Oracle
Oracle Commerce Platform: vulnerabilidades y CVE
Oracle Commerce Platform tiene 44 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 8 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE44
Últimos 12 meses12
Críticas8
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-22965 | Crítica (9.8) | 100% | ⚠ Explotación activa | 1 abr 2022 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the… |
| CVE-2020-2555 | Crítica (9.8) | 97% | ⚠ Explotación activa | 15 ene 2020 | Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-70955 | Alta (7.5) | 0.33% | — | 18 ago 2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows… |
| CVE-2026-70954 | Crítica (9.8) | 0.51% | — | 18 ago 2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows… |
| CVE-2026-70953 | Crítica (9.8) | 0.51% | — | 18 ago 2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows… |
| CVE-2026-61137 | Alta (8.1) | 0.39% | — | 21 jul 2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows… |
| CVE-2026-61136 | Alta (7.3) | 0.31% | — | 21 jul 2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows… |
| CVE-2026-61135 | Alta (7.4) | 0.34% | — | 21 jul 2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows… |
| CVE-2026-61134 | Media (6.8) | 0.29% | — | 21 jul 2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low… |
| CVE-2026-61133 | Alta (7.5) | 0.44% | — | 21 jul 2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows… |
| CVE-2026-61132 | Alta (7.6) | 0.15% | — | 21 jul 2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low… |
| CVE-2026-61131 | Crítica (9.8) | 0.51% | — | 21 jul 2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows… |
| CVE-2026-61130 | Crítica (9.1) | 0.49% | — | 21 jul 2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows… |
| CVE-2026-61129 | Crítica (9.8) | 0.51% | — | 21 jul 2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: ATG Portals). The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with… |
| CVE-2025-21576 | Media (5.4) | 0.19% | — | 15 abr 2025 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Personalization Server). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Easily exploitable vulnerability… |
| CVE-2024-21100 | Media (4) | 0.35% | — | 16 abr 2024 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Platform). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Difficult to exploit vulnerability allows… |
| CVE-2022-21559 | Media (5.5) | 0.24% | — | 19 jul 2022 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Easily exploitable vulnerability… |
| CVE-2022-22965 | Crítica (9.8) | 100% | ⚠ Explotación activa | 1 abr 2022 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the… |
| CVE-2020-36518 | Alta (7.5) | 4.9% | — | 11 mar 2022 | jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. |
| CVE-2022-21387 | Media (5.3) | 1.1% | — | 19 ene 2022 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Easily exploitable vulnerability… |
| CVE-2021-40690 | Alta (7.5) | 7.4% | — | 19 sept 2021 | All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference… |
| CVE-2021-2351 | Alta (7.5) | 2.4% | — | 21 jul 2021 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated… |
| CVE-2021-2463 | Crítica (9.8) | 1.6% | — | 21 jul 2021 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported versions that are affected are 11.0.0, 11.1.0, 11.2.0 and 11.3.0-11.3.2. Easily exploitable… |
| CVE-2020-36183 | Alta (8.1) | 4.9% | — | 7 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool. |
| CVE-2020-36182 | Alta (8.1) | 4.0% | — | 7 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS. |
| CVE-2020-36180 | Alta (8.1) | 4.0% | — | 7 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS. |
| CVE-2020-36179 | Alta (8.1) | 17% | — | 7 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS. |
| CVE-2020-36189 | Alta (8.1) | 3.9% | — | 6 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource. |
| CVE-2020-36188 | Alta (8.1) | 8.8% | — | 6 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource. |
| CVE-2020-36187 | Alta (8.1) | 4.2% | — | 6 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource. |
| CVE-2020-36186 | Alta (8.1) | 4.2% | — | 6 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource. |
| CVE-2020-36185 | Alta (8.1) | 4.2% | — | 6 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.