Skip to main content

Vendor/product archive

oracle / retail_merchandising_system CVEs

Beta · best-effort

25 CVEs tagged to oracle / retail_merchandising_system10 Critical, 9 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2020-6950

Published Jun 2, 2021

Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.

CVSS 6.5 · Medium

CVE-2020-5413

Published Jul 31, 2020

Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered class…

CVSS 9.8 · Critical

CVE-2018-12023

Published Mar 21, 2019

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the servi…

CVSS 7.5 · High

CVE-2018-12022

Published Mar 21, 2019

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the servi…

CVSS 7.5 · High

CVE-2018-3125

Published Jan 16, 2019

Vulnerability in the Oracle Retail Merchandising System component of Oracle Retail Applications (subcomponent: Security (SQL Logger)). The supported version that is affected is 14…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-2730

Published Jan 18, 2018

Vulnerability in the Oracle Retail Merchandising System component of Oracle Retail Applications (subcomponent: Cross Pillar). The supported version that is affected is 16.0. Easil…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1