Commerce Platform

Vendor:

First CVE: Apr 16, 2015 · Active for 11 years

33
Total CVEs
More Total CVEs than 96% of tracked products
4.1
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
6.1%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Commerce Platform over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 16, 2015
11 years ago
Most Recent CVE
Apr 15, 2025
465 days ago

CVE Severity & Scoring

Commerce Platform33 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local1 (3.0%)
Network29 (87.9%)
Unknown3 (9.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (45.5%)
High15 (45.5%)
Unknown3 (9.1%)
User Interaction
None22 (66.7%)
Unknown3 (9.1%)
Required8 (24.2%)
Privileges Required
Low2 (6.1%)
High1 (3.0%)
None27 (81.8%)
Unknown3 (9.1%)

Top CVEs

Signals from CVEs in this product scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run
Apr 1, 20229.898YESYES
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0,
Jan 15, 20209.898YESYES
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapte
Jan 7, 20218.136NONO
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The hi
Dec 3, 20207.533NONO
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDICo
Dec 27, 20208.131NONO
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDICo
Jan 6, 20218.130NONO
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolD
Jan 6, 20218.130NONO
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). Supported versions that are affected are 11.0.0, 11.1.0, 11.2.0
Jul 21, 20219.829NONO
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when crea
Sep 19, 20217.528NONO
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulne
Jul 21, 20218.328NONO

Exploit Exposure

Signals from CVEs in this product scope (33 CVEs).

CISA KEV
2 CVEs
6.1% of CVEs· 97th percentile
Metasploit
2 CVEs
6.1% of CVEs· 97th percentile
Nuclei
1 CVE
3.0% of CVEs· 96th percentile
ExploitDB
1 CVE
3.0% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (33 CVEs).

Media Mentions

Signals from CVEs in this product scope (33 CVEs).

Top CNAs Publishing CVEs For Commerce Platform

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.414.31.5%00
3.1.225.71.9%00
3.1.125.71.9%00
3.0.215.01.9%00
11.3.286.714.5%11
11.3.176.01.5%00
11.3.066.01.5%00
11.2.0.326.11.0%00
11.2.0.214.31.1%00
11.2.0158.314.1%11
11.1.029.849.4%11
11.125.71.9%00
11.0.029.849.4%11
11.025.71.9%00
10.2.0.514.31.1%00
10.214.31.5%00
10.0.3.514.31.1%00
10.014.31.5%00