | 11.2.0.3 | All | All | All |
| Application | Oracle | Commerce Platform | 11.2.0.2 | All | All | All |
| Application | Oracle | Commerce Platform | 11.1 | All | All | All |
| Application | Oracle | Commerce Platform | 11.0 | All | All | All |
| Application | Oracle | Commerce Platform | 10.2.0.5 | All | All | All |
| Application | Oracle | Commerce Platform | 10.2 | All | All | All |
| Application | Oracle | Commerce Platform | 10.0.3.5 | All | All | All |
| Application | Oracle | Commerce Platform | 10.0 | All | All | All |