We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2022-21466



Assigneroracle
Reserved2021-11-15
Published2022-04-19
Updated2024-09-24

Description

Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Tools and Frameworks). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).



HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Product status

11.3.2
affected

References

https://www.oracle.com/security-alerts/cpuapr2022.html

cve.org CVE-2022-21466

nvd.nist.gov CVE-2022-21466

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2022-21466
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.