Commerce Platform
Vendor:
First CVE: Apr 16, 2015 · Active for 11 years
33
Total CVEs
More Total CVEs than 96% of tracked products
4.1
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
6.1%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Commerce Platform over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 16, 2015
11 years ago
Most Recent CVE
Apr 15, 2025
465 days ago
CVE Severity & Scoring
Commerce Platform33 CVEs
36%
52%
9%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (3.0%)
Network29 (87.9%)
Unknown3 (9.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (45.5%)
High15 (45.5%)
Unknown3 (9.1%)
User Interaction
None22 (66.7%)
Unknown3 (9.1%)
Required8 (24.2%)
Privileges Required
Low2 (6.1%)
High1 (3.0%)
None27 (81.8%)
Unknown3 (9.1%)
Top CVEs
Signals from CVEs in this product scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22965CRITICAL A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run | Apr 1, 2022 | 9.8 | 98 | YES | YES |
CVE-2020-2555CRITICAL Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, | Jan 15, 2020 | 9.8 | 98 | YES | YES |
CVE-2020-36179HIGH FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapte | Jan 7, 2021 | 8.1 | 36 | NO | NO |
CVE-2020-25649HIGH A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The hi | Dec 3, 2020 | 7.5 | 33 | NO | NO |
CVE-2020-35728HIGH FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDICo | Dec 27, 2020 | 8.1 | 31 | NO | NO |
CVE-2020-36188HIGH FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDICo | Jan 6, 2021 | 8.1 | 30 | NO | NO |
CVE-2020-36184HIGH FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolD | Jan 6, 2021 | 8.1 | 30 | NO | NO |
CVE-2021-2463CRITICAL Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported versions that are affected are 11.0.0, 11.1.0, 11.2.0 | Jul 21, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-40690HIGH All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when crea | Sep 19, 2021 | 7.5 | 28 | NO | NO |
CVE-2021-2351HIGH Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulne | Jul 21, 2021 | 8.3 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (33 CVEs).
CISA KEV
2 CVEs
6.1% of CVEs· 97th percentile
Metasploit
2 CVEs
6.1% of CVEs· 97th percentile
Nuclei
1 CVE
3.0% of CVEs· 96th percentile
ExploitDB
1 CVE
3.0% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (33 CVEs).
Media Mentions
Signals from CVEs in this product scope (33 CVEs).
Top CNAs Publishing CVEs For Commerce Platform
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.4 | 1 | 4.3 | 1.5% | 0 | 0 |
| 3.1.2 | 2 | 5.7 | 1.9% | 0 | 0 |
| 3.1.1 | 2 | 5.7 | 1.9% | 0 | 0 |
| 3.0.2 | 1 | 5.0 | 1.9% | 0 | 0 |
| 11.3.2 | 8 | 6.7 | 14.5% | 1 | 1 |
| 11.3.1 | 7 | 6.0 | 1.5% | 0 | 0 |
| 11.3.0 | 6 | 6.0 | 1.5% | 0 | 0 |
| 11.2.0.3 | 2 | 6.1 | 1.0% | 0 | 0 |
| 11.2.0.2 | 1 | 4.3 | 1.1% | 0 | 0 |
| 11.2.0 | 15 | 8.3 | 14.1% | 1 | 1 |
| 11.1.0 | 2 | 9.8 | 49.4% | 1 | 1 |
| 11.1 | 2 | 5.7 | 1.9% | 0 | 0 |
| 11.0.0 | 2 | 9.8 | 49.4% | 1 | 1 |
| 11.0 | 2 | 5.7 | 1.9% | 0 | 0 |
| 10.2.0.5 | 1 | 4.3 | 1.1% | 0 | 0 |
| 10.2 | 1 | 4.3 | 1.5% | 0 | 0 |
| 10.0.3.5 | 1 | 4.3 | 1.1% | 0 | 0 |
| 10.0 | 1 | 4.3 | 1.5% | 0 | 0 |