Oracle

Commerce Guided Search

135 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.17%
  • Veröffentlicht 08.11.2019 15:15:11
  • Zuletzt bearbeitet 07.07.2025 14:15:21

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

  • EPSS 6.26%
  • Veröffentlicht 06.11.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 04:22:46

Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large nu...

  • EPSS 13.84%
  • Veröffentlicht 06.11.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 04:22:48

Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is...

  • EPSS 1.43%
  • Veröffentlicht 25.10.2016 14:29:19
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Unspecified vulnerability in the Oracle Commerce Guided Search component in Oracle Commerce 6.2.2, 6.3.0, 6.4.1.2, and 6.5.0 through 6.5.2 allows remote attackers to affect confidentiality and integrity via unknown vectors.

  • EPSS 2.01%
  • Veröffentlicht 16.04.2015 16:59:45
  • Zuletzt bearbeitet 24.07.2026 14:18:58

Unspecified vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component in Oracle Commerce Platform 3.x and 11.x allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors ...