This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HJoyent Json
APPJoyent< 10.0.0Oracle Commerce Guided Search
APPOracle11.3.2Oracle Financial Services Crime And Compliance Management Studio
APPOracle8.0.8.2.08.0.8.3.0Oracle Financial Services Regulatory Reporting With Agilereporter
APPOracle8.0.9.6.3Oracle Timesten In Memory Database
APPOracle< 21.1.1.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References
Related vulnerabilities
CVE-2022-22947CRITICAL10.0⚠ KEVPL ✓same product
RCE poprzez code injection w VMware Spring Cloud Gateway (Actuator endpoint)
CVE-2018-1273CRITICAL9.8⚠ KEVPL ✓same product
RCE w Spring Data Commons — podatność property bindera
CVE-2026-70977CRITICAL9.1same product
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Comm...
CVE-2026-70976CRITICAL9.1same product
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Comm...
CVE-2026-70978CRITICAL9.1same product
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Comm...