Oracle Commerce Merchandising 11.2.0

CPE Details

Oracle Commerce Merchandising 11.2.0
11.2.0
2021-09-29
13h49 +00:00
2021-09-29
14h14 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:oracle:commerce_merchandising:11.2.0:*:*:*:*:*:*:*

Informations

Vendor

oracle

Product

commerce_merchandising

Version

11.2.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-26272 2021-01-26 19h39 +00:00 It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
6.5
Medium
CVE-2020-27193 2020-11-12 19h31 +00:00 A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
6.1
Medium