Comparison Overview
Bath & Body Works

Bath & Body Works
Columbus, Ohio, US, 43068
Last Update: 02/04/2026
We were founded on a simple idea: to make the world a brighter, happier place through the power of fragrance. As we've grown, so has our purpose and today, we help the world live more fully through the power of fragrance. We’re a team that cares about our customers and...

Dillard's
1600 Cantrell Rd., Little Rock, 72201, US
Last Update: 01/04/2026
Dillard's, Inc. ranks among the nation's largest fashion apparel and home furnishings retailers with annual revenues exceeding $6.1 billion. The Company focuses on delivering maximum fashion and value to its shoppers by offering compelling apparel and home selections co...
Compliance Ranges Comparison

Bath & Body Works







Dillard's






Benchmark & Cyber Underwriting Signals
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for Bath & Body Works in 2026.
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for Dillard's in 2026.
Incident History - Bath & Body Works (X = Date, Y = Severity)
Bath & Body Works cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Dillard's (X = Date, Y = Severity)
Dillard's cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Bath & Body Works

Dillard's
FAQ
Latest Global CVEs
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.
An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS. Strict-winding polygons are intentionally unsupported for indexing, but the guard that rejects them does not inspect members of a GeometryCollection, allowing the unsafe path to be reached which ends with an ensuing null-pointer dereference.
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.