Oracle fixes 39 vulnerabilities in Commerce Platform and Guided Search (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- 39 vulnerabilities in Oracle Commerce Platform and Guided Search/Experience Manager version 11.4.0
- 11 critical vulnerabilities with CVSS score >= 9.0
- Attackers can gain unauthorized access, execute arbitrary code, or cause denial-of-service
"The Dutch NCSC reported that Oracle patched 39 vulnerabilities in Oracle Commerce Platform and Oracle Commerce Guided Search/Experience Manager, both version 11.4.0. 11 of these have CVSS scores of 9 or higher. Unauthenticated attackers can exploit some via network access over HTTP or LDAP to access sensitive data, modify data, or achieve full system compromise. Some require user interaction. Denial-of-service is also possible."
no comments yet.