{"document":{"category":"Oracle Critical Patch Update Advisory","csaf_version":"2.0","publisher":{"category":"vendor","name":"Oracle","namespace":"https://www.oracle.com"},"references":[{"summary":"URL to html version of Advisory","url":"https://www.oracle.com/security-alerts/cpujan2023.html"},{"category":"self","summary":"URL to CSAF version of Advisory","url":"https://www.oracle.com/docs/tech/security-alerts/cpujan2023csaf.json"}],"title":"Oracle Critical Patch Update Advisory - January 2023 - Oracle CSAF","tracking":{"current_release_date":"2023-02-27T13:00:00-07:00","id":"CPUJan2023csaf","initial_release_date":"2023-01-17T13:00:00-07:00","revision_history":[{"date":"2023-01-17T13:00:00-07:00","number":"1","summary":"Initial Release"},{"date":"2023-01-20T13:00:00-07:00","number":"2","summary":"Rev 2. Java matrix note changes. WLS version updated for CVE-2022-25647. Credit name updates."},{"date":"2023-02-27T13:00:00-07:00","number":"3","summary":"Rev 3. Coherence version updated for CVE-2022-23305. Credit name update."}],"status":"draft","version":"3"}},"product_tree":{"branches":[{"branches":[{"branches":[{"branches":[{"category":"product_version","name":"Oracle BI Publisher Version 12.2.1.4.0","product":{"name":"Oracle BI Publisher Version 12.2.1.4.0","product_id":"P-1479V-12.2.1.4.0"}},{"category":"product_version","name":"Oracle BI Publisher Version 5.9.0.0.0","product":{"name":"Oracle BI Publisher Version 5.9.0.0.0","product_id":"P-1479V-5.9.0.0.0"}},{"category":"product_version","name":"Oracle BI Publisher Version 6.4.0.0.0","product":{"name":"Oracle BI Publisher Version 6.4.0.0.0","product_id":"P-1479V-6.4.0.0.0"}}],"category":"product_name","name":"Oracle BI Publisher"},{"branches":[{"category":"product_version","name":"Oracle Business Intelligence Enterprise Edition Version 5.9.0.0.0","product":{"name":"Oracle Business Intelligence Enterprise Edition Version 5.9.0.0.0","product_id":"P-2025V-5.9.0.0.0"}},{"category":"product_version","name":"Oracle Business Intelligence Enterprise Edition Version 6.4.0.0.0","product":{"name":"Oracle Business Intelligence Enterprise Edition Version 6.4.0.0.0","product_id":"P-2025V-6.4.0.0.0"}}],"category":"product_name","name":"Oracle Business Intelligence Enterprise Edition"}],"category":"product_family","name":"Oracle Analytics"},{"branches":[{"branches":[{"category":"product_version_range","name":"Big Data Spatial and Graph Version Prior to 21.4.3","product":{"name":"Big Data Spatial and Graph Version Prior to 21.4.3","product_id":"P-11528V-Prior to 21.4.3"}},{"category":"product_version_range","name":"Big Data Spatial and Graph Version Prior to 23.1.0","product":{"name":"Big Data Spatial and Graph Version Prior to 23.1.0","product_id":"P-11528V-Prior to 23.1.0"}}],"category":"product_name","name":"Big Data Spatial and Graph"}],"category":"product_family","name":"Oracle Big Data Graph"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Commerce Guided Search Version 11.3.2","product":{"name":"Oracle Commerce Guided Search Version 11.3.2","product_id":"P-9633V-11.3.2"}}],"category":"product_name","name":"Oracle Commerce Guided Search"}],"category":"product_family","name":"Oracle Commerce"},{"branches":[{"branches":[{"category":"product_version","name":"Management Cloud Engine Version 22.1.0.0.0","product":{"name":"Management Cloud Engine Version 22.1.0.0.0","product_id":"P-14252V-22.1.0.0.0"}}],"category":"product_name","name":"Management Cloud Engine"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Automated Test Suite Version 22.2.2","product":{"name":"Oracle Communications Cloud Native Core Automated Test Suite Version 22.2.2","product_id":"P-14488V-22.2.2"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Automated Test Suite Version 22.3.1","product":{"name":"Oracle Communications Cloud Native Core Automated Test Suite Version 22.3.1","product_id":"P-14488V-22.3.1"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Automated Test Suite Version 22.4.0","product":{"name":"Oracle Communications Cloud Native Core Automated Test Suite Version 22.4.0","product_id":"P-14488V-22.4.0"}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Automated Test Suite"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.1.0","product":{"name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.1.0","product_id":"P-14121V-22.1.0"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.1.1","product":{"name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.1.1","product_id":"P-14121V-22.1.1"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.2.0","product":{"name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.2.0","product_id":"P-14121V-22.2.0"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.2.1","product":{"name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.2.1","product_id":"P-14121V-22.2.1"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.2.2","product":{"name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.2.2","product_id":"P-14121V-22.2.2"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.2.4","product":{"name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.2.4","product_id":"P-14121V-22.2.4"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.3.0","product":{"name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.3.0","product_id":"P-14121V-22.3.0"}},{"category":"product_version_range","name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.3.0-22.4.0","product":{"name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.3.0-22.4.0","product_id":"P-14121V-22.3.0-22.4.0"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.3.1","product":{"name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.3.1","product_id":"P-14121V-22.3.1"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.3.2","product":{"name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.3.2","product_id":"P-14121V-22.3.2"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.4.0","product":{"name":"Oracle Communications Cloud Native Core Binding Support Function Version 22.4.0","product_id":"P-14121V-22.4.0"}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Binding Support Function"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Console Version 22.3.0","product":{"name":"Oracle Communications Cloud Native Core Console Version 22.3.0","product_id":"P-14250V-22.3.0"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Console Version 22.4.0","product":{"name":"Oracle Communications Cloud Native Core Console Version 22.4.0","product_id":"P-14250V-22.4.0"}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Console"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Network Data Analytics Function Version 22.0.0.0.0","product":{"name":"Oracle Communications Cloud Native Core Network Data Analytics Function Version 22.0.0.0.0","product_id":"P-14489V-22.0.0.0.0"}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Network Data Analytics Function"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Network Exposure Function Version 22.3.1","product":{"name":"Oracle Communications Cloud Native Core Network Exposure Function Version 22.3.1","product_id":"P-14122V-22.3.1"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Network Exposure Function Version 22.4.0","product":{"name":"Oracle Communications Cloud Native Core Network Exposure Function Version 22.4.0","product_id":"P-14122V-22.4.0"}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Network Exposure Function"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 22.3.0","product":{"name":"Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 22.3.0","product_id":"P-14125V-22.3.0"}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Network Function Cloud Native Environment"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Network Repository Function Version 22.3.0","product":{"name":"Oracle Communications Cloud Native Core Network Repository Function Version 22.3.0","product_id":"P-14118V-22.3.0"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Network Repository Function Version 22.3.2","product":{"name":"Oracle Communications Cloud Native Core Network Repository Function Version 22.3.2","product_id":"P-14118V-22.3.2"}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Network Repository Function"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Network Slice Selection Function Version 22.3.1","product":{"name":"Oracle Communications Cloud Native Core Network Slice Selection Function Version 22.3.1","product_id":"P-14130V-22.3.1"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Network Slice Selection Function Version 22.4.1","product":{"name":"Oracle Communications Cloud Native Core Network Slice Selection Function Version 22.4.1","product_id":"P-14130V-22.4.1"}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Network Slice Selection Function"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Policy Version 1.11.0","product":{"name":"Oracle Communications Cloud Native Core Policy Version 1.11.0","product_id":"P-14277V-1.11.0"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Policy Version 22.3.0","product":{"name":"Oracle Communications Cloud Native Core Policy Version 22.3.0","product_id":"P-14277V-22.3.0"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Policy Version 22.4.0","product":{"name":"Oracle Communications Cloud Native Core Policy Version 22.4.0","product_id":"P-14277V-22.4.0"}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Policy"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 22.3.1","product":{"name":"Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 22.3.1","product_id":"P-14123V-22.3.1"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 22.4.0","product":{"name":"Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 22.4.0","product_id":"P-14123V-22.4.0"}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Security Edge Protection Proxy"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Unified Data Repository Version 22.2.2","product":{"name":"Oracle Communications Cloud Native Core Unified Data Repository Version 22.2.2","product_id":"P-14119V-22.2.2"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Unified Data Repository Version 22.2.3","product":{"name":"Oracle Communications Cloud Native Core Unified Data Repository Version 22.2.3","product_id":"P-14119V-22.2.3"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Unified Data Repository Version 22.3.3","product":{"name":"Oracle Communications Cloud Native Core Unified Data Repository Version 22.3.3","product_id":"P-14119V-22.3.3"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Unified Data Repository Version 22.3.4","product":{"name":"Oracle Communications Cloud Native Core Unified Data Repository Version 22.3.4","product_id":"P-14119V-22.3.4"}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Unified Data Repository Version 22.4.0","product":{"name":"Oracle Communications Cloud Native Core Unified Data Repository Version 22.4.0","product_id":"P-14119V-22.4.0"}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Unified Data Repository"},{"branches":[{"category":"product_version","name":"Oracle Communications Converged Application Server Version 7.1.0","product":{"name":"Oracle Communications Converged Application Server Version 7.1.0","product_id":"P-5382V-7.1.0"}},{"category":"product_version","name":"Oracle Communications Converged Application Server Version 8.0.0","product":{"name":"Oracle Communications Converged Application Server Version 8.0.0","product_id":"P-5382V-8.0.0"}}],"category":"product_name","name":"Oracle Communications Converged Application Server"},{"branches":[{"category":"product_version","name":"Oracle Communications Diameter Intelligence Hub Version 8.2.3.0","product":{"name":"Oracle Communications Diameter Intelligence Hub Version 8.2.3.0","product_id":"P-11126V-8.2.3.0"}}],"category":"product_name","name":"Oracle Communications Diameter Intelligence Hub"},{"branches":[{"category":"product_version","name":"Oracle Communications Diameter Signaling Router Version 8.6.0.0","product":{"name":"Oracle Communications Diameter Signaling Router Version 8.6.0.0","product_id":"P-10899V-8.6.0.0"}}],"category":"product_name","name":"Oracle Communications Diameter Signaling Router"},{"branches":[{"category":"product_version","name":"Oracle Communications Performance Intelligence Center (PIC) Software Version 10.4.0.4.1","product":{"name":"Oracle Communications Performance Intelligence Center (PIC) Software Version 10.4.0.4.1","product_id":"P-11044V-10.4.0.4.1"}}],"category":"product_name","name":"Oracle Communications Performance Intelligence Center (PIC) Software"},{"branches":[{"category":"product_version","name":"Oracle SD-WAN Aware Version 8.2.1.9.0","product":{"name":"Oracle SD-WAN Aware Version 8.2.1.9.0","product_id":"P-13941V-8.2.1.9.0"}},{"category":"product_version","name":"Oracle SD-WAN Aware Version 9.0.1.4.0","product":{"name":"Oracle SD-WAN Aware Version 9.0.1.4.0","product_id":"P-13941V-9.0.1.4.0"}}],"category":"product_name","name":"Oracle SD-WAN Aware"}],"category":"product_family","name":"Oracle Communications"},{"branches":[{"branches":[{"category":"product_version_range","name":"Oracle Communications BRM - Elastic Charging Engine Version 12.0.0.3.0-12.0.0.7.0","product":{"name":"Oracle Communications BRM - Elastic Charging Engine Version 12.0.0.3.0-12.0.0.7.0","product_id":"P-9742V-12.0.0.3.0-12.0.0.7.0"}}],"category":"product_name","name":"Oracle Communications BRM - Elastic Charging Engine"},{"branches":[{"category":"product_version_range","name":"Oracle Communications Billing and Revenue Management(EAI Manager) Version 12.0.0.4.0-12.0.0.7.0","product":{"name":"Oracle Communications Billing and Revenue Management(EAI Manager) Version 12.0.0.4.0-12.0.0.7.0","product_id":"P-2136(EAI Manager)V-12.0.0.4.0-12.0.0.7.0"}},{"category":"product_version_range","name":"Oracle Communications Billing and Revenue Management(REST Services Manager) Version 12.0.0.4.0-12.0.0.7.0","product":{"name":"Oracle Communications Billing and Revenue Management(REST Services Manager) Version 12.0.0.4.0-12.0.0.7.0","product_id":"P-2136(REST Services Manager)V-12.0.0.4.0-12.0.0.7.0"}},{"category":"product_version_range","name":"Oracle Communications Billing and Revenue Management Version 12.0.0.4.0-12.0.0.7.0","product":{"name":"Oracle Communications Billing and Revenue Management Version 12.0.0.4.0-12.0.0.7.0","product_id":"P-2136V-12.0.0.4.0-12.0.0.7.0"}}],"category":"product_name","name":"Oracle Communications Billing and Revenue Management"},{"branches":[{"category":"product_version","name":"Oracle Communications Calendar Server Version 8.0.0.6.0","product":{"name":"Oracle Communications Calendar Server Version 8.0.0.6.0","product_id":"P-8494V-8.0.0.6.0"}}],"category":"product_name","name":"Oracle Communications Calendar Server"},{"branches":[{"category":"product_version","name":"Oracle Communications Contacts Server Version 8.0.0.7.0","product":{"name":"Oracle Communications Contacts Server Version 8.0.0.7.0","product_id":"P-10696V-8.0.0.7.0"}}],"category":"product_name","name":"Oracle Communications Contacts Server"},{"branches":[{"category":"product_version","name":"Oracle Communications Convergence Version 3.0.3.1.0","product":{"name":"Oracle Communications Convergence Version 3.0.3.1.0","product_id":"P-8501V-3.0.3.1.0"}}],"category":"product_name","name":"Oracle Communications Convergence"},{"branches":[{"category":"product_version","name":"Oracle Communications Design Studio Version 7.4.2","product":{"name":"Oracle Communications Design Studio Version 7.4.2","product_id":"P-2283V-7.4.2"}}],"category":"product_name","name":"Oracle Communications Design Studio"},{"branches":[{"category":"product_version_range","name":"Oracle Communications Elastic Charging Engine Version 12.0.0.3.0-12.0.0.7.0","product":{"name":"Oracle Communications Elastic Charging Engine Version 12.0.0.3.0-12.0.0.7.0","product_id":"P-9742V-12.0.0.3.0-12.0.0.7.0"}},{"category":"product_version_range","name":"Oracle Communications Elastic Charging Engine Version 12.0.0.5.0-12.0.0.7.0","product":{"name":"Oracle Communications Elastic Charging Engine Version 12.0.0.5.0-12.0.0.7.0","product_id":"P-9742V-12.0.0.5.0-12.0.0.7.0"}}],"category":"product_name","name":"Oracle Communications Elastic Charging Engine"},{"branches":[{"category":"product_version","name":"Oracle Communications Instant Messaging Server Version 10.0.1.6.0","product":{"name":"Oracle Communications Instant Messaging Server Version 10.0.1.6.0","product_id":"P-8495V-10.0.1.6.0"}}],"category":"product_name","name":"Oracle Communications Instant Messaging Server"},{"branches":[{"category":"product_version","name":"Oracle Communications Messaging Server Version 8.1.0.20.0","product":{"name":"Oracle Communications Messaging Server Version 8.1.0.20.0","product_id":"P-8496V-8.1.0.20.0"}}],"category":"product_name","name":"Oracle Communications Messaging Server"},{"branches":[{"category":"product_version","name":"Oracle Communications MetaSolv Solution Version 6.3.1","product":{"name":"Oracle Communications MetaSolv Solution Version 6.3.1","product_id":"P-2267V-6.3.1"}}],"category":"product_name","name":"Oracle Communications MetaSolv Solution"},{"branches":[{"category":"product_version","name":"Oracle Communications Order and Service Management Version 7.4.0","product":{"name":"Oracle Communications Order and Service Management Version 7.4.0","product_id":"P-2270V-7.4.0"}}],"category":"product_name","name":"Oracle Communications Order and Service Management"},{"branches":[{"category":"product_version_range","name":"Oracle Communications Pricing Design Center Version 12.0.0.5.0-12.0.0.7.0","product":{"name":"Oracle Communications Pricing Design Center Version 12.0.0.5.0-12.0.0.7.0","product_id":"P-9437V-12.0.0.5.0-12.0.0.7.0"}}],"category":"product_name","name":"Oracle Communications Pricing Design Center"},{"branches":[{"category":"product_version_range","name":"Oracle Communications Unified Assurance Version 5.5.0-5.5.9","product":{"name":"Oracle Communications Unified Assurance Version 5.5.0-5.5.9","product_id":"P-14597V-5.5.0-5.5.9"}},{"category":"product_version_range","name":"Oracle Communications Unified Assurance Version 6.0.0-6.0.1","product":{"name":"Oracle Communications Unified Assurance Version 6.0.0-6.0.1","product_id":"P-14597V-6.0.0-6.0.1"}}],"category":"product_name","name":"Oracle Communications Unified Assurance"},{"branches":[{"category":"product_version","name":"Oracle Communications Unified Inventory Management Version 7.4.0","product":{"name":"Oracle Communications Unified Inventory Management Version 7.4.0","product_id":"P-4516V-7.4.0"}},{"category":"product_version_range","name":"Oracle Communications Unified Inventory Management Version 7.4.0-7.4.2","product":{"name":"Oracle Communications Unified Inventory Management Version 7.4.0-7.4.2","product_id":"P-4516V-7.4.0-7.4.2"}},{"category":"product_version","name":"Oracle Communications Unified Inventory Management Version 7.4.1","product":{"name":"Oracle Communications Unified Inventory Management Version 7.4.1","product_id":"P-4516V-7.4.1"}},{"category":"product_version","name":"Oracle Communications Unified Inventory Management Version 7.4.2","product":{"name":"Oracle Communications Unified Inventory Management Version 7.4.2","product_id":"P-4516V-7.4.2"}},{"category":"product_version","name":"Oracle Communications Unified Inventory Management Version 7.5.0","product":{"name":"Oracle Communications Unified Inventory Management Version 7.5.0","product_id":"P-4516V-7.5.0"}}],"category":"product_name","name":"Oracle Communications Unified Inventory Management"}],"category":"product_family","name":"Oracle Communications Applications"},{"branches":[{"branches":[{"category":"product_version_range","name":"Primavera Gateway Version 18.8.0-18.8.15","product":{"name":"Primavera Gateway Version 18.8.0-18.8.15","product_id":"P-10605V-18.8.0-18.8.15"}},{"category":"product_version_range","name":"Primavera Gateway Version 19.12.0-19.12.15","product":{"name":"Primavera Gateway Version 19.12.0-19.12.15","product_id":"P-10605V-19.12.0-19.12.15"}},{"category":"product_version_range","name":"Primavera Gateway Version 20.12.0-20.12.10","product":{"name":"Primavera Gateway Version 20.12.0-20.12.10","product_id":"P-10605V-20.12.0-20.12.10"}},{"category":"product_version_range","name":"Primavera Gateway Version 21.12.0-21.12.8","product":{"name":"Primavera Gateway Version 21.12.0-21.12.8","product_id":"P-10605V-21.12.0-21.12.8"}}],"category":"product_name","name":"Primavera Gateway"},{"branches":[{"category":"product_version","name":"Primavera Unifier Version 18.8","product":{"name":"Primavera Unifier Version 18.8","product_id":"P-10354V-18.8"}},{"category":"product_version","name":"Primavera Unifier Version 19.12","product":{"name":"Primavera Unifier Version 19.12","product_id":"P-10354V-19.12"}},{"category":"product_version","name":"Primavera Unifier Version 20.12","product":{"name":"Primavera Unifier Version 20.12","product_id":"P-10354V-20.12"}},{"category":"product_version","name":"Primavera Unifier Version 21.12","product":{"name":"Primavera Unifier Version 21.12","product_id":"P-10354V-21.12"}},{"category":"product_version","name":"Primavera Unifier Version 22.12","product":{"name":"Primavera Unifier Version 22.12","product_id":"P-10354V-22.12"}}],"category":"product_name","name":"Primavera Unifier"}],"category":"product_family","name":"Oracle Construction and Engineering"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Data Provider for .NET Version 19c","product":{"name":"Oracle Data Provider for .NET Version 19c","product_id":"P-1321V-19c"}},{"category":"product_version","name":"Oracle Data Provider for .NET Version 21c","product":{"name":"Oracle Data Provider for .NET Version 21c","product_id":"P-1321V-21c"}}],"category":"product_name","name":"Oracle Data Provider for .NET"},{"branches":[{"category":"product_version","name":"Oracle Database Server(Java VM) Version 19c","product":{"name":"Oracle Database Server(Java VM) Version 19c","product_id":"P-5(Java VM)V-19c"}},{"category":"product_version","name":"Oracle Database Server(Oracle Database Data Redaction) Version 19c","product":{"name":"Oracle Database Server(Oracle Database Data Redaction) Version 19c","product_id":"P-5(Oracle Database Data Redaction)V-19c"}},{"category":"product_version","name":"Oracle Database Server(Oracle Database Fleet Patching) Version 19c","product":{"name":"Oracle Database Server(Oracle Database Fleet Patching) Version 19c","product_id":"P-5(Oracle Database Fleet Patching)V-19c"}},{"category":"product_version","name":"Oracle Database Server(Oracle Database RDBMS Security) Version 19c","product":{"name":"Oracle Database Server(Oracle Database RDBMS Security) Version 19c","product_id":"P-5(Oracle Database RDBMS Security)V-19c"}},{"category":"product_version","name":"Oracle Database Server(Oracle Database SQLcl) Version 19c","product":{"name":"Oracle Database Server(Oracle Database SQLcl) Version 19c","product_id":"P-5(Oracle Database SQLcl)V-19c"}},{"category":"product_version","name":"Oracle Database Server(Oracle Database) Version 19c","product":{"name":"Oracle Database Server(Oracle Database) Version 19c","product_id":"P-5(Oracle Database)V-19c"}},{"category":"product_version","name":"Oracle Database Server(GraalVM Multilingual Engine) Version 21c","product":{"name":"Oracle Database Server(GraalVM Multilingual Engine) Version 21c","product_id":"P-5(GraalVM Multilingual Engine)V-21c"}},{"category":"product_version","name":"Oracle Database Server(Java VM) Version 21c","product":{"name":"Oracle Database Server(Java VM) Version 21c","product_id":"P-5(Java VM)V-21c"}},{"category":"product_version","name":"Oracle Database Server(Oracle Database - Machine Learning for Python) Version 21c","product":{"name":"Oracle Database Server(Oracle Database - Machine Learning for Python) Version 21c","product_id":"P-5(Oracle Database - Machine Learning for Python)V-21c"}},{"category":"product_version","name":"Oracle Database Server(Oracle Database Data Redaction) Version 21c","product":{"name":"Oracle Database Server(Oracle Database Data Redaction) Version 21c","product_id":"P-5(Oracle Database Data Redaction)V-21c"}},{"category":"product_version","name":"Oracle Database Server(Oracle Database Fleet Patching) Version 21c","product":{"name":"Oracle Database Server(Oracle Database Fleet Patching) Version 21c","product_id":"P-5(Oracle Database Fleet Patching)V-21c"}},{"category":"product_version","name":"Oracle Database Server(Oracle Database Portable Clusterware) Version 21c","product":{"name":"Oracle Database Server(Oracle Database Portable Clusterware) Version 21c","product_id":"P-5(Oracle Database Portable Clusterware)V-21c"}},{"category":"product_version","name":"Oracle Database Server(Oracle Database RDBMS Security) Version 21c","product":{"name":"Oracle Database Server(Oracle Database RDBMS Security) Version 21c","product_id":"P-5(Oracle Database RDBMS Security)V-21c"}},{"category":"product_version","name":"Oracle Database Server(Oracle Database SQLcl) Version 21c","product":{"name":"Oracle Database Server(Oracle Database SQLcl) Version 21c","product_id":"P-5(Oracle Database SQLcl)V-21c"}},{"category":"product_version","name":"Oracle Database Server(Oracle Database) Version 21c","product":{"name":"Oracle Database Server(Oracle Database) Version 21c","product_id":"P-5(Oracle Database)V-21c"}}],"category":"product_name","name":"Oracle Database Server"},{"branches":[{"category":"product_version","name":"Oracle SQLcl Version 19c","product":{"name":"Oracle SQLcl Version 19c","product_id":"P-13824V-19c"}},{"category":"product_version","name":"Oracle SQLcl Version 21c","product":{"name":"Oracle SQLcl Version 21c","product_id":"P-13824V-21c"}}],"category":"product_name","name":"Oracle SQLcl"},{"branches":[{"category":"product_version_range","name":"Perl Version Perl: Prior to 5.35","product":{"name":"Perl Version Perl: Prior to 5.35","product_id":"P-9472V-Perl: Prior to 5.35"}}],"category":"product_name","name":"Perl"},{"branches":[{"category":"product_version","name":"Spatial and Graph Version 19c","product":{"name":"Spatial and Graph Version 19c","product_id":"P-619V-19c"}},{"category":"product_version","name":"Spatial and Graph Version 21c","product":{"name":"Spatial and Graph Version 21c","product_id":"P-619V-21c"}}],"category":"product_name","name":"Spatial and Graph"},{"branches":[{"category":"product_version","name":"Spatial and Graph Mapviewer Version 19c","product":{"name":"Spatial and Graph Mapviewer Version 19c","product_id":"P-619V-19c"}},{"category":"product_version","name":"Spatial and Graph Mapviewer Version 21c","product":{"name":"Spatial and Graph Mapviewer Version 21c","product_id":"P-619V-21c"}}],"category":"product_name","name":"Spatial and Graph Mapviewer"}],"category":"product_family","name":"Oracle Database Server"},{"branches":[{"branches":[{"category":"product_version_range","name":"Oracle Applications DBA Version 12.2.3-12.2.12","product":{"name":"Oracle Applications DBA Version 12.2.3-12.2.12","product_id":"P-166V-12.2.3-12.2.12"}}],"category":"product_name","name":"Oracle Applications DBA"},{"branches":[{"category":"product_version_range","name":"Oracle Collaborative Planning Version 12.2.3-12.2.12","product":{"name":"Oracle Collaborative Planning Version 12.2.3-12.2.12","product_id":"P-1037V-12.2.3-12.2.12"}}],"category":"product_name","name":"Oracle Collaborative Planning"},{"branches":[{"category":"product_version_range","name":"Oracle HCM Common Architecture Version 12.2.3-12.2.12","product":{"name":"Oracle HCM Common Architecture Version 12.2.3-12.2.12","product_id":"P-2021V-12.2.3-12.2.12"}}],"category":"product_name","name":"Oracle HCM Common Architecture"},{"branches":[{"category":"product_version_range","name":"Oracle Learning Management Version 12.2.3-12.2.12","product":{"name":"Oracle Learning Management Version 12.2.3-12.2.12","product_id":"P-937V-12.2.3-12.2.12"}}],"category":"product_name","name":"Oracle Learning Management"},{"branches":[{"category":"product_version_range","name":"Oracle Marketing Version 12.2.3-12.2.12","product":{"name":"Oracle Marketing Version 12.2.3-12.2.12","product_id":"P-229V-12.2.3-12.2.12"}}],"category":"product_name","name":"Oracle Marketing"},{"branches":[{"category":"product_version_range","name":"Oracle Mobile Field Service Version 12.2.3-12.2.12","product":{"name":"Oracle Mobile Field Service Version 12.2.3-12.2.12","product_id":"P-753V-12.2.3-12.2.12"}}],"category":"product_name","name":"Oracle Mobile Field Service"},{"branches":[{"category":"product_version_range","name":"Oracle Sales Offline Version 12.2.3-12.2.12","product":{"name":"Oracle Sales Offline Version 12.2.3-12.2.12","product_id":"P-1009V-12.2.3-12.2.12"}}],"category":"product_name","name":"Oracle Sales Offline"},{"branches":[{"category":"product_version_range","name":"Oracle Sales for Handhelds Version 12.2.3-12.2.12","product":{"name":"Oracle Sales for Handhelds Version 12.2.3-12.2.12","product_id":"P-186V-12.2.3-12.2.12"}}],"category":"product_name","name":"Oracle Sales for Handhelds"},{"branches":[{"category":"product_version_range","name":"Oracle Self-Service Human Resources Version 12.2.3-12.2.12","product":{"name":"Oracle Self-Service Human Resources Version 12.2.3-12.2.12","product_id":"P-1566V-12.2.3-12.2.12"}}],"category":"product_name","name":"Oracle Self-Service Human Resources"},{"branches":[{"category":"product_version_range","name":"Oracle Web Applications Desktop Integrator Version 12.2.3-12.2.12","product":{"name":"Oracle Web Applications Desktop Integrator Version 12.2.3-12.2.12","product_id":"P-1171V-12.2.3-12.2.12"}}],"category":"product_name","name":"Oracle Web Applications Desktop Integrator"},{"branches":[{"category":"product_version_range","name":"Oracle iSetup Version 12.2.3-12.2.12","product":{"name":"Oracle iSetup Version 12.2.3-12.2.12","product_id":"P-841V-12.2.3-12.2.12"}}],"category":"product_name","name":"Oracle iSetup"},{"branches":[{"category":"product_version_range","name":"Oracle iSupplier Portal Version 12.2.6-12.2.8","product":{"name":"Oracle iSupplier Portal Version 12.2.6-12.2.8","product_id":"P-208V-12.2.6-12.2.8"}}],"category":"product_name","name":"Oracle iSupplier Portal"}],"category":"product_family","name":"Oracle E-Business Suite"},{"branches":[{"branches":[{"category":"product_version","name":"Enterprise Manager Base Platform Version 13.4.0.0","product":{"name":"Enterprise Manager Base Platform Version 13.4.0.0","product_id":"P-1370V-13.4.0.0"}},{"category":"product_version","name":"Enterprise Manager Base Platform Version 13.5.0.0","product":{"name":"Enterprise Manager Base Platform Version 13.5.0.0","product_id":"P-1370V-13.5.0.0"}}],"category":"product_name","name":"Enterprise Manager Base Platform"},{"branches":[{"category":"product_version","name":"Enterprise Manager Ops Center Version 12.4.0.0","product":{"name":"Enterprise Manager Ops Center Version 12.4.0.0","product_id":"P-9835V-12.4.0.0"}}],"category":"product_name","name":"Enterprise Manager Ops Center"}],"category":"product_family","name":"Oracle Enterprise Manager"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Essbase Version 21.4","product":{"name":"Oracle Essbase Version 21.4","product_id":"P-4379V-21.4"}}],"category":"product_name","name":"Oracle Essbase"}],"category":"product_family","name":"Oracle Essbase"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Banking Enterprise Default Management Version 2.12.0","product":{"name":"Oracle Banking Enterprise Default Management Version 2.12.0","product_id":"P-13390V-2.12.0"}},{"category":"product_version","name":"Oracle Banking Enterprise Default Management Version 2.6.2","product":{"name":"Oracle Banking Enterprise Default Management Version 2.6.2","product_id":"P-13390V-2.6.2"}},{"category":"product_version","name":"Oracle Banking Enterprise Default Management Version 2.7.0","product":{"name":"Oracle Banking Enterprise Default Management Version 2.7.0","product_id":"P-13390V-2.7.0"}},{"category":"product_version","name":"Oracle Banking Enterprise Default Management Version 2.7.1","product":{"name":"Oracle Banking Enterprise Default Management Version 2.7.1","product_id":"P-13390V-2.7.1"}}],"category":"product_name","name":"Oracle Banking Enterprise Default Management"},{"branches":[{"category":"product_version","name":"Oracle Banking Loans Servicing Version 2.12.0","product":{"name":"Oracle Banking Loans Servicing Version 2.12.0","product_id":"P-13927V-2.12.0"}},{"category":"product_version","name":"Oracle Banking Loans Servicing Version 2.8.0","product":{"name":"Oracle Banking Loans Servicing Version 2.8.0","product_id":"P-13927V-2.8.0"}}],"category":"product_name","name":"Oracle Banking Loans Servicing"},{"branches":[{"category":"product_version","name":"Oracle Banking Party Management Version 2.7.0","product":{"name":"Oracle Banking Party Management Version 2.7.0","product_id":"P-13929V-2.7.0"}}],"category":"product_name","name":"Oracle Banking Party Management"},{"branches":[{"category":"product_version","name":"Oracle Banking Platform Version 2.12.0","product":{"name":"Oracle Banking Platform Version 2.12.0","product_id":"P-9178V-2.12.0"}},{"category":"product_version","name":"Oracle Banking Platform Version 2.6.2","product":{"name":"Oracle Banking Platform Version 2.6.2","product_id":"P-9178V-2.6.2"}},{"category":"product_version","name":"Oracle Banking Platform Version 2.7.1","product":{"name":"Oracle Banking Platform Version 2.7.1","product_id":"P-9178V-2.7.1"}},{"category":"product_version","name":"Oracle Banking Platform Version 2.9.0","product":{"name":"Oracle Banking Platform Version 2.9.0","product_id":"P-9178V-2.9.0"}}],"category":"product_name","name":"Oracle Banking Platform"},{"branches":[{"category":"product_version","name":"Oracle Financial Services Crime and Compliance Management Studio Version 8.0.8.3.1","product":{"name":"Oracle Financial Services Crime and Compliance Management Studio Version 8.0.8.3.1","product_id":"P-13595V-8.0.8.3.1"}}],"category":"product_name","name":"Oracle Financial Services Crime and Compliance Management Studio"}],"category":"product_family","name":"Oracle Financial Services Applications"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Hospitality Gift and Loyalty Version 9.1.0","product":{"name":"Oracle Hospitality Gift and Loyalty Version 9.1.0","product_id":"P-11600V-9.1.0"}}],"category":"product_name","name":"Oracle Hospitality Gift and Loyalty"},{"branches":[{"category":"product_version","name":"Oracle Hospitality Labor Management Version 9.1.0","product":{"name":"Oracle Hospitality Labor Management Version 9.1.0","product_id":"P-11601V-9.1.0"}}],"category":"product_name","name":"Oracle Hospitality Labor Management"},{"branches":[{"category":"product_version","name":"Oracle Hospitality Reporting and Analytics Version 9.1.0","product":{"name":"Oracle Hospitality Reporting and Analytics Version 9.1.0","product_id":"P-11599V-9.1.0"}}],"category":"product_name","name":"Oracle Hospitality Reporting and Analytics"},{"branches":[{"category":"product_version","name":"Oracle Hospitality Simphony Version 18.2.11","product":{"name":"Oracle Hospitality Simphony Version 18.2.11","product_id":"P-11594V-18.2.11"}},{"category":"product_version","name":"Oracle Hospitality Simphony Version 19.3.4","product":{"name":"Oracle Hospitality Simphony Version 19.3.4","product_id":"P-11594V-19.3.4"}}],"category":"product_name","name":"Oracle Hospitality Simphony"}],"category":"product_family","name":"Oracle Food and Beverage Applications"},{"branches":[{"branches":[{"category":"product_version","name":"Middleware Common Libraries and Tools Version 12.2.1.4.0","product":{"name":"Middleware Common Libraries and Tools Version 12.2.1.4.0","product_id":"P-4647V-12.2.1.4.0"}},{"category":"product_version","name":"Middleware Common Libraries and Tools Version 14.1.1.0.0","product":{"name":"Middleware Common Libraries and Tools Version 14.1.1.0.0","product_id":"P-4647V-14.1.1.0.0"}}],"category":"product_name","name":"Middleware Common Libraries and Tools"},{"branches":[{"category":"product_version","name":"Oracle Access Manager Version 12.2.1.4.0","product":{"name":"Oracle Access Manager Version 12.2.1.4.0","product_id":"P-5565V-12.2.1.4.0"}}],"category":"product_name","name":"Oracle Access Manager"},{"branches":[{"category":"product_version","name":"Oracle Coherence Version 14.1.1.0.0","product":{"name":"Oracle Coherence Version 14.1.1.0.0","product_id":"P-2545V-14.1.1.0.0"}}],"category":"product_name","name":"Oracle Coherence"},{"branches":[{"category":"product_version","name":"Oracle Fusion Middleware MapViewer Version 12.2.1.4.0","product":{"name":"Oracle Fusion Middleware MapViewer Version 12.2.1.4.0","product_id":"P-1215V-12.2.1.4.0"}}],"category":"product_name","name":"Oracle Fusion Middleware MapViewer"},{"branches":[{"category":"product_version_range","name":"Oracle Global Lifecycle Management NextGen OUI Framework Version Prior to 13.9.4.2.11","product":{"name":"Oracle Global Lifecycle Management NextGen OUI Framework Version Prior to 13.9.4.2.11","product_id":"P-12738V-Prior to 13.9.4.2.11"}}],"category":"product_name","name":"Oracle Global Lifecycle Management NextGen OUI Framework"},{"branches":[{"category":"product_version","name":"Oracle HTTP Server Version 12.2.1.4.0","product":{"name":"Oracle HTTP Server Version 12.2.1.4.0","product_id":"P-1042V-12.2.1.4.0"}}],"category":"product_name","name":"Oracle HTTP Server"},{"branches":[{"category":"product_version","name":"Oracle Middleware Common Libraries and Tools Version 12.2.1.4.0","product":{"name":"Oracle Middleware Common Libraries and Tools Version 12.2.1.4.0","product_id":"P-4647V-12.2.1.4.0"}}],"category":"product_name","name":"Oracle Middleware Common Libraries and Tools"},{"branches":[{"category":"product_version","name":"Oracle Outside In Technology Version 8.5.6","product":{"name":"Oracle Outside In Technology Version 8.5.6","product_id":"P-2276V-8.5.6"}}],"category":"product_name","name":"Oracle Outside In Technology"},{"branches":[{"category":"product_version","name":"Oracle Web Services Manager Version 12.2.1.4.0","product":{"name":"Oracle Web Services Manager Version 12.2.1.4.0","product_id":"P-1775V-12.2.1.4.0"}}],"category":"product_name","name":"Oracle Web Services Manager"},{"branches":[{"category":"product_version","name":"Oracle WebCenter Content Version 12.2.1.4.0","product":{"name":"Oracle WebCenter Content Version 12.2.1.4.0","product_id":"P-2271V-12.2.1.4.0"}}],"category":"product_name","name":"Oracle WebCenter Content"},{"branches":[{"category":"product_version","name":"Oracle WebCenter Sites Version 12.2.1.4.0","product":{"name":"Oracle WebCenter Sites Version 12.2.1.4.0","product_id":"P-9617V-12.2.1.4.0"}}],"category":"product_name","name":"Oracle WebCenter Sites"},{"branches":[{"category":"product_version","name":"Oracle WebLogic Server Version 12.2.1.3.0","product":{"name":"Oracle WebLogic Server Version 12.2.1.3.0","product_id":"P-5242V-12.2.1.3.0"}},{"category":"product_version","name":"Oracle WebLogic Server Version 12.2.1.4.0","product":{"name":"Oracle WebLogic Server Version 12.2.1.4.0","product_id":"P-5242V-12.2.1.4.0"}},{"category":"product_version","name":"Oracle WebLogic Server Version 14.1.1.0.0","product":{"name":"Oracle WebLogic Server Version 14.1.1.0.0","product_id":"P-5242V-14.1.1.0.0"}}],"category":"product_name","name":"Oracle WebLogic Server"}],"category":"product_family","name":"Oracle Fusion Middleware"},{"branches":[{"branches":[{"category":"product_version_range","name":"Oracle Global Lifecycle Management OPatchAuto Version DB: Prior to 12.2.0.1.32","product":{"name":"Oracle Global Lifecycle Management OPatchAuto Version DB: Prior to 12.2.0.1.32","product_id":"P-12752V-DB: Prior to 12.2.0.1.32"}},{"category":"product_version_range","name":"Oracle Global Lifecycle Management OPatchAuto Version DB: Prior to 12.2.0.1.35","product":{"name":"Oracle Global Lifecycle Management OPatchAuto Version DB: Prior to 12.2.0.1.35","product_id":"P-12752V-DB: Prior to 12.2.0.1.35"}}],"category":"product_name","name":"Oracle Global Lifecycle Management OPatchAuto"}],"category":"product_family","name":"Oracle Global Lifecycle Management"},{"branches":[{"branches":[{"category":"product_version_range","name":"GoldenGate Stream Analytics Version Prior to 19.1.0.0.8","product":{"name":"GoldenGate Stream Analytics Version Prior to 19.1.0.0.8","product_id":"P-5370V-Prior to 19.1.0.0.8"}},{"category":"product_version_range","name":"GoldenGate Stream Analytics Version Prior to 19.1.0.0.8","product":{"name":"GoldenGate Stream Analytics Version Prior to 19.1.0.0.8","product_id":"P-14015V-Prior to 19.1.0.0.8"}}],"category":"product_name","name":"GoldenGate Stream Analytics"},{"branches":[{"category":"product_version_range","name":"GoldenGate Veridata Version Prior to 12.2.1.4.220831","product":{"name":"GoldenGate Veridata Version Prior to 12.2.1.4.220831","product_id":"P-5758V-Prior to 12.2.1.4.220831"}}],"category":"product_name","name":"GoldenGate Veridata"},{"branches":[{"category":"product_version_range","name":"Management Pack for Oracle GoldenGate Version Prior to 12.2.1.2.221115","product":{"name":"Management Pack for Oracle GoldenGate Version Prior to 12.2.1.2.221115","product_id":"P-5759V-Prior to 12.2.1.2.221115"}}],"category":"product_name","name":"Management Pack for Oracle GoldenGate"},{"branches":[{"category":"product_version_range","name":"Oracle Stream Analytics Version Prior to 19.1.0.0.8","product":{"name":"Oracle Stream Analytics Version Prior to 19.1.0.0.8","product_id":"P-5370V-Prior to 19.1.0.0.8"}}],"category":"product_name","name":"Oracle Stream Analytics"}],"category":"product_family","name":"Oracle GoldenGate"},{"branches":[{"branches":[{"category":"product_version_range","name":"Oracle Graph Server and Client Version Prior to 21.4.3","product":{"name":"Oracle Graph Server and Client Version Prior to 21.4.3","product_id":"P-14069V-Prior to 21.4.3"}},{"category":"product_version_range","name":"Oracle Graph Server and Client Version Prior to 22.4.0","product":{"name":"Oracle Graph Server and Client Version Prior to 22.4.0","product_id":"P-14069V-Prior to 22.4.0"}},{"category":"product_version_range","name":"Oracle Graph Server and Client Version Prior to 23.1.0","product":{"name":"Oracle Graph Server and Client Version Prior to 23.1.0","product_id":"P-14069V-Prior to 23.1.0"}}],"category":"product_name","name":"Oracle Graph Server and Client"}],"category":"product_family","name":"Oracle Graph Server and Client"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Health Sciences Empirica Signal Version 9.1.0.52","product":{"name":"Oracle Health Sciences Empirica Signal Version 9.1.0.52","product_id":"P-9646V-9.1.0.52"}},{"category":"product_version","name":"Oracle Health Sciences Empirica Signal Version 9.2.0.52","product":{"name":"Oracle Health Sciences Empirica Signal Version 9.2.0.52","product_id":"P-9646V-9.2.0.52"}}],"category":"product_name","name":"Oracle Health Sciences Empirica Signal"}],"category":"product_family","name":"Oracle Health Sciences Applications"},{"branches":[{"branches":[{"category":"product_version_range","name":"Oracle Healthcare Data Repository Version 8.1.0.0-8.1.3.1","product":{"name":"Oracle Healthcare Data Repository Version 8.1.0.0-8.1.3.1","product_id":"P-9161V-8.1.0.0-8.1.3.1"}}],"category":"product_name","name":"Oracle Healthcare Data Repository"},{"branches":[{"category":"product_version_range","name":"Oracle Healthcare Translational Research Version 4.1.0.0-4.1.1.1","product":{"name":"Oracle Healthcare Translational Research Version 4.1.0.0-4.1.1.1","product_id":"P-9427V-4.1.0.0-4.1.1.1"}}],"category":"product_name","name":"Oracle Healthcare Translational Research"}],"category":"product_family","name":"Oracle HealthCare Applications"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Hospitality Cruise Shipboard Property Management System Version 20.2.2","product":{"name":"Oracle Hospitality Cruise Shipboard Property Management System Version 20.2.2","product_id":"P-11607V-20.2.2"}}],"category":"product_name","name":"Oracle Hospitality Cruise Shipboard Property Management System"}],"category":"product_family","name":"Oracle Hospitality Applications"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Hyperion Infrastructure Technology Version 11.2.10","product":{"name":"Oracle Hyperion Infrastructure Technology Version 11.2.10","product_id":"P-4392V-11.2.10"}}],"category":"product_name","name":"Oracle Hyperion Infrastructure Technology"}],"category":"product_family","name":"Oracle Hyperion"},{"branches":[{"branches":[{"category":"product_version_range","name":"Oracle Documaker Version 12.4.0-12.7.0","product":{"name":"Oracle Documaker Version 12.4.0-12.7.0","product_id":"P-5477V-12.4.0-12.7.0"}}],"category":"product_name","name":"Oracle Documaker"}],"category":"product_family","name":"Oracle Insurance Applications"},{"branches":[{"branches":[{"category":"product_version_range","name":"JD Edwards EnterpriseOne Orchestrator Version Prior to 9.2.7.2","product":{"name":"JD Edwards EnterpriseOne Orchestrator Version Prior to 9.2.7.2","product_id":"P-11681V-Prior to 9.2.7.2"}}],"category":"product_name","name":"JD Edwards EnterpriseOne Orchestrator"},{"branches":[{"category":"product_version_range","name":"JD Edwards EnterpriseOne Tools Version Prior to 9.2.7.2","product":{"name":"JD Edwards EnterpriseOne Tools Version Prior to 9.2.7.2","product_id":"P-4781V-Prior to 9.2.7.2"}}],"category":"product_name","name":"JD Edwards EnterpriseOne Tools"}],"category":"product_family","name":"Oracle JD Edwards"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Java SE Version Oracle GraalVM Enterprise Edition:20.3.8","product":{"name":"Oracle Java SE Version Oracle GraalVM Enterprise Edition:20.3.8","product_id":"P-13497V-Oracle GraalVM Enterprise Edition:20.3.8"}},{"category":"product_version","name":"Oracle Java SE Version Oracle GraalVM Enterprise Edition:21.3.4","product":{"name":"Oracle Java SE Version Oracle GraalVM Enterprise Edition:21.3.4","product_id":"P-13497V-Oracle GraalVM Enterprise Edition:21.3.4"}},{"category":"product_version","name":"Oracle Java SE Version Oracle GraalVM Enterprise Edition:22.3.0","product":{"name":"Oracle Java SE Version Oracle GraalVM Enterprise Edition:22.3.0","product_id":"P-13497V-Oracle GraalVM Enterprise Edition:22.3.0"}},{"category":"product_version","name":"Oracle Java SE Version Oracle Java SE:11.0.17","product":{"name":"Oracle Java SE Version Oracle Java SE:11.0.17","product_id":"P-856V-Oracle Java SE:11.0.17"}},{"category":"product_version","name":"Oracle Java SE Version Oracle Java SE:17.0.5","product":{"name":"Oracle Java SE Version Oracle Java SE:17.0.5","product_id":"P-856V-Oracle Java SE:17.0.5"}},{"category":"product_version","name":"Oracle Java SE Version Oracle Java SE:19.0.1","product":{"name":"Oracle Java SE Version Oracle Java SE:19.0.1","product_id":"P-856V-Oracle Java SE:19.0.1"}},{"category":"product_version","name":"Oracle Java SE Version Oracle Java SE:8u351","product":{"name":"Oracle Java SE Version Oracle Java SE:8u351","product_id":"P-856V-Oracle Java SE:8u351"}},{"category":"product_version_range","name":"Oracle Java SE Version Oracle Java SE:8u351-perf","product":{"name":"Oracle Java SE Version Oracle Java SE:8u351-perf","product_id":"P-856V-Oracle Java SE:8u351-perf"}}],"category":"product_name","name":"Oracle Java SE"}],"category":"product_family","name":"Oracle Java SE"},{"branches":[{"branches":[{"category":"product_version_range","name":"MySQL Cluster Version 7.4.38 and prior","product":{"name":"MySQL Cluster Version 7.4.38 and prior","product_id":"P-8479V-7.4.38 and prior"}},{"category":"product_version_range","name":"MySQL Cluster Version 7.5.28 and prior","product":{"name":"MySQL Cluster Version 7.5.28 and prior","product_id":"P-8479V-7.5.28 and prior"}},{"category":"product_version_range","name":"MySQL Cluster Version 7.6.24 and prior","product":{"name":"MySQL Cluster Version 7.6.24 and prior","product_id":"P-8479V-7.6.24 and prior"}},{"category":"product_version_range","name":"MySQL Cluster Version 8.0.31 and prior","product":{"name":"MySQL Cluster Version 8.0.31 and prior","product_id":"P-8479V-8.0.31 and prior"}}],"category":"product_name","name":"MySQL Cluster"},{"branches":[{"category":"product_version_range","name":"MySQL Connectors(Connector/C++) Version 8.0.31 and prior","product":{"name":"MySQL Connectors(Connector/C++) Version 8.0.31 and prior","product_id":"P-8576(Connector/C++)V-8.0.31 and prior"}},{"category":"product_version_range","name":"MySQL Connectors(Connector/ODBC) Version 8.0.31 and prior","product":{"name":"MySQL Connectors(Connector/ODBC) Version 8.0.31 and prior","product_id":"P-8576(Connector/ODBC)V-8.0.31 and prior"}},{"category":"product_version_range","name":"MySQL Connectors Version 8.0.31 and prior","product":{"name":"MySQL Connectors Version 8.0.31 and prior","product_id":"P-8576V-8.0.31 and prior"}}],"category":"product_name","name":"MySQL Connectors"},{"branches":[{"category":"product_version_range","name":"MySQL Enterprise Monitor Version 8.0.32 and prior","product":{"name":"MySQL Enterprise Monitor Version 8.0.32 and prior","product_id":"P-8480V-8.0.32 and prior"}}],"category":"product_name","name":"MySQL Enterprise Monitor"},{"branches":[{"category":"product_version_range","name":"MySQL Server Version 5.7.40 and prior","product":{"name":"MySQL Server Version 5.7.40 and prior","product_id":"P-8478V-5.7.40 and prior"}},{"category":"product_version_range","name":"MySQL Server Version 8.0.28 and prior","product":{"name":"MySQL Server Version 8.0.28 and prior","product_id":"P-8478V-8.0.28 and prior"}},{"category":"product_version_range","name":"MySQL Server Version 8.0.29 and prior","product":{"name":"MySQL Server Version 8.0.29 and prior","product_id":"P-8478V-8.0.29 and prior"}},{"category":"product_version_range","name":"MySQL Server Version 8.0.30 and prior","product":{"name":"MySQL Server Version 8.0.30 and prior","product_id":"P-8478V-8.0.30 and prior"}},{"category":"product_version_range","name":"MySQL Server Version 8.0.31 and prior","product":{"name":"MySQL Server Version 8.0.31 and prior","product_id":"P-8478V-8.0.31 and prior"}}],"category":"product_name","name":"MySQL Server"},{"branches":[{"category":"product_version_range","name":"MySQL Shell Version 8.0.31 and prior","product":{"name":"MySQL Shell Version 8.0.31 and prior","product_id":"P-8478V-8.0.31 and prior"}}],"category":"product_name","name":"MySQL Shell"},{"branches":[{"category":"product_version_range","name":"MySQL Workbench Version 8.0.31 and prior","product":{"name":"MySQL Workbench Version 8.0.31 and prior","product_id":"P-4627V-8.0.31 and prior"}}],"category":"product_name","name":"MySQL Workbench"}],"category":"product_family","name":"Oracle MySQL"},{"branches":[{"branches":[{"category":"product_version","name":"PeopleSoft Enterprise CC Common Application Objects Version 9.2","product":{"name":"PeopleSoft Enterprise CC Common Application Objects Version 9.2","product_id":"P-8911V-9.2"}}],"category":"product_name","name":"PeopleSoft Enterprise CC Common Application Objects"},{"branches":[{"category":"product_version","name":"PeopleSoft Enterprise CS Academic Advisement Version 9.2","product":{"name":"PeopleSoft Enterprise CS Academic Advisement Version 9.2","product_id":"P-5181V-9.2"}}],"category":"product_name","name":"PeopleSoft Enterprise CS Academic Advisement"},{"branches":[{"category":"product_version","name":"PeopleSoft Enterprise PeopleTools Version 8.58","product":{"name":"PeopleSoft Enterprise PeopleTools Version 8.58","product_id":"P-5085V-8.58"}},{"category":"product_version","name":"PeopleSoft Enterprise PeopleTools Version 8.59","product":{"name":"PeopleSoft Enterprise PeopleTools Version 8.59","product_id":"P-5085V-8.59"}},{"category":"product_version","name":"PeopleSoft Enterprise PeopleTools(Panel Processor) Version 8.60","product":{"name":"PeopleSoft Enterprise PeopleTools(Panel Processor) Version 8.60","product_id":"P-5085(Panel Processor)V-8.60"}},{"category":"product_version","name":"PeopleSoft Enterprise PeopleTools Version 8.60","product":{"name":"PeopleSoft Enterprise PeopleTools Version 8.60","product_id":"P-5085V-8.60"}}],"category":"product_name","name":"PeopleSoft Enterprise PeopleTools"}],"category":"product_family","name":"Oracle PeopleSoft"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Retail Service Backbone Version 14.1.3.2","product":{"name":"Oracle Retail Service Backbone Version 14.1.3.2","product_id":"P-10867V-14.1.3.2"}},{"category":"product_version","name":"Oracle Retail Service Backbone Version 15.0.3.1","product":{"name":"Oracle Retail Service Backbone Version 15.0.3.1","product_id":"P-10867V-15.0.3.1"}},{"category":"product_version","name":"Oracle Retail Service Backbone Version 16.0.3","product":{"name":"Oracle Retail Service Backbone Version 16.0.3","product_id":"P-10867V-16.0.3"}}],"category":"product_name","name":"Oracle Retail Service Backbone"}],"category":"product_family","name":"Oracle Retail Applications"},{"branches":[{"branches":[{"category":"product_version_range","name":"Siebel Apps - Marketing Version 22.10 and prior","product":{"name":"Siebel Apps - Marketing Version 22.10 and prior","product_id":"P-8974V-22.10 and prior"}}],"category":"product_name","name":"Siebel Apps - Marketing"},{"branches":[{"category":"product_version_range","name":"Siebel CRM Version 22.10 and prior","product":{"name":"Siebel CRM Version 22.10 and prior","product_id":"P-9001V-22.10 and prior"}}],"category":"product_name","name":"Siebel CRM"}],"category":"product_family","name":"Oracle Siebel CRM"},{"branches":[{"branches":[{"category":"product_version_range","name":"Oracle Spatial Studio Version Prior to 22.3.0","product":{"name":"Oracle Spatial Studio Version Prior to 22.3.0","product_id":"P-13600V-Prior to 22.3.0"}}],"category":"product_name","name":"Oracle Spatial Studio"}],"category":"product_family","name":"Oracle Spatial Studio"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Agile PLM Version 9.3.6","product":{"name":"Oracle Agile PLM Version 9.3.6","product_id":"P-4461V-9.3.6"}}],"category":"product_name","name":"Oracle Agile PLM"},{"branches":[{"category":"product_version_range","name":"Oracle AutoVue Version Prior to 21.0.2.0","product":{"name":"Oracle AutoVue Version Prior to 21.0.2.0","product_id":"P-4450V-Prior to 21.0.2.0"}},{"category":"product_version_range","name":"Oracle AutoVue Version Prior to 21.0.2.6","product":{"name":"Oracle AutoVue Version Prior to 21.0.2.6","product_id":"P-4450V-Prior to 21.0.2.6"}},{"category":"product_version_range","name":"Oracle AutoVue Version Prior to 21.0.2.6","product":{"name":"Oracle AutoVue Version Prior to 21.0.2.6","product_id":"P-4451V-Prior to 21.0.2.6"}}],"category":"product_name","name":"Oracle AutoVue"},{"branches":[{"category":"product_version","name":"Oracle Demantra Demand Management Version 12.1","product":{"name":"Oracle Demantra Demand Management Version 12.1","product_id":"P-2100V-12.1"}},{"category":"product_version","name":"Oracle Demantra Demand Management Version 12.2","product":{"name":"Oracle Demantra Demand Management Version 12.2","product_id":"P-2100V-12.2"}},{"category":"product_version","name":"Oracle Demantra Demand Management Version 12.2.10","product":{"name":"Oracle Demantra Demand Management Version 12.2.10","product_id":"P-2100V-12.2.10"}},{"category":"product_version","name":"Oracle Demantra Demand Management Version 12.2.11","product":{"name":"Oracle Demantra Demand Management Version 12.2.11","product_id":"P-2100V-12.2.11"}},{"category":"product_version","name":"Oracle Demantra Demand Management Version 12.2.12","product":{"name":"Oracle Demantra Demand Management Version 12.2.12","product_id":"P-2100V-12.2.12"}},{"category":"product_version","name":"Oracle Demantra Demand Management Version 12.2.7","product":{"name":"Oracle Demantra Demand Management Version 12.2.7","product_id":"P-2100V-12.2.7"}},{"category":"product_version","name":"Oracle Demantra Demand Management Version 12.2.8","product":{"name":"Oracle Demantra Demand Management Version 12.2.8","product_id":"P-2100V-12.2.8"}},{"category":"product_version","name":"Oracle Demantra Demand Management Version 12.2.9","product":{"name":"Oracle Demantra Demand Management Version 12.2.9","product_id":"P-2100V-12.2.9"}}],"category":"product_name","name":"Oracle Demantra Demand Management"}],"category":"product_family","name":"Oracle Supply Chain"},{"branches":[{"branches":[{"category":"product_version","name":"OSS Support Tools(Diagnostic Assistant) Version 2.12.43","product":{"name":"OSS Support Tools(Diagnostic Assistant) Version 2.12.43","product_id":"P-1330(Diagnostic Assistant)V-2.12.43"}},{"category":"product_version","name":"OSS Support Tools(Services Tools Bundle) Version 22.2.22.4.5","product":{"name":"OSS Support Tools(Services Tools Bundle) Version 22.2.22.4.5","product_id":"P-1330(Services Tools Bundle)V-22.2.22.4.5"}},{"category":"product_version","name":"OSS Support Tools(RDA - Remote Diagnostic Agent) Version 22.4.22.10.18","product":{"name":"OSS Support Tools(RDA - Remote Diagnostic Agent) Version 22.4.22.10.18","product_id":"P-1330(RDA - Remote Diagnostic Agent)V-22.4.22.10.18"}},{"category":"product_version","name":"OSS Support Tools(Services Tools Bundle) Version 22.4.22.10.18","product":{"name":"OSS Support Tools(Services Tools Bundle) Version 22.4.22.10.18","product_id":"P-1330(Services Tools Bundle)V-22.4.22.10.18"}}],"category":"product_name","name":"OSS Support Tools"}],"category":"product_family","name":"Oracle Support Tools"},{"branches":[{"branches":[{"category":"product_version_range","name":"Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers Version Prior to XCP2411","product":{"name":"Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers Version Prior to XCP2411","product_id":"P-10656V-Prior to XCP2411"}},{"category":"product_version_range","name":"Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers Version prior to XCP3111","product":{"name":"Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers Version prior to XCP3111","product_id":"P-10656V-prior to XCP3111"}},{"category":"product_version_range","name":"Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers Version prior to XCP4011","product":{"name":"Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers Version prior to XCP4011","product_id":"P-10656V-prior to XCP4011"}}],"category":"product_name","name":"Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers"},{"branches":[{"category":"product_version","name":"Oracle Solaris Version 10","product":{"name":"Oracle Solaris Version 10","product_id":"P-10006V-10"}},{"category":"product_version","name":"Oracle Solaris Version 11","product":{"name":"Oracle Solaris Version 11","product_id":"P-10006V-11"}}],"category":"product_name","name":"Oracle Solaris"}],"category":"product_family","name":"Oracle Systems"},{"branches":[{"branches":[{"category":"product_version_range","name":"Oracle TimesTen In-Memory Database Version Prior to 11.2.2.8.65","product":{"name":"Oracle TimesTen In-Memory Database Version Prior to 11.2.2.8.65","product_id":"P-1870V-Prior to 11.2.2.8.65"}}],"category":"product_name","name":"Oracle TimesTen In-Memory Database"}],"category":"product_family","name":"Oracle TimesTen In-Memory Database"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Utilities Framework Version 4.3.0.5.0","product":{"name":"Oracle Utilities Framework Version 4.3.0.5.0","product_id":"P-2245V-4.3.0.5.0"}},{"category":"product_version","name":"Oracle Utilities Framework Version 4.3.0.6.0","product":{"name":"Oracle Utilities Framework Version 4.3.0.6.0","product_id":"P-2245V-4.3.0.6.0"}},{"category":"product_version","name":"Oracle Utilities Framework Version 4.4.0.0.0","product":{"name":"Oracle Utilities Framework Version 4.4.0.0.0","product_id":"P-2245V-4.4.0.0.0"}},{"category":"product_version","name":"Oracle Utilities Framework Version 4.4.0.2.0","product":{"name":"Oracle Utilities Framework Version 4.4.0.2.0","product_id":"P-2245V-4.4.0.2.0"}},{"category":"product_version","name":"Oracle Utilities Framework Version 4.4.0.3.0","product":{"name":"Oracle Utilities Framework Version 4.4.0.3.0","product_id":"P-2245V-4.4.0.3.0"}},{"category":"product_version","name":"Oracle Utilities Framework Version 4.5.0.0.0","product":{"name":"Oracle Utilities Framework Version 4.5.0.0.0","product_id":"P-2245V-4.5.0.0.0"}}],"category":"product_name","name":"Oracle Utilities Framework"},{"branches":[{"category":"product_version","name":"Oracle Utilities Network Management System Version 2.3.0.2","product":{"name":"Oracle Utilities Network Management System Version 2.3.0.2","product_id":"P-2241V-2.3.0.2"}},{"category":"product_version","name":"Oracle Utilities Network Management System Version 2.4.0.1","product":{"name":"Oracle Utilities Network Management System Version 2.4.0.1","product_id":"P-2241V-2.4.0.1"}},{"category":"product_version","name":"Oracle Utilities Network Management System Version 2.5.0.0","product":{"name":"Oracle Utilities Network Management System Version 2.5.0.0","product_id":"P-2241V-2.5.0.0"}},{"category":"product_version_range","name":"Oracle Utilities Network Management System Version 2.5.0.0-2.5.0.2","product":{"name":"Oracle Utilities Network Management System Version 2.5.0.0-2.5.0.2","product_id":"P-2241V-2.5.0.0-2.5.0.2"}},{"category":"product_version","name":"Oracle Utilities Network Management System Version 2.5.0.1","product":{"name":"Oracle Utilities Network Management System Version 2.5.0.1","product_id":"P-2241V-2.5.0.1"}},{"category":"product_version","name":"Oracle Utilities Network Management System Version 2.5.0.2","product":{"name":"Oracle Utilities Network Management System Version 2.5.0.2","product_id":"P-2241V-2.5.0.2"}}],"category":"product_name","name":"Oracle Utilities Network Management System"}],"category":"product_family","name":"Oracle Utilities Applications"},{"branches":[{"branches":[{"category":"product_version_range","name":"Oracle VM VirtualBox Version Prior to 6.1.42","product":{"name":"Oracle VM VirtualBox Version Prior to 6.1.42","product_id":"P-8370V-Prior to 6.1.42"}},{"category":"product_version_range","name":"Oracle VM VirtualBox Version prior to 7.0.6","product":{"name":"Oracle VM VirtualBox Version prior to 7.0.6","product_id":"P-8370V-prior to 7.0.6"}}],"category":"product_name","name":"Oracle VM VirtualBox"}],"category":"product_family","name":"Oracle Virtualization"}],"category":"vendor","name":"Oracle"}]},"vulnerabilities":[{"cve":"CVE-2018-1273","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Studio (Spring Data Commons)).   The supported version that is affected is 22.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR Server (Spring Data Commons)).  Supported versions that are affected are 8.1.0.0-8.1.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Data Repository. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14121V-22.2.0","P-9161V-8.1.0.0-8.1.3.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9161V-8.1.0.0-8.1.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916773.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-14121V-22.2.0","P-9161V-8.1.0.0-8.1.3.1"]}]},{"cve":"CVE-2018-25032","notes":[{"category":"description","text":"Vulnerability in the Oracle Database (zlib) component of Oracle Database Server.  Supported versions that are affected are 19c and  21c. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise Oracle Database (zlib).  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Database (zlib). CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (zlib)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1042V-12.2.1.4.0","P-5(Oracle Database)V-21c","P-5(Oracle Database)V-19c"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5(Oracle Database)V-19c","P-5(Oracle Database)V-21c"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["P-5(Oracle Database)V-19c","P-5(Oracle Database)V-21c"]},{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-1042V-12.2.1.4.0"]}]},{"cve":"CVE-2018-7489","notes":[{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Third Party Jars (jackson-databind)).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0","P-5242V-14.1.1.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"]}]},{"cve":"CVE-2019-12402","notes":[{"category":"description","text":"Security-in-Depth issue in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide (Apache Commons Compress)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-2241V-2.5.0.0-2.5.0.2","P-2241V-2.4.0.1","P-2241V-2.3.0.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2241V-2.5.0.0-2.5.0.2","P-2241V-2.4.0.1","P-2241V-2.3.0.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915778.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-2241V-2.5.0.0-2.5.0.2","P-2241V-2.4.0.1","P-2241V-2.3.0.2"]}]},{"cve":"CVE-2019-12415","notes":[{"category":"description","text":"Vulnerability in the Oracle AutoVue product of Oracle Supply Chain (component: Installation (Apache POI)).  Supported versions that are affected are Prior to 21.0.2.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle AutoVue executes to compromise Oracle AutoVue.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle AutoVue accessible data.  Note: This vulnerability applies to Oracle AutoVue Office, Oracle AutoVue 2D Professional, Oracle AutoVue 3D Professional Advanced, Oracle AutoVue EDA Professional and Oracle AutoVue Electro-Mechanical Professional. Please refer to Patch Availability Document for more details. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4450V-Prior to 21.0.2.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4450V-Prior to 21.0.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915508.1"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-4450V-Prior to 21.0.2.0"]}]},{"cve":"CVE-2019-17571","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Message Bus (Apache Log4j)).  Supported versions that are affected are 5.5.0-5.5.9 and  6.0.0-6.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916530.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"]}]},{"cve":"CVE-2019-7317","notes":[{"category":"description","text":"Vulnerability in the Oracle AutoVue product of Oracle Supply Chain (component: Security (libpng)).  Supported versions that are affected are Prior to 21.0.2.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle AutoVue.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle AutoVue.  Note: This vulnerability applies to Oracle AutoVue Office, Oracle AutoVue 2D Professional, Oracle AutoVue 3D Professional Advanced, Oracle AutoVue EDA Professional and Oracle AutoVue Electro-Mechanical Professional. Please refer to Patch Availability Document for more details. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4450V-Prior to 21.0.2.6"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4450V-Prior to 21.0.2.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915508.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-4450V-Prior to 21.0.2.6"]}]},{"cve":"CVE-2020-10683","notes":[{"category":"description","text":"Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Content Acquisition System (dom4j)).  Supported versions that are affected are 2.3.0.2, 2.4.0.1, 2.5.0.0, 2.5.0.1 and  2.5.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Network Management System. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2241V-2.4.0.1","P-2241V-2.3.0.2","P-2241V-2.5.0.2","P-2241V-2.5.0.1","P-2241V-2.5.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2241V-2.4.0.1","P-2241V-2.3.0.2","P-2241V-2.5.0.2","P-2241V-2.5.0.1","P-2241V-2.5.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915778.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-2241V-2.4.0.1","P-2241V-2.3.0.2","P-2241V-2.5.0.2","P-2241V-2.5.0.1","P-2241V-2.5.0.0"]}]},{"cve":"CVE-2020-10693","notes":[{"category":"description","text":"Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party Patch (Hibernate Validator)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4647V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4647V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"products":["P-4647V-12.2.1.4.0"]}]},{"cve":"CVE-2020-10735","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (Python)).   The supported version that is affected is 22.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Database (Python) component of Oracle Database Server.   The supported version that is affected is 21c. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via multiple protocols to compromise Oracle Database (Python).  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Database (Python). CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client (Python)).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Shell.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Shell.  Note: CVE-2020-10735 is non-exploitable in MySQL Shell, because it is a flaw in Python that is distributed in the MySQL Shell and the affected module in Python is not a functional dependency in MySQL Shell. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Porting (Python)).  Supported versions that are affected are 8.58, 8.59 and  8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior","P-14121V-22.2.1","P-5085V-8.58","P-5085V-8.60","P-5(Oracle Database)V-21c","P-5085V-8.59"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.2.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5(Oracle Database)V-21c"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.58","P-5085V-8.59","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915481.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior","P-5085V-8.58","P-5085V-8.59","P-14121V-22.2.1","P-5085V-8.60"]},{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["P-5(Oracle Database)V-21c"]}]},{"cve":"CVE-2020-10878","notes":[{"category":"description","text":"Security-in-Depth issue in the Perl component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-9472V-Perl: Prior to 5.35"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9472V-Perl: Prior to 5.35"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-9472V-Perl: Prior to 5.35"]}]},{"cve":"CVE-2020-11979","notes":[{"category":"description","text":"Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Installation (Apache Ant)).  Supported versions that are affected are 2.3.0.2, 2.4.0.1, 2.5.0.0, 2.5.0.1 and  2.5.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2241V-2.4.0.1","P-2241V-2.3.0.2","P-2241V-2.5.0.2","P-2241V-2.5.0.1","P-2241V-2.5.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2241V-2.4.0.1","P-2241V-2.3.0.2","P-2241V-2.5.0.2","P-2241V-2.5.0.1","P-2241V-2.5.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915778.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-2241V-2.4.0.1","P-2241V-2.3.0.2","P-2241V-2.5.0.2","P-2241V-2.5.0.1","P-2241V-2.5.0.0"]}]},{"cve":"CVE-2020-11987","notes":[{"category":"description","text":"Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party Patch (Apache Batik)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data as well as  unauthorized update, insert or delete access to some of Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4647V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4647V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":8.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","version":"3.1"},"products":["P-4647V-12.2.1.4.0"]}]},{"cve":"CVE-2020-13920","notes":[{"category":"description","text":"Security-in-Depth issue in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: Stream Analytics  (Apache ActiveMQ)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-5370V-Prior to 19.1.0.0.8"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5370V-Prior to 19.1.0.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-5370V-Prior to 19.1.0.0.8"]}]},{"cve":"CVE-2020-13956","notes":[{"category":"description","text":"Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party Patch  (Apache HttpClient)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Stream Analytics product of Oracle GoldenGate (component: Stream Analytics  (Apache  HttpClient)).  Supported versions that are affected are Prior to 19.1.0.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Stream Analytics.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Stream Analytics accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4647V-12.2.1.4.0","P-5370V-Prior to 19.1.0.0.8"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4647V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5370V-Prior to 19.1.0.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"products":["P-4647V-12.2.1.4.0"]},{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"products":["P-5370V-Prior to 19.1.0.0.8"]}]},{"cve":"CVE-2020-16156","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Perl DBI)).  Supported versions that are affected are 5.5.0-5.5.9 and  6.0.0-6.0.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916530.1"}],"scores":[{"cvss_v3":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"]}]},{"cve":"CVE-2020-27844","notes":[{"category":"description","text":"Vulnerability in the Oracle AutoVue product of Oracle Supply Chain (component: Security (OpenJPEG)).  Supported versions that are affected are Prior to 21.0.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle AutoVue executes to compromise Oracle AutoVue.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle AutoVue.  Note: This vulnerability applies to Oracle AutoVue Office, Oracle AutoVue 2D Professional, Oracle AutoVue 3D Professional Advanced, Oracle AutoVue EDA Professional and Oracle AutoVue Electro-Mechanical Professional. Please refer to Patch Availability Document for more details. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4451V-Prior to 21.0.2.6"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4451V-Prior to 21.0.2.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915508.1"}],"scores":[{"cvss_v3":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-4451V-Prior to 21.0.2.6"]}]},{"cve":"CVE-2020-36242","notes":[{"category":"description","text":"Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client (cryptography)).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Shell.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Shell accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Shell.  Note: CVE-2020-36242 is non-exploitable in MySQL Shell, because it is a flaw in cryptography that is distributed in the MySQL Shell and the affected module in cryptography is not a functional dependency in MySQL Shell. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"cve":"CVE-2020-36518","notes":[{"category":"description","text":"Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (jackson-databind)).   The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: GoldenGate Stream Analytics (jackson-databind)).  Supported versions that are affected are Prior to 19.1.0.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of GoldenGate Stream Analytics. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14015V-Prior to 19.1.0.0.8","P-9633V-11.3.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9633V-11.3.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916255.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14015V-Prior to 19.1.0.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-9633V-11.3.2"]},{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14015V-Prior to 19.1.0.0.8"]}]},{"cve":"CVE-2021-21708","notes":[{"category":"description","text":"Security-in-Depth issue in the Oracle SD-WAN Aware product of Oracle Communications (component: Management (PHP)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-13941V-8.2.1.9.0","P-13941V-9.0.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13941V-8.2.1.9.0","P-13941V-9.0.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2920552.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13941V-8.2.1.9.0","P-13941V-9.0.1.4.0"]}]},{"cve":"CVE-2021-23358","notes":[{"category":"description","text":"Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: User Interface (UnderscoreJS)).  Supported versions that are affected are 18.8, 19.12, 20.12, 21.12 and  22.12. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera Unifier accessible data as well as  unauthorized read access to a subset of Primavera Unifier accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10354V-19.12","P-10354V-20.12","P-10354V-18.8","P-10354V-22.12","P-10354V-21.12"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10354V-18.8","P-10354V-19.12","P-10354V-20.12","P-10354V-22.12","P-10354V-21.12"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917469.1"}],"scores":[{"cvss_v3":{"baseScore":3.3,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-10354V-18.8","P-10354V-19.12","P-10354V-20.12","P-10354V-22.12","P-10354V-21.12"]}]},{"cve":"CVE-2021-2351","notes":[{"category":"description","text":"Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Reporting).   The supported version that is affected is 9.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Hospitality Reporting and Analytics.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Reporting and Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Reporting and Analytics. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-11599V-9.1.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11599V-9.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2913273.1"}],"scores":[{"cvss_v3":{"baseScore":8.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","version":"3.1"},"products":["P-11599V-9.1.0"]}]},{"cve":"CVE-2021-29425","notes":[{"category":"description","text":"Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide (Apache Commons IO)).  Supported versions that are affected are 2.3.0.2, 2.4.0.1 and  2.5.0.0-2.5.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Utilities Network Management System accessible data as well as  unauthorized read access to a subset of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2241V-2.5.0.0-2.5.0.2","P-2241V-2.4.0.1","P-2241V-2.3.0.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2241V-2.5.0.0-2.5.0.2","P-2241V-2.4.0.1","P-2241V-2.3.0.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915778.1"}],"scores":[{"cvss_v3":{"baseScore":4.8,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-2241V-2.5.0.0-2.5.0.2","P-2241V-2.4.0.1","P-2241V-2.3.0.2"]}]},{"cve":"CVE-2021-31805","notes":[{"category":"description","text":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration (Apache Struts)).   The supported version that is affected is 11.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4392V-11.2.10"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4392V-11.2.10"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2775466.2"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-4392V-11.2.10"]}]},{"cve":"CVE-2021-31812","notes":[{"category":"description","text":"Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites (Apache PDFBox)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebCenter Sites executes to compromise Oracle WebCenter Sites.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9617V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9617V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-9617V-12.2.1.4.0"]}]},{"cve":"CVE-2021-36090","notes":[{"category":"description","text":"Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party Patch (Apache Commons Compress)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4647V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4647V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-4647V-12.2.1.4.0"]}]},{"cve":"CVE-2021-36483","notes":[{"category":"description","text":"Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System product of Oracle Hospitality Applications (component: FMS Suite (DevExpress)).   The supported version that is affected is 20.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management System.  Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Cruise Shipboard Property Management System. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-11607V-20.2.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11607V-20.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917992.1"}],"scores":[{"cvss_v3":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-11607V-20.2.2"]}]},{"cve":"CVE-2021-36770","notes":[{"category":"description","text":"Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party Patch (Perl)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Middleware Common Libraries and Tools executes to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4647V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4647V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-4647V-12.2.1.4.0"]}]},{"cve":"CVE-2021-3737","notes":[{"category":"description","text":"Vulnerability in the Oracle Database - Machine Learning for Python (Python) component of Oracle Database Server.   The supported version that is affected is 21c. Easily exploitable vulnerability allows low privileged attacker having Database User privilege with network access via Oracle Net to compromise Oracle Database - Machine Learning for Python (Python).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Database - Machine Learning for Python (Python). CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5(Oracle Database - Machine Learning for Python)V-21c"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5(Oracle Database - Machine Learning for Python)V-21c"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-5(Oracle Database - Machine Learning for Python)V-21c"]}]},{"cve":"CVE-2021-37533","notes":[{"category":"description","text":"Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Diagnostic Assistant (Apache Commons Net)).   The supported version that is affected is 2.12.43. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise OSS Support Tools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all OSS Support Tools accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: RDA - Remote Diagnostic Agent (Apache Commons Net)).   The supported version that is affected is 22.4.22.10.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise OSS Support Tools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all OSS Support Tools accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Services Tools Bundle (Apache Commons Net)).   The supported version that is affected is 22.4.22.10.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise OSS Support Tools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all OSS Support Tools accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1330(Diagnostic Assistant)V-2.12.43","P-1330(Services Tools Bundle)V-22.4.22.10.18","P-1330(RDA - Remote Diagnostic Agent)V-22.4.22.10.18"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1330(Diagnostic Assistant)V-2.12.43","P-1330(Services Tools Bundle)V-22.4.22.10.18","P-1330(RDA - Remote Diagnostic Agent)V-22.4.22.10.18"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919775.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-1330(Diagnostic Assistant)V-2.12.43","P-1330(Services Tools Bundle)V-22.4.22.10.18","P-1330(RDA - Remote Diagnostic Agent)V-22.4.22.10.18"]}]},{"cve":"CVE-2021-37750","notes":[{"category":"description","text":"Security-in-Depth issue in the Oracle Database (MIT Kerberos KDC) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-5(Oracle Database)V-21c","P-5(Oracle Database)V-19c"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5(Oracle Database)V-19c","P-5(Oracle Database)V-21c"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-5(Oracle Database)V-19c","P-5(Oracle Database)V-21c"]}]},{"cve":"CVE-2021-3918","notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Chatbot Framework (JSON Schema)).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CC Common Application Objects. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search (JSON Schema)).  Supported versions that are affected are 8.58, 8.59 and  8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8911V-9.2","P-5085V-8.58","P-5085V-8.60","P-5085V-8.59"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8911V-9.2","P-5085V-8.58","P-5085V-8.59","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915481.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-8911V-9.2","P-5085V-8.58","P-5085V-8.59","P-5085V-8.60"]}]},{"cve":"CVE-2021-40528","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (Libgcrypt)).   The supported version that is affected is 22.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14121V-22.2.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"}],"scores":[{"cvss_v3":{"baseScore":5.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-14121V-22.2.0"]}]},{"cve":"CVE-2021-41184","notes":[{"category":"description","text":"Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Engagement (jQuery UI)).  Supported versions that are affected are 18.2.11 and  19.3.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Simphony, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hospitality Simphony accessible data as well as  unauthorized read access to a subset of Oracle Hospitality Simphony accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-11594V-19.3.4","P-11594V-18.2.11"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11594V-18.2.11","P-11594V-19.3.4"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2913296.1"}],"scores":[{"cvss_v3":{"baseScore":6.1,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-11594V-18.2.11","P-11594V-19.3.4"]}]},{"cve":"CVE-2021-41411","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Rulesets (XStream)).  Supported versions that are affected are 7.4.0, 7.4.1, 7.4.2 and  7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4516V-7.4.0","P-4516V-7.4.1","P-4516V-7.5.0","P-4516V-7.4.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4516V-7.4.0","P-4516V-7.4.1","P-4516V-7.5.0","P-4516V-7.4.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916531.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-4516V-7.4.0","P-4516V-7.4.1","P-4516V-7.5.0","P-4516V-7.4.2"]}]},{"cve":"CVE-2021-42717","notes":[{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (ModSecurity)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1042V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-1042V-12.2.1.4.0"]}]},{"cve":"CVE-2021-43797","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Elastic Charging Engine product of Oracle Communications Applications (component: Security (Netty)).  Supported versions that are affected are 12.0.0.3.0-12.0.0.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Elastic Charging Engine.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Elastic Charging Engine accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide (Netty)).  Supported versions that are affected are 2.5.0.1 and  2.5.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2241V-2.5.0.2","P-2241V-2.5.0.1","P-9742V-12.0.0.3.0-12.0.0.7.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9742V-12.0.0.3.0-12.0.0.7.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916540.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2241V-2.5.0.2","P-2241V-2.5.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915778.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-9742V-12.0.0.3.0-12.0.0.7.0","P-2241V-2.5.0.2","P-2241V-2.5.0.1"]}]},{"cve":"CVE-2021-44832","notes":[{"category":"description","text":"Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: Security (Apache Log4j)).  Supported versions that are affected are 12.2.7, 12.2.8, 12.2.9, 12.2.10, 12.2.11 and  12.2.12. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Demantra Demand Management.  Successful attacks of this vulnerability can result in takeover of Oracle Demantra Demand Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Hospitality Gift and Loyalty product of Oracle Food and Beverage Applications (component: Reporting (Apache Log4j)).   The supported version that is affected is 9.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Hospitality Gift and Loyalty.  Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Gift and Loyalty. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Hospitality Labor Management product of Oracle Food and Beverage Applications (component: Reporting (Apache Log4j)).   The supported version that is affected is 9.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Hospitality Labor Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Labor Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Reporting (Apache Log4j)).   The supported version that is affected is 9.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Hospitality Reporting and Analytics.  Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Reporting and Analytics. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing  (Apache Log4j)).  Supported versions that are affected are 22.10 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing.  Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-11599V-9.1.0","P-2100V-12.2.10","P-2100V-12.2.12","P-2100V-12.2.11","P-2100V-12.2.8","P-11601V-9.1.0","P-2100V-12.2.9","P-2100V-12.2.7","P-11600V-9.1.0","P-8974V-22.10 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2100V-12.2.10","P-2100V-12.2.12","P-2100V-12.2.11","P-2100V-12.2.8","P-2100V-12.2.9","P-2100V-12.2.7"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915508.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11599V-9.1.0","P-11601V-9.1.0","P-11600V-9.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2913273.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8974V-22.10 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915482.1"}],"scores":[{"cvss_v3":{"baseScore":6.6,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-11599V-9.1.0","P-2100V-12.2.10","P-2100V-12.2.12","P-2100V-12.2.11","P-2100V-12.2.8","P-11601V-9.1.0","P-2100V-12.2.9","P-2100V-12.2.7","P-11600V-9.1.0","P-8974V-22.10 and prior"]}]},{"cve":"CVE-2021-45105","notes":[{"category":"description","text":"Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide (Apache Log4j)).  Supported versions that are affected are 2.3.0.2, 2.4.0.1 and  2.5.0.0-2.5.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Network Management System. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2241V-2.5.0.0-2.5.0.2","P-2241V-2.4.0.1","P-2241V-2.3.0.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2241V-2.5.0.0-2.5.0.2","P-2241V-2.4.0.1","P-2241V-2.3.0.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915778.1"}],"scores":[{"cvss_v3":{"baseScore":5.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-2241V-2.5.0.0-2.5.0.2","P-2241V-2.4.0.1","P-2241V-2.3.0.2"]}]},{"cve":"CVE-2022-0084","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (xnio-api)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14250V-22.3.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14250V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919017.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14250V-22.3.0"]}]},{"cve":"CVE-2022-0492","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Platform (Kernel)).   The supported version that is affected is 8.6.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Diameter Signaling Router executes to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10899V-8.6.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-8.6.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919053.1"}],"scores":[{"cvss_v3":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-10899V-8.6.0.0"]}]},{"cve":"CVE-2022-0934","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Oracle Linux 8 (dnsmasq)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14125V-22.3.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14125V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919019.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14125V-22.3.0"]}]},{"cve":"CVE-2022-1122","notes":[{"category":"description","text":"Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: DC-Specific Component (OpenJPEG)).   The supported version that is affected is 8.5.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Spatial and Graph (OpenJPEG) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2276V-8.5.6"],"known_not_affected":["P-619V-21c","P-619V-19c"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2276V-8.5.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-619V-19c","P-619V-21c"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-2276V-8.5.6"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-619V-19c","P-619V-21c"]}]},{"cve":"CVE-2022-1304","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Oracle Linux (e2fsprogs)).  Supported versions that are affected are 22.3.1 and  22.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Exposure Function executes to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Installation and Configuration (e2fsprogs)).  Supported versions that are affected are 22.4.0 and  22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Security Edge Protection Proxy executes to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14122V-22.3.1","P-14122V-22.4.0","P-14123V-22.4.0","P-14123V-22.3.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14122V-22.3.1","P-14122V-22.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919018.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-22.4.0","P-14123V-22.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919045.1"}],"scores":[{"cvss_v3":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-14122V-22.3.1","P-14122V-22.4.0","P-14123V-22.4.0","P-14123V-22.3.1"]}]},{"cve":"CVE-2022-1319","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Installation (Undertow)).   The supported version that is affected is 22.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14118V-22.3.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14118V-22.3.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919001.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14118V-22.3.2"]}]},{"cve":"CVE-2022-1941","notes":[{"category":"description","text":"Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python (Python)).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8576V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8576V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8576V-8.0.31 and prior"]}]},{"cve":"CVE-2022-2048","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Signaling (Eclipse Jetty)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Eclipse Jetty)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Crime and Compliance Management Studio product of Oracle Financial Services Applications (component: Studio (Eclipse Jetty)).   The supported version that is affected is 8.0.8.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Crime and Compliance Management Studio.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Crime and Compliance Management Studio. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: GoldenGate Stream Analytics (Eclipse Jetty)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-13595V-8.0.8.3.1","P-14277V-22.3.0","P-14121V-22.3.0"],"known_not_affected":["P-14015V-Prior to 19.1.0.0.8"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919044.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13595V-8.0.8.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917625.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14015V-Prior to 19.1.0.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-13595V-8.0.8.3.1","P-14277V-22.3.0","P-14121V-22.3.0"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-14015V-Prior to 19.1.0.0.8"]}]},{"cve":"CVE-2022-2053","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Signaling (Undertow)).  Supported versions that are affected are 22.3.0-22.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (undertow-core)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Signaling (Undertow)).  Supported versions that are affected are 22.3.0 and  22.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14277V-22.4.0","P-14250V-22.3.0","P-14277V-22.3.0","P-14121V-22.3.0-22.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.3.0-22.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14250V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919017.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-22.4.0","P-14277V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919044.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14277V-22.4.0","P-14277V-22.3.0","P-14121V-22.3.0-22.4.0","P-14250V-22.3.0"]}]},{"cve":"CVE-2022-21597","notes":[{"category":"description","text":"Security-in-Depth issue in the GraalVM Multilingual Engine component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-5(GraalVM Multilingual Engine)V-21c"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5(GraalVM Multilingual Engine)V-21c"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-5(GraalVM Multilingual Engine)V-21c"]}]},{"cve":"CVE-2022-21824","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Policy (MySQL)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function as well as  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (MySQL)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy as well as  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14277V-22.3.0","P-14121V-22.3.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919044.1"}],"scores":[{"cvss_v3":{"baseScore":8.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"products":["P-14277V-22.3.0","P-14121V-22.3.0"]}]},{"cve":"CVE-2022-2274","notes":[{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (OpenSSL)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in Oracle Essbase (component: Essbase Web Platform (OpenSSL)).   The supported version that is affected is 21.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Essbase.  Successful attacks of this vulnerability can result in takeover of Oracle Essbase. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: Siebel Core - Server Infrastructure (OpenSSL)).  Supported versions that are affected are 22.10 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM.  Successful attacks of this vulnerability can result in takeover of Siebel CRM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4379V-21.4","P-1042V-12.2.1.4.0","P-9001V-22.10 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4379V-21.4"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9001V-22.10 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915482.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-4379V-21.4","P-1042V-12.2.1.4.0","P-9001V-22.10 and prior"]}]},{"cve":"CVE-2022-22950","notes":[{"category":"description","text":"Security-in-Depth issue in the Management Pack for Oracle GoldenGate product of Oracle GoldenGate (component: Monitor (Spring Framework)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-5759V-Prior to 12.2.1.2.221115"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5759V-Prior to 12.2.1.2.221115"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-5759V-Prior to 12.2.1.2.221115"]}]},{"cve":"CVE-2022-22965","notes":[{"category":"description","text":"Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Spring Framework)).   The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9633V-11.3.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9633V-11.3.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916255.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-9633V-11.3.2"]}]},{"cve":"CVE-2022-22970","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Signaling (Spring Framework)).   The supported version that is affected is 1.11.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14277V-1.11.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-1.11.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919044.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14277V-1.11.0"]}]},{"cve":"CVE-2022-22971","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Elastic Charging Engine product of Oracle Communications Applications (component: Security (Spring Framework)).  Supported versions that are affected are 12.0.0.3.0-12.0.0.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Communications Elastic Charging Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Elastic Charging Engine. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (Spring Framework)).  Supported versions that are affected are 22.3.2 and  22.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Intelligence Hub product of Oracle Communications (component: Mediation (Spring Framework)).   The supported version that is affected is 8.2.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Diameter Intelligence Hub.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Intelligence Hub. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: TMF APIs (Spring Framework)).  Supported versions that are affected are 7.4.0, 7.4.1 and  7.4.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the GoldenGate Veridata product of Oracle GoldenGate (component: GoldenGate Veridata (Spring Framework)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR Server (Spring Framework)).  Supported versions that are affected are 8.1.0.0-8.1.3.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Healthcare Data Repository.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Healthcare Data Repository. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Healthcare Translational Research product of Oracle HealthCare Applications (component: Data Studio (Spring Framework)).  Supported versions that are affected are 4.1.0.0-4.1.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Healthcare Translational Research.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Healthcare Translational Research. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (Spring Framework)).  Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Enterprise Monitor. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9427V-4.1.0.0-4.1.1.1","P-14121V-22.3.2","P-9742V-12.0.0.3.0-12.0.0.7.0","P-8480V-8.0.32 and prior","P-14121V-22.2.0","P-11126V-8.2.3.0","P-9161V-8.1.0.0-8.1.3.1","P-4516V-7.4.0","P-4516V-7.4.1","P-4516V-7.4.2"],"known_not_affected":["P-5758V-Prior to 12.2.1.4.220831"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9742V-12.0.0.3.0-12.0.0.7.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916540.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.3.2","P-14121V-22.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11126V-8.2.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919022.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4516V-7.4.0","P-4516V-7.4.1","P-4516V-7.4.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916531.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5758V-Prior to 12.2.1.4.220831"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9427V-4.1.0.0-4.1.1.1","P-9161V-8.1.0.0-8.1.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916773.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8480V-8.0.32 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-9427V-4.1.0.0-4.1.1.1","P-14121V-22.3.2","P-9742V-12.0.0.3.0-12.0.0.7.0","P-8480V-8.0.32 and prior","P-14121V-22.2.0","P-11126V-8.2.3.0","P-9161V-8.1.0.0-8.1.3.1","P-4516V-7.4.0","P-4516V-7.4.1","P-4516V-7.4.2"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-5758V-Prior to 12.2.1.4.220831"]}]},{"cve":"CVE-2022-22978","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Message Bus (Spring Security)).  Supported versions that are affected are 5.5.0-5.5.9 and  6.0.0-6.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916530.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"]}]},{"cve":"CVE-2022-23219","notes":[{"category":"description","text":"Vulnerability in the Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers product of Oracle Systems (component: XCP Firmware (glibc)).  Supported versions that are affected are Prior to XCP2411, prior to XCP3111 and  prior to XCP4011. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers.  Successful attacks of this vulnerability can result in takeover of Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10656V-prior to XCP4011","P-10656V-Prior to XCP2411","P-10656V-prior to XCP3111"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10656V-prior to XCP4011","P-10656V-Prior to XCP2411","P-10656V-prior to XCP3111"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2920776.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-10656V-prior to XCP4011","P-10656V-Prior to XCP2411","P-10656V-prior to XCP3111"]}]},{"cve":"CVE-2022-23221","notes":[{"category":"description","text":"Vulnerability in the Oracle Healthcare Translational Research product of Oracle HealthCare Applications (component: Data Studio (H2 Database)).  Supported versions that are affected are 4.1.0.0-4.1.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Translational Research.  Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Translational Research. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9427V-4.1.0.0-4.1.1.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9427V-4.1.0.0-4.1.1.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916773.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-9427V-4.1.0.0-4.1.1.1"]}]},{"cve":"CVE-2022-23305","notes":[{"category":"description","text":"Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core (Apache Log4j)).   The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2545V-14.1.1.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2545V-14.1.1.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-2545V-14.1.1.0.0"]}]},{"cve":"CVE-2022-23437","notes":[{"category":"description","text":"Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Development Tools (Apache Xerces-J)).  Supported versions that are affected are 12.4.0-12.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Documaker. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5477V-12.4.0-12.7.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5477V-12.4.0-12.7.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2918819.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-5477V-12.4.0-12.7.0"]}]},{"cve":"CVE-2022-23457","notes":[{"category":"description","text":"Vulnerability in the Oracle Health Sciences Empirica Signal product of Oracle Health Sciences Applications (component: Core (Enterprise Security API)).  Supported versions that are affected are 9.1.0.52 and  9.2.0.52. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences Empirica Signal.  Successful attacks of this vulnerability can result in takeover of Oracle Health Sciences Empirica Signal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party Patch  (Enterprise Security API)).   The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in takeover of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9646V-9.1.0.52","P-4647V-12.2.1.4.0","P-9646V-9.2.0.52"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9646V-9.1.0.52","P-9646V-9.2.0.52"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916626.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4647V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-9646V-9.1.0.52","P-9646V-9.2.0.52"]},{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-4647V-12.2.1.4.0"]}]},{"cve":"CVE-2022-24329","notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Analytics.  Supported versions that are affected are 5.9.0.0.0 and  6.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-6.4.0.0.0","P-2025V-5.9.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-5.9.0.0.0","P-2025V-6.4.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917214.2"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"products":["P-2025V-5.9.0.0.0","P-2025V-6.4.0.0.0"]}]},{"cve":"CVE-2022-24407","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (Cyrus SASL)).   The supported version that is affected is 22.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++ (Cyrus SASL)).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC (Cyrus SASL)).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8576(Connector/C++)V-8.0.31 and prior","P-14121V-22.2.1","P-8576(Connector/ODBC)V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.2.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8576(Connector/C++)V-8.0.31 and prior","P-8576(Connector/ODBC)V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-8576(Connector/C++)V-8.0.31 and prior","P-14121V-22.2.1","P-8576(Connector/ODBC)V-8.0.31 and prior"]}]},{"cve":"CVE-2022-24823","notes":[{"category":"description","text":"Vulnerability in the Oracle Banking Enterprise Default Management product of Oracle Financial Services Applications (component: Collections (Netty)).   The supported version that is affected is 2.7.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Banking Enterprise Default Management executes to compromise Oracle Banking Enterprise Default Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Banking Enterprise Default Management accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Banking Party Management product of Oracle Financial Services Applications (component: Web UI (Netty)).   The supported version that is affected is 2.7.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Banking Party Management executes to compromise Oracle Banking Party Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Banking Party Management accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (Netty)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Binding Support Function executes to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14121V-22.3.0","P-13390V-2.7.0","P-13929V-2.7.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13390V-2.7.0","P-13929V-2.7.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917336.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-14121V-22.3.0","P-13390V-2.7.0","P-13929V-2.7.0"]}]},{"cve":"CVE-2022-24839","notes":[{"category":"description","text":"Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security (NekoHTML)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4461V-9.3.6"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4461V-9.3.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915508.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-4461V-9.3.6"]}]},{"cve":"CVE-2022-24903","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Platform (Multiple)).   The supported version that is affected is 8.6.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SYSLOG to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10899V-8.6.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-8.6.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919053.1"}],"scores":[{"cvss_v3":{"baseScore":8.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-10899V-8.6.0.0"]}]},{"cve":"CVE-2022-2509","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Policy (Oracle Linux)).  Supported versions that are affected are 22.2.0, 22.2.2 and  22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14121V-22.2.0","P-14121V-22.2.2","P-14121V-22.3.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.2.0","P-14121V-22.2.2","P-14121V-22.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14121V-22.2.0","P-14121V-22.2.2","P-14121V-22.3.1"]}]},{"cve":"CVE-2022-25236","notes":[{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Expat)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1042V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-1042V-12.2.1.4.0"]}]},{"cve":"CVE-2022-2526","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: ATS Framework (systemd-libs)).  Supported versions that are affected are 22.2.2, 22.3.1 and  22.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14488V-22.2.2","P-14488V-22.3.1","P-14488V-22.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14488V-22.2.2","P-14488V-22.3.1","P-14488V-22.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919015.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-14488V-22.2.2","P-14488V-22.3.1","P-14488V-22.4.0"]}]},{"cve":"CVE-2022-25315","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (LibExpat)).   The supported version that is affected is 22.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14121V-22.2.4"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.2.4"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-14121V-22.2.4"]}]},{"cve":"CVE-2022-25647","notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Analytics.  Supported versions that are affected are 5.9.0.0.0 and  6.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: ATS Framework (Google Gson)).  Supported versions that are affected are 22.2.2, 22.3.1 and  22.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (Google Gson)).   The supported version that is affected is 22.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Performance Intelligence Center (PIC) Software product of Oracle Communications (component: Management (Google Gson)).   The supported version that is affected is 10.4.0.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Performance Intelligence Center (PIC) Software.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Performance Intelligence Center (PIC) Software. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: REST API (Google Gson)).  Supported versions that are affected are 7.4.0, 7.4.1, 7.4.2 and  7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Config Console (Google Gson)).  Supported versions that are affected are 13.4.0.0 and  13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the GoldenGate Stream Analytics product of Oracle GoldenGate (component: GoldenGate Stream Analytics (Google Gson)).  Supported versions that are affected are Prior to 19.1.0.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of GoldenGate Stream Analytics. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples (Google GSON)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-11044V-10.4.0.4.1","P-14015V-Prior to 19.1.0.0.8","P-1370V-13.4.0.0","P-14488V-22.2.2","P-14488V-22.3.1","P-14488V-22.4.0","P-4516V-7.4.0","P-2025V-6.4.0.0.0","P-4516V-7.4.1","P-4516V-7.5.0","P-4516V-7.4.2","P-2025V-5.9.0.0.0","P-5242V-14.1.1.0.0","P-1370V-13.5.0.0","P-14121V-22.2.0","P-5242V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-5.9.0.0.0","P-2025V-6.4.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917214.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14488V-22.2.2","P-14488V-22.3.1","P-14488V-22.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919015.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11044V-10.4.0.4.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2920603.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4516V-7.4.0","P-4516V-7.4.1","P-4516V-7.5.0","P-4516V-7.4.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916531.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1370V-13.4.0.0","P-1370V-13.5.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906900.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14015V-Prior to 19.1.0.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-11044V-10.4.0.4.1","P-1370V-13.4.0.0","P-14488V-22.2.2","P-14488V-22.3.1","P-14488V-22.4.0","P-4516V-7.4.0","P-2025V-6.4.0.0.0","P-4516V-7.4.1","P-4516V-7.5.0","P-4516V-7.4.2","P-2025V-5.9.0.0.0","P-5242V-14.1.1.0.0","P-1370V-13.5.0.0","P-14121V-22.2.0","P-5242V-12.2.1.4.0"]},{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14015V-Prior to 19.1.0.0.8"]}]},{"cve":"CVE-2022-25857","notes":[{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: EAI Manager (SnakeYAML)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: REST Services Manager (SnakeYaml)).  Supported versions that are affected are 12.0.0.4.0-12.0.0.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Signaling (SnakeYAML)).   The supported version that is affected is 22.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cloud Manager (SnakeYAML)).  Supported versions that are affected are 8.58, 8.59 and  8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2136(REST Services Manager)V-12.0.0.4.0-12.0.0.7.0","P-14121V-22.2.2","P-5085V-8.58","P-5085V-8.60","P-5085V-8.59"],"known_not_affected":["P-2136(EAI Manager)V-12.0.0.4.0-12.0.0.7.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2136(EAI Manager)V-12.0.0.4.0-12.0.0.7.0","P-2136(REST Services Manager)V-12.0.0.4.0-12.0.0.7.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916540.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.58","P-5085V-8.59","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915481.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-2136(EAI Manager)V-12.0.0.4.0-12.0.0.7.0"]},{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-5085V-8.58","P-5085V-8.59","P-2136(REST Services Manager)V-12.0.0.4.0-12.0.0.7.0","P-14121V-22.2.2","P-5085V-8.60"]}]},{"cve":"CVE-2022-26336","notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC (Apache POI)).  Supported versions that are affected are Prior to 9.2.7.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.7.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.7.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915506.1"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-4781V-Prior to 9.2.7.2"]}]},{"cve":"CVE-2022-27404","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (FreeType)).   The supported version that is affected is 22.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Oracle Linux 8 (FreeType)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: DC-Specific Component (FreeType)).   The supported version that is affected is 8.5.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14121V-22.2.1","P-2276V-8.5.6","P-14125V-22.3.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.2.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14125V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919019.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2276V-8.5.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-14125V-22.3.0","P-14121V-22.2.1","P-2276V-8.5.6"]}]},{"cve":"CVE-2022-27782","notes":[{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (cURL)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: File Processing (cURL)).  Supported versions that are affected are 8.58, 8.59 and  8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1042V-12.2.1.4.0","P-5085V-8.58","P-5085V-8.60","P-5085V-8.59"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.58","P-5085V-8.59","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915481.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-5085V-8.58","P-5085V-8.59","P-1042V-12.2.1.4.0","P-5085V-8.60"]}]},{"cve":"CVE-2022-29824","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (libxml2)).   The supported version that is affected is 22.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (libxml2)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14121V-22.2.0","P-1042V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14121V-22.2.0","P-1042V-12.2.1.4.0"]}]},{"cve":"CVE-2022-30126","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications Applications (component: ISC (Apache Tika)).   The supported version that is affected is 8.1.0.20.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Messaging Server executes to compromise Oracle Communications Messaging Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Messaging Server. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8496V-8.1.0.20.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8496V-8.1.0.20.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916529.1"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8496V-8.1.0.20.0"]}]},{"cve":"CVE-2022-3028","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Virtual Network Function Manager (Kernel)).   The supported version that is affected is 8.6.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Diameter Signaling Router executes to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10899V-8.6.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-8.6.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919053.1"}],"scores":[{"cvss_v3":{"baseScore":7.0,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-10899V-8.6.0.0"]}]},{"cve":"CVE-2022-30293","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Signaling (WebKitGTK)).  Supported versions that are affected are 22.3.3 and  22.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14119V-22.3.3","P-14119V-22.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14119V-22.3.3","P-14119V-22.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919035.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-14119V-22.3.3","P-14119V-22.4.0"]}]},{"cve":"CVE-2022-31129","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (Moment.js)).  Supported versions that are affected are 22.1.0 and  22.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle Graph Server and Client (component: PGX Java Client (Moment.js)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle Essbase (component: Essbase Web Platform (Moment)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search (Moment.js)).  Supported versions that are affected are 8.58, 8.59 and  8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14121V-22.2.0","P-14121V-22.1.0","P-5085V-8.58","P-5085V-8.60","P-5085V-8.59"],"known_not_affected":["P-4379V-21.4","P-14069V-Prior to 22.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.2.0","P-14121V-22.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4379V-21.4","P-14069V-Prior to 22.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.58","P-5085V-8.59","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915481.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-5085V-8.58","P-5085V-8.59","P-14121V-22.2.0","P-14121V-22.1.0","P-5085V-8.60"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-4379V-21.4","P-14069V-Prior to 22.4.0"]}]},{"cve":"CVE-2022-31629","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Platform (PHP)).   The supported version that is affected is 8.6.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Diameter Signaling Router accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10899V-8.6.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-8.6.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919053.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-10899V-8.6.0.0"]}]},{"cve":"CVE-2022-31692","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (Spring Security)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Spring Security)).   The supported version that is affected is 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Installation (Spring Security crypto)).   The supported version that is affected is 22.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Spring Security)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Spring Security)).   The supported version that is affected is 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: REST API (Spring Security)).  Supported versions that are affected are 7.4.0, 7.4.1 and  7.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (Spring Security)).  Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor.  Successful attacks of this vulnerability can result in takeover of MySQL Enterprise Monitor. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14118V-22.3.2","P-14277V-22.3.0","P-8480V-8.0.32 and prior","P-14122V-22.3.1","P-4516V-7.4.0","P-14250V-22.3.0","P-4516V-7.4.1","P-4516V-7.4.2","P-14123V-22.3.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14250V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919017.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14122V-22.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919018.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14118V-22.3.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919001.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919044.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-22.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919045.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4516V-7.4.0","P-4516V-7.4.1","P-4516V-7.4.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916531.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8480V-8.0.32 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-14118V-22.3.2","P-14277V-22.3.0","P-8480V-8.0.32 and prior","P-14122V-22.3.1","P-4516V-7.4.0","P-14250V-22.3.0","P-4516V-7.4.1","P-4516V-7.4.2","P-14123V-22.3.1"]}]},{"cve":"CVE-2022-3171","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Policy (Google Protobuf-Java)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (Google Protobuf-Java)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Google Protobuf-Java)).   The supported version that is affected is 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Installation (Google Protobuf-Java)).   The supported version that is affected is 22.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Platform (Google Protobuf-Java)).   The supported version that is affected is 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Signaling (Google Protobuf-Java)).   The supported version that is affected is 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Signaling (Google Protobuf-Java)).  Supported versions that are affected are 22.2.2 and  22.3.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Policy (Google Protobuf-Java)).  Supported versions that are affected are 7.4.0-7.4.2 and  7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Crime and Compliance Management Studio product of Oracle Financial Services Applications (component: Studio (Google Protobuf-Java)).   The supported version that is affected is 8.0.8.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Crime and Compliance Management Studio.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Crime and Compliance Management Studio. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Fusion Middleware MapViewer product of Oracle Fusion Middleware (component: Install (Google Protobuf-Java)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Fusion Middleware MapViewer.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Fusion Middleware MapViewer. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle Graph Server and Client (component: Packaging/install (Google Protobuf-Java)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net (Google Protobuf-Java)).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Google Protobuf-Java)).  Supported versions that are affected are 18.8.0-18.8.15, 19.12.0-19.12.15, 20.12.0-20.12.10 and  21.12.0-21.12.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Primavera Gateway. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle Spatial Studio (component: Oracle Spatial Studio (Google Protobuf-Java)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Spatial and Graph Mapviewer (Google Protobuf-Java) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10605V-19.12.0-19.12.15","P-10605V-18.8.0-18.8.15","P-1215V-12.2.1.4.0","P-10605V-21.12.0-21.12.8","P-14122V-22.3.1","P-10605V-20.12.0-20.12.10","P-4516V-7.5.0","P-14123V-22.3.1","P-13595V-8.0.8.3.1","P-14118V-22.3.2","P-14119V-22.3.3","P-14130V-22.3.1","P-14119V-22.2.2","P-4516V-7.4.0-7.4.2","P-14250V-22.3.0","P-14121V-22.3.0","P-8576V-8.0.31 and prior"],"known_not_affected":["P-14069V-Prior to 23.1.0","P-619V-19c","P-619V-21c","P-13600V-Prior to 22.3.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14250V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919017.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14122V-22.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919018.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14118V-22.3.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919001.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14130V-22.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919002.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-22.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919045.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14119V-22.3.3","P-14119V-22.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919035.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4516V-7.4.0-7.4.2","P-4516V-7.5.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916531.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13595V-8.0.8.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917625.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1215V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14069V-Prior to 23.1.0","P-619V-19c","P-13600V-Prior to 22.3.0","P-619V-21c"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8576V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10605V-19.12.0-19.12.15","P-10605V-18.8.0-18.8.15","P-10605V-21.12.0-21.12.8","P-10605V-20.12.0-20.12.10"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917469.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-10605V-19.12.0-19.12.15","P-10605V-18.8.0-18.8.15","P-1215V-12.2.1.4.0","P-10605V-21.12.0-21.12.8","P-14122V-22.3.1","P-10605V-20.12.0-20.12.10","P-4516V-7.5.0","P-14123V-22.3.1","P-13595V-8.0.8.3.1","P-14118V-22.3.2","P-14119V-22.3.3","P-14130V-22.3.1","P-14119V-22.2.2","P-4516V-7.4.0-7.4.2","P-14250V-22.3.0","P-14121V-22.3.0","P-8576V-8.0.31 and prior"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-14069V-Prior to 23.1.0","P-619V-19c","P-13600V-Prior to 22.3.0","P-619V-21c"]}]},{"cve":"CVE-2022-31813","notes":[{"category":"description","text":"Vulnerability in the Enterprise Manager Ops Center product of Oracle Enterprise Manager (component: Update Provisioning (Apache HTTP Server)).   The supported version that is affected is 12.4.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Enterprise Manager Ops Center executes to compromise Enterprise Manager Ops Center.  Successful attacks of this vulnerability can result in takeover of Enterprise Manager Ops Center. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (Apache HTTP Server)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9835V-12.4.0.0","P-1042V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9835V-12.4.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906900.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":6.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-9835V-12.4.0.0"]},{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-1042V-12.2.1.4.0"]}]},{"cve":"CVE-2022-32212","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: User Interface (Node.js)).  Supported versions that are affected are 5.5.0-5.5.9 and  6.0.0-6.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916530.1"}],"scores":[{"cvss_v3":{"baseScore":8.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"]}]},{"cve":"CVE-2022-32221","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging (cURL)).  Supported versions that are affected are 5.7.40 and prior and  8.0.31 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-5.7.40 and prior","P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-5.7.40 and prior","P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-8478V-5.7.40 and prior","P-8478V-8.0.31 and prior"]}]},{"cve":"CVE-2022-33980","notes":[{"category":"description","text":"Vulnerability in the Oracle Banking Enterprise Default Management product of Oracle Financial Services Applications (component: Collections (Apache Commons Configuration)).   The supported version that is affected is 2.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Enterprise Default Management.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Enterprise Default Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Banking Party Management product of Oracle Financial Services Applications (component: Web UI (Apache Commons Configuration)).   The supported version that is affected is 2.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Party Management.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Party Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Elastic Charging Engine product of Oracle Communications Applications (component: Cloud native deployment (Apache Commons Configuration)).  Supported versions that are affected are 12.0.0.5.0-12.0.0.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Elastic Charging Engine. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Crime and Compliance Management Studio product of Oracle Financial Services Applications (component: Studio (Apache Commons Configuration)).   The supported version that is affected is 8.0.8.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Crime and Compliance Management Studio.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Crime and Compliance Management Studio. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle Graph Server and Client (component: Oracle Graph Server (Apache Commons Configuration)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-13595V-8.0.8.3.1","P-13390V-2.7.0","P-9742V-12.0.0.5.0-12.0.0.7.0","P-13929V-2.7.0"],"known_not_affected":["P-14069V-Prior to 22.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13390V-2.7.0","P-13929V-2.7.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917336.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9742V-12.0.0.5.0-12.0.0.7.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916540.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13595V-8.0.8.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917625.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14069V-Prior to 22.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-13595V-8.0.8.3.1","P-13390V-2.7.0","P-9742V-12.0.0.5.0-12.0.0.7.0","P-13929V-2.7.0"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-14069V-Prior to 22.4.0"]}]},{"cve":"CVE-2022-34169","notes":[{"category":"description","text":"Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server (Apache Xalan-J)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4461V-9.3.6"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4461V-9.3.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915508.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-4461V-9.3.6"]}]},{"cve":"CVE-2022-34305","notes":[{"category":"description","text":"Vulnerability in the Management Cloud Engine product of Oracle Communications (component: Backend Server (Apache Tomcat)).   The supported version that is affected is 22.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Management Cloud Engine.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Management Cloud Engine, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Management Cloud Engine accessible data as well as  unauthorized read access to a subset of Management Cloud Engine accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14252V-22.1.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14252V-22.1.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919078.1"}],"scores":[{"cvss_v3":{"baseScore":6.1,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-14252V-22.1.0.0.0"]}]},{"cve":"CVE-2022-34917","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Elastic Charging Engine product of Oracle Communications Applications (component: Security (Apache Kafka)).  Supported versions that are affected are 12.0.0.5.0-12.0.0.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Elastic Charging Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Elastic Charging Engine. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Event Streams and Communications (Apache Kafka)).  Supported versions that are affected are 18.8, 19.12, 20.12, 21.12 and  22.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Primavera Unifier. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10354V-18.8","P-10354V-19.12","P-10354V-20.12","P-9742V-12.0.0.5.0-12.0.0.7.0","P-10354V-22.12","P-10354V-21.12"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9742V-12.0.0.5.0-12.0.0.7.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916540.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10354V-18.8","P-10354V-19.12","P-10354V-20.12","P-10354V-22.12","P-10354V-21.12"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917469.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-10354V-18.8","P-10354V-19.12","P-10354V-20.12","P-9742V-12.0.0.5.0-12.0.0.7.0","P-10354V-22.12","P-10354V-21.12"]}]},{"cve":"CVE-2022-3510","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Google Protobuf-Java)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14277V-22.3.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919044.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14277V-22.3.0"]}]},{"cve":"CVE-2022-35737","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications Applications (component: IMAP (NSS)).   The supported version that is affected is 8.1.0.20.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Messaging Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8496V-8.1.0.20.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8496V-8.1.0.20.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916529.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8496V-8.1.0.20.0"]}]},{"cve":"CVE-2022-36033","notes":[{"category":"description","text":"Vulnerability in the Oracle Financial Services Crime and Compliance Management Studio product of Oracle Financial Services Applications (component: Studio (jsoup)).   The supported version that is affected is 8.0.8.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Crime and Compliance Management Studio.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Crime and Compliance Management Studio, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Crime and Compliance Management Studio accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Crime and Compliance Management Studio accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-13595V-8.0.8.3.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13595V-8.0.8.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917625.1"}],"scores":[{"cvss_v3":{"baseScore":6.1,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-13595V-8.0.8.3.1"]}]},{"cve":"CVE-2022-36055","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Helm)).  Supported versions that are affected are 5.5.0-5.5.9 and  6.0.0-6.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916530.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"]}]},{"cve":"CVE-2022-37434","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (zlib)).   The supported version that is affected is 22.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (zlib)).   The supported version that is affected is 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Platform (zlib)).   The supported version that is affected is 8.6.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the MySQL Workbench product of Oracle MySQL (component: Workbench (zlib)).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in takeover of MySQL Workbench. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: DC-Specific Component (zlib)).   The supported version that is affected is 8.5.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleSoft CDA (zlib)).  Supported versions that are affected are 8.58, 8.59 and  8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in Oracle TimesTen In-Memory Database (component: In-Memory Database (zlib)).  Supported versions that are affected are Prior to 11.2.2.8.65. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle TimesTen In-Memory Database. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core (zlib)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4627V-8.0.31 and prior","P-1870V-Prior to 11.2.2.8.65","P-5085V-8.58","P-5085V-8.59","P-14121V-22.1.1","P-10899V-8.6.0.0","P-2276V-8.5.6","P-14123V-22.3.1","P-5085V-8.60"],"known_not_affected":["P-8370V-prior to 7.0.6","P-8370V-Prior to 6.1.42"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.1.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-22.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919045.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-8.6.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919053.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4627V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2276V-8.5.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.58","P-5085V-8.59","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915481.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1870V-Prior to 11.2.2.8.65"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8370V-Prior to 6.1.42","P-8370V-prior to 7.0.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919776.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-4627V-8.0.31 and prior","P-5085V-8.58","P-5085V-8.59","P-14121V-22.1.1","P-10899V-8.6.0.0","P-2276V-8.5.6","P-14123V-22.3.1","P-5085V-8.60"]},{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-1870V-Prior to 11.2.2.8.65"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-8370V-Prior to 6.1.42","P-8370V-prior to 7.0.6"]}]},{"cve":"CVE-2022-37454","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: User Interface (PHP)).  Supported versions that are affected are 5.5.0-5.5.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14597V-5.5.0-5.5.9"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-5.5.0-5.5.9"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916530.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-14597V-5.5.0-5.5.9"]}]},{"cve":"CVE-2022-38752","notes":[{"category":"description","text":"Vulnerability in the Oracle Banking Enterprise Default Management product of Oracle Financial Services Applications (component: Collections (SnakeYAML)).   The supported version that is affected is 2.6.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Enterprise Default Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Enterprise Default Management. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Banking Party Management product of Oracle Financial Services Applications (component: Web UI (SnakeYAML)).   The supported version that is affected is 2.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Party Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Party Management. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Big Data Spatial and Graph product of Oracle Big Data Graph (component: Big Data Graph (SnakeYAML)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: ATS Framework (SnakeYAML)).  Supported versions that are affected are 22.2.2, 22.3.1 and  22.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Installation (SnakeYAML)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Signaling (SnakeYAML)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Signaling (SnakeYAML)).  Supported versions that are affected are 22.3.4 and  22.2.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Virtual Network Function Manager (SnakeYAML)).   The supported version that is affected is 8.6.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Signaling (SnakeYAML)).   The supported version that is affected is 7.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle Graph Server and Client (component: Packaging/install (SnakeYAML)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14277V-22.3.0","P-14119V-22.3.4","P-14119V-22.2.3","P-14488V-22.2.2","P-14488V-22.3.1","P-14488V-22.4.0","P-13390V-2.6.2","P-4516V-7.5.0","P-10899V-8.6.0.0","P-14118V-22.3.0","P-13929V-2.7.0"],"known_not_affected":["P-11528V-Prior to 21.4.3","P-14069V-Prior to 21.4.3"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13390V-2.6.2","P-13929V-2.7.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917336.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14069V-Prior to 21.4.3","P-11528V-Prior to 21.4.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14488V-22.2.2","P-14488V-22.3.1","P-14488V-22.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919015.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14118V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919001.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919044.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14119V-22.3.4","P-14119V-22.2.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919035.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-8.6.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919053.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4516V-7.5.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916531.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14277V-22.3.0","P-14119V-22.3.4","P-14119V-22.2.3","P-14488V-22.2.2","P-14488V-22.3.1","P-14488V-22.4.0","P-13390V-2.6.2","P-4516V-7.5.0","P-10899V-8.6.0.0","P-14118V-22.3.0","P-13929V-2.7.0"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-14069V-Prior to 21.4.3","P-11528V-Prior to 21.4.3"]}]},{"cve":"CVE-2022-39271","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Cloud Native (Traefik)).   The supported version that is affected is 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4516V-7.5.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4516V-7.5.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916531.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-4516V-7.5.0"]}]},{"cve":"CVE-2022-39429","notes":[{"category":"description","text":"Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19c and  21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java VM. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5(Java VM)V-19c","P-5(Java VM)V-21c"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5(Java VM)V-19c","P-5(Java VM)V-21c"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"}],"scores":[{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["P-5(Java VM)V-19c","P-5(Java VM)V-21c"]}]},{"cve":"CVE-2022-40146","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications MetaSolv Solution product of Oracle Communications Applications (component: Utilities (Apache Batik)).   The supported version that is affected is 6.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications MetaSolv Solution.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications MetaSolv Solution accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Fusion Middleware MapViewer product of Oracle Fusion Middleware (component: Install (Apache Batik)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Fusion Middleware MapViewer.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Fusion Middleware MapViewer accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2267V-6.3.1","P-1215V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2267V-6.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916548.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1215V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-2267V-6.3.1","P-1215V-12.2.1.4.0"]}]},{"cve":"CVE-2022-40149","notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security (Jettison)).   The supported version that is affected is 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.58"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.58"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915481.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-5085V-8.58"]}]},{"cve":"CVE-2022-40150","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Webservices Manager (Jettison)).  Supported versions that are affected are 12.0.0.4.0-12.0.0.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Third Party Jars (Jettison)).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5242V-12.2.1.3.0","P-2136V-12.0.0.4.0-12.0.0.7.0","P-5242V-12.2.1.4.0","P-5242V-14.1.1.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2136V-12.0.0.4.0-12.0.0.7.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916540.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-2136V-12.0.0.4.0-12.0.0.7.0","P-5242V-14.1.1.0.0","P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"]}]},{"cve":"CVE-2022-40153","notes":[{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Third Party Jars (XStream)).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0","P-5242V-14.1.1.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"]}]},{"cve":"CVE-2022-40304","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Oracle Linux (libxml2)).  Supported versions that are affected are 22.3.1 and  22.4.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Slice Selection Function executes to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the MySQL Workbench product of Oracle MySQL (component: Workbench (libxml2)).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Workbench executes to compromise MySQL Workbench.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Workbench. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4627V-8.0.31 and prior","P-14130V-22.4.1","P-14130V-22.3.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14130V-22.4.1","P-14130V-22.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919002.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4627V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-4627V-8.0.31 and prior","P-14130V-22.4.1","P-14130V-22.3.1"]}]},{"cve":"CVE-2022-40664","notes":[{"category":"description","text":"Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites (Apache Shiro)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9617V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9617V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-9617V-12.2.1.4.0"]}]},{"cve":"CVE-2022-4147","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (Quarkus)).  Supported versions that are affected are 22.3.0 and  22.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14250V-22.4.0","P-14250V-22.3.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14250V-22.3.0","P-14250V-22.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919017.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-14250V-22.3.0","P-14250V-22.4.0"]}]},{"cve":"CVE-2022-41720","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Go)).  Supported versions that are affected are 5.5.0-5.5.9 and  6.0.0-6.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916530.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"]}]},{"cve":"CVE-2022-41881","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (Netty)).  Supported versions that are affected are 22.3.0 and  22.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14250V-22.4.0","P-14250V-22.3.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14250V-22.3.0","P-14250V-22.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919017.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14250V-22.3.0","P-14250V-22.4.0"]}]},{"cve":"CVE-2022-42003","notes":[{"category":"description","text":"Vulnerability in the Oracle Banking Enterprise Default Management product of Oracle Financial Services Applications (component: Collections (jackson-databind)).  Supported versions that are affected are 2.7.1 and  2.12.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Enterprise Default Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Enterprise Default Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Banking Loans Servicing product of Oracle Financial Services Applications (component: Web UI (jackson-databind)).  Supported versions that are affected are 2.8.0 and  2.12.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Loans Servicing.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Loans Servicing. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Banking Party Management product of Oracle Financial Services Applications (component: Web UI (jackson-databind)).   The supported version that is affected is 2.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Party Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Party Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Banking Platform product of Oracle Financial Services Applications (component: Security (jackson-databind)).  Supported versions that are affected are 2.6.2, 2.7.1, 2.9.0 and  2.12.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Platform. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care, BOC, DM Kafka, REST API (jackson-databind)).  Supported versions that are affected are 12.0.0.4.0-12.0.0.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Calendar Server product of Oracle Communications Applications (component: Calendar Server (jackson-databind)).   The supported version that is affected is 8.0.0.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Calendar Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Calendar Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (jackson-databind)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (jackson-databind)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Data Analytics Function product of Oracle Communications (component: REST API (jackson-databind)).   The supported version that is affected is 22.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Data Analytics Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Data Analytics Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (jackson-databind)).   The supported version that is affected is 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Installation (jackson-databind)).   The supported version that is affected is 22.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Platform (jackson-databind)).   The supported version that is affected is 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (jackson-databind)).   The supported version that is affected is 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Signaling (jackson-databind)).  Supported versions that are affected are 22.2.2 and  22.3.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Contacts Server product of Oracle Communications Applications (component: Contact Server (jackson-databind)).   The supported version that is affected is 8.0.0.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Contacts Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Contacts Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Intelligence Hub product of Oracle Communications (component: Mediation (jackson-databind)).   The supported version that is affected is 8.2.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Intelligence Hub.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Intelligence Hub. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Instant Messaging Server product of Oracle Communications Applications (component: DBPlugin (jackson-databind)).   The supported version that is affected is 10.0.1.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Instant Messaging Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Instant Messaging Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications Applications (component: ISC (jackson-databind)).   The supported version that is affected is 8.1.0.20.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Messaging Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: REST Service Manager (jackson-databind)).  Supported versions that are affected are 12.0.0.5.0-12.0.0.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Pricing Design Center. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Message Bus (jackson-databind)).  Supported versions that are affected are 5.5.0-5.5.9 and  6.0.0-6.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Others (jackson-databind)).  Supported versions that are affected are 7.4.0, 7.4.1, 7.4.2 and  7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Database Fleet Patching (jackson-databind) component of Oracle Database Server.  Supported versions that are affected are 19c and  21c. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via HTTP to compromise Oracle Database Fleet Patching (jackson-databind).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Database Fleet Patching (jackson-databind). CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Crime and Compliance Management Studio product of Oracle Financial Services Applications (component: Studio (jackson-databind)).   The supported version that is affected is 8.0.8.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Crime and Compliance Management Studio.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Crime and Compliance Management Studio. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer issues  (jackson-databind)).  Supported versions that are affected are Prior to 13.9.4.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Global Lifecycle Management NextGen OUI Framework.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Global Lifecycle Management NextGen OUI Framework. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Health Sciences Empirica Signal product of Oracle Health Sciences Applications (component: Core (jackson-databind)).  Supported versions that are affected are 9.1.0.52 and  9.2.0.52. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences Empirica Signal.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Health Sciences Empirica Signal. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Management Cloud Engine product of Oracle Communications (component: Security (jackson-databind)).   The supported version that is affected is 22.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Management Cloud Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Management Cloud Engine. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search (jackson-databind)).  Supported versions that are affected are 8.59 and  8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (jackson-databind)).  Supported versions that are affected are 18.8.0-18.8.15, 19.12.0-19.12.15, 20.12.0-20.12.10 and  21.12.0-21.12.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Primavera Gateway. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Document Management (jackson-databind)).  Supported versions that are affected are 18.8, 19.12, 20.12, 21.12 and  22.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Primavera Unifier. CVSS 3.1 Base Score 5.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: Installation (jackson-databind)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1 and  16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Service Backbone. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle Spatial Studio (component: Oracle Spatial Studio (jackson-databind)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component: General (jackson-databind)).  Supported versions that are affected are 4.3.0.5.0, 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0 and  4.5.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Framework.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Framework. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10867V-15.0.3.1","P-14597V-5.5.0-5.5.9","P-13390V-2.7.1","P-4516V-7.5.0","P-2245V-4.3.0.6.0","P-8494V-8.0.0.6.0","P-2245V-4.4.0.3.0","P-9646V-9.1.0.52","P-5(Oracle Database Fleet Patching)V-21c","P-10354V-18.8","P-12738V-Prior to 13.9.4.2.11","P-9178V-2.7.1","P-10605V-18.8.0-18.8.15","P-9178V-2.9.0","P-10696V-8.0.0.7.0","P-5085V-8.59","P-14122V-22.3.1","P-10605V-20.12.0-20.12.10","P-2245V-4.5.0.0.0","P-5(Oracle Database Fleet Patching)V-19c","P-14489V-22.0.0.0.0","P-8496V-8.1.0.20.0","P-9437V-12.0.0.5.0-12.0.0.7.0","P-10867V-16.0.3","P-14119V-22.3.3","P-10354V-20.12","P-5085V-8.60","P-13929V-2.7.0","P-10605V-21.12.0-21.12.8","P-4516V-7.4.0","P-4516V-7.4.1","P-4516V-7.4.2","P-2245V-4.4.0.0.0","P-2245V-4.4.0.2.0","P-13595V-8.0.8.3.1","P-14252V-22.1.0.0.0","P-2245V-4.3.0.5.0","P-14130V-22.3.1","P-13927V-2.12.0","P-14250V-22.3.0","P-14597V-6.0.0-6.0.1","P-9646V-9.2.0.52","P-10354V-21.12","P-8495V-10.0.1.6.0","P-10605V-19.12.0-19.12.15","P-9178V-2.6.2","P-11126V-8.2.3.0","P-10867V-14.1.3.2","P-10354V-19.12","P-14123V-22.3.1","P-13927V-2.8.0","P-2136V-12.0.0.4.0-12.0.0.7.0","P-13390V-2.12.0","P-14118V-22.3.2","P-9178V-2.12.0","P-14119V-22.2.2","P-10354V-22.12"],"known_not_affected":["P-14121V-22.4.0","P-13600V-Prior to 22.3.0","P-14121V-22.3.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13927V-2.8.0","P-13390V-2.12.0","P-9178V-2.6.2","P-9178V-2.7.1","P-9178V-2.12.0","P-9178V-2.9.0","P-13927V-2.12.0","P-13390V-2.7.1","P-13929V-2.7.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917336.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2136V-12.0.0.4.0-12.0.0.7.0","P-9437V-12.0.0.5.0-12.0.0.7.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916540.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8495V-10.0.1.6.0","P-10696V-8.0.0.7.0","P-8494V-8.0.0.6.0","P-8496V-8.1.0.20.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916529.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.4.0","P-14121V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14250V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919017.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14489V-22.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2920604.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14122V-22.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919018.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14118V-22.3.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919001.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14130V-22.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919002.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-22.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919045.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14119V-22.3.3","P-14119V-22.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919035.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11126V-8.2.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919022.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916530.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4516V-7.4.0","P-4516V-7.4.1","P-4516V-7.5.0","P-4516V-7.4.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916531.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5(Oracle Database Fleet Patching)V-21c","P-13600V-Prior to 22.3.0","P-5(Oracle Database Fleet Patching)V-19c"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13595V-8.0.8.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917625.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-12738V-Prior to 13.9.4.2.11"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9646V-9.1.0.52","P-9646V-9.2.0.52"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916626.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14252V-22.1.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919078.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.59","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915481.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10354V-18.8","P-10605V-19.12.0-19.12.15","P-10605V-18.8.0-18.8.15","P-10605V-21.12.0-21.12.8","P-10354V-19.12","P-10354V-20.12","P-10605V-20.12.0-20.12.10","P-10354V-22.12","P-10354V-21.12"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917469.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10867V-15.0.3.1","P-10867V-16.0.3","P-10867V-14.1.3.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915671.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2245V-4.3.0.5.0","P-2245V-4.3.0.6.0","P-2245V-4.5.0.0.0","P-2245V-4.4.0.0.0","P-2245V-4.4.0.2.0","P-2245V-4.4.0.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915778.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-10867V-15.0.3.1","P-14597V-5.5.0-5.5.9","P-13390V-2.7.1","P-4516V-7.5.0","P-2245V-4.3.0.6.0","P-8494V-8.0.0.6.0","P-2245V-4.4.0.3.0","P-9646V-9.1.0.52","P-12738V-Prior to 13.9.4.2.11","P-9178V-2.7.1","P-10605V-18.8.0-18.8.15","P-9178V-2.9.0","P-10696V-8.0.0.7.0","P-5085V-8.59","P-14122V-22.3.1","P-10605V-20.12.0-20.12.10","P-2245V-4.5.0.0.0","P-14489V-22.0.0.0.0","P-8496V-8.1.0.20.0","P-9437V-12.0.0.5.0-12.0.0.7.0","P-10867V-16.0.3","P-14119V-22.3.3","P-5085V-8.60","P-13929V-2.7.0","P-10605V-21.12.0-21.12.8","P-4516V-7.4.0","P-4516V-7.4.1","P-4516V-7.4.2","P-2245V-4.4.0.0.0","P-2245V-4.4.0.2.0","P-13595V-8.0.8.3.1","P-14252V-22.1.0.0.0","P-2245V-4.3.0.5.0","P-14130V-22.3.1","P-13927V-2.12.0","P-14250V-22.3.0","P-14597V-6.0.0-6.0.1","P-9646V-9.2.0.52","P-8495V-10.0.1.6.0","P-10605V-19.12.0-19.12.15","P-9178V-2.6.2","P-11126V-8.2.3.0","P-10867V-14.1.3.2","P-14123V-22.3.1","P-13927V-2.8.0","P-2136V-12.0.0.4.0-12.0.0.7.0","P-13390V-2.12.0","P-14118V-22.3.2","P-9178V-2.12.0","P-14119V-22.2.2"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-14121V-22.4.0","P-14121V-22.3.0"]},{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-5(Oracle Database Fleet Patching)V-21c","P-5(Oracle Database Fleet Patching)V-19c"]},{"cvss_v3":{"baseScore":5.7,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-10354V-18.8","P-10354V-19.12","P-10354V-20.12","P-10354V-22.12","P-10354V-21.12"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13600V-Prior to 22.3.0"]}]},{"cve":"CVE-2022-42004","notes":[{"category":"description","text":"Security-in-Depth issue in the Oracle Global Lifecycle Management OPatchAuto product of Oracle Global Lifecycle Management (component: Database extensions (jackson-databind)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-12752V-DB: Prior to 12.2.0.1.32"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-12752V-DB: Prior to 12.2.0.1.32"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-12752V-DB: Prior to 12.2.0.1.32"]}]},{"cve":"CVE-2022-42252","notes":[{"category":"description","text":"Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security (Apache Tomcat)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Big Data Spatial and Graph product of Oracle Big Data Graph (component: Big Data Graph (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Policy (Apache Tomcat)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Apache Tomcat)).   The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Platform (Apache Tomcat)).   The supported version that is affected is 8.6.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Diameter Signaling Router accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Instant Messaging Server product of Oracle Communications Applications (component: DBPlugin (Apache Tomcat)).   The supported version that is affected is 10.0.1.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Instant Messaging Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Instant Messaging Server accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Integration (Apache Tomcat)).  Supported versions that are affected are 5.5.0-5.5.9 and  6.0.0-6.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Crime and Compliance Management Studio product of Oracle Financial Services Applications (component: Studio (Apache Tomcat)).   The supported version that is affected is 8.0.8.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Crime and Compliance Management Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Crime and Compliance Management Studio accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle Graph Server and Client (component: Packaging/install (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (Apache Tomcat)).  Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Enterprise Monitor accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8495V-10.0.1.6.0","P-13595V-8.0.8.3.1","P-14277V-22.3.0","P-8480V-8.0.32 and prior","P-4461V-9.3.6","P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1","P-14121V-22.3.0","P-10899V-8.6.0.0"],"known_not_affected":["P-11528V-Prior to 23.1.0","P-14069V-Prior to 23.1.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4461V-9.3.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915508.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14069V-Prior to 23.1.0","P-11528V-Prior to 23.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919044.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-8.6.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919053.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8495V-10.0.1.6.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916529.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916530.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13595V-8.0.8.3.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917625.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8480V-8.0.32 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-8495V-10.0.1.6.0","P-13595V-8.0.8.3.1","P-14277V-22.3.0","P-8480V-8.0.32 and prior","P-4461V-9.3.6","P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1","P-14121V-22.3.0","P-10899V-8.6.0.0"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-14069V-Prior to 23.1.0","P-11528V-Prior to 23.1.0"]}]},{"cve":"CVE-2022-42889","notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Analytics.  Supported versions that are affected are 5.9.0.0.0 and  6.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Elastic Charging Engine product of Oracle Communications Applications (component: Security (Apache Commons Text)).  Supported versions that are affected are 12.0.0.3.0-12.0.0.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Elastic Charging Engine. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Signaling (Apache Commons Text)).  Supported versions that are affected are 22.3.4 and  22.2.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Design Studio product of Oracle Communications Applications (component: PSR Designer (Apache Commons Text)).   The supported version that is affected is 7.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Design Studio.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Design Studio. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Virtual Network Function Manager (Apache Common Text)).   The supported version that is affected is 8.6.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Installer (Apache Commons Text)).   The supported version that is affected is 7.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Order and Service Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Commons Text)).  Supported versions that are affected are 5.5.0-5.5.9 and  6.0.0-6.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Database SQLcl (Apache Commons Text) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Management Agent (Apache Commons Text)).  Supported versions that are affected are 13.4.0.0 and    13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in takeover of Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration (Apache Commons Text)).   The supported version that is affected is 11.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security (Apache Commons Text)).  Supported versions that are affected are Prior to 9.2.7.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Orchestrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Management Cloud Engine product of Oracle Communications (component: Security (Apache Commons Text)).   The supported version that is affected is 22.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Management Cloud Engine.  Successful attacks of this vulnerability can result in takeover of Management Cloud Engine. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party Patch  (Apache Commons Text)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in takeover of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Apache Commons Text)).  Supported versions that are affected are 18.8.0-18.8.15, 19.12.0-19.12.15, 20.12.0-20.12.10 and  21.12.0-21.12.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in takeover of Primavera Gateway. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component: General (Apache Commons Text)).  Supported versions that are affected are 4.4.0.3.0 and  4.5.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Framework. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server (Apache Commons Text)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10605V-19.12.0-19.12.15","P-10605V-18.8.0-18.8.15","P-1370V-13.4.0.0","P-9742V-12.0.0.3.0-12.0.0.7.0","P-10605V-21.12.0-21.12.8","P-2270V-7.4.0","P-14597V-5.5.0-5.5.9","P-10605V-20.12.0-20.12.10","P-2025V-6.4.0.0.0","P-2245V-4.5.0.0.0","P-4392V-11.2.10","P-2245V-4.4.0.3.0","P-2283V-7.4.2","P-2025V-5.9.0.0.0","P-14119V-22.3.4","P-11681V-Prior to 9.2.7.2","P-14252V-22.1.0.0.0","P-14119V-22.2.3","P-1370V-13.5.0.0","P-4647V-12.2.1.4.0","P-2271V-12.2.1.4.0","P-14597V-6.0.0-6.0.1","P-10899V-8.6.0.0"],"known_not_affected":["P-5(Oracle Database SQLcl)V-19c","P-5(Oracle Database SQLcl)V-21c"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-5.9.0.0.0","P-2025V-6.4.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917214.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9742V-12.0.0.3.0-12.0.0.7.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916540.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14119V-22.3.4","P-14119V-22.2.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919035.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2283V-7.4.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2918168.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-8.6.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919053.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2270V-7.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916532.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-5.5.0-5.5.9","P-14597V-6.0.0-6.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916530.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5(Oracle Database SQLcl)V-21c","P-5(Oracle Database SQLcl)V-19c"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1370V-13.4.0.0","P-1370V-13.5.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906900.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4392V-11.2.10"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2775466.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11681V-Prior to 9.2.7.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915506.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14252V-22.1.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919078.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4647V-12.2.1.4.0","P-2271V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10605V-19.12.0-19.12.15","P-10605V-18.8.0-18.8.15","P-10605V-21.12.0-21.12.8","P-10605V-20.12.0-20.12.10"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917469.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2245V-4.5.0.0.0","P-2245V-4.4.0.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915778.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-10605V-19.12.0-19.12.15","P-10605V-18.8.0-18.8.15","P-1370V-13.4.0.0","P-9742V-12.0.0.3.0-12.0.0.7.0","P-10605V-21.12.0-21.12.8","P-2270V-7.4.0","P-14597V-5.5.0-5.5.9","P-10605V-20.12.0-20.12.10","P-2025V-6.4.0.0.0","P-2245V-4.5.0.0.0","P-4392V-11.2.10","P-2245V-4.4.0.3.0","P-2283V-7.4.2","P-2025V-5.9.0.0.0","P-14119V-22.3.4","P-11681V-Prior to 9.2.7.2","P-14252V-22.1.0.0.0","P-14119V-22.2.3","P-1370V-13.5.0.0","P-4647V-12.2.1.4.0","P-2271V-12.2.1.4.0","P-14597V-6.0.0-6.0.1","P-10899V-8.6.0.0"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-5(Oracle Database SQLcl)V-21c","P-5(Oracle Database SQLcl)V-19c"]}]},{"cve":"CVE-2022-42915","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (cURL)).   The supported version that is affected is 22.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in Oracle Essbase (component: Infrastructure (cURL)).   The supported version that is affected is 21.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Essbase.  Successful attacks of this vulnerability can result in takeover of Oracle Essbase. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14121V-22.1.1","P-4379V-21.4"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-22.1.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4379V-21.4"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-14121V-22.1.1"]},{"cvss_v3":{"baseScore":7.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-4379V-21.4"]}]},{"cve":"CVE-2022-42920","notes":[{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Third party Jars (Apache Commons BCEL)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"]}]},{"cve":"CVE-2022-43403","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Signaling (Jenkins Script)).   The supported version that is affected is 22.3.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  While the vulnerability is in Oracle Communications Cloud Native Core Unified Data Repository, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14119V-22.3.3"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14119V-22.3.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919035.1"}],"scores":[{"cvss_v3":{"baseScore":9.9,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"products":["P-14119V-22.3.3"]}]},{"cve":"CVE-2022-43548","notes":[{"category":"description","text":"Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Node (Node.js)).  Supported versions that are affected are Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and  22.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle GraalVM Enterprise Edition. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-13497V-Oracle GraalVM Enterprise Edition:20.3.8","P-13497V-Oracle GraalVM Enterprise Edition:21.3.4","P-13497V-Oracle GraalVM Enterprise Edition:22.3.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13497V-Oracle GraalVM Enterprise Edition:20.3.8","P-13497V-Oracle GraalVM Enterprise Edition:21.3.4","P-13497V-Oracle GraalVM Enterprise Edition:22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917310.1"}],"scores":[{"cvss_v3":{"baseScore":8.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-13497V-Oracle GraalVM Enterprise Edition:20.3.8","P-13497V-Oracle GraalVM Enterprise Edition:21.3.4","P-13497V-Oracle GraalVM Enterprise Edition:22.3.0"]}]},{"cve":"CVE-2022-43680","notes":[{"category":"description","text":"Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Centralized Third-party Jars (Libexpat)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: DC-Specific Component (LibExpat)).   The supported version that is affected is 8.5.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4647V-12.2.1.4.0","P-2276V-8.5.6"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4647V-12.2.1.4.0","P-2276V-8.5.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-4647V-12.2.1.4.0","P-2276V-8.5.6"]}]},{"cve":"CVE-2022-45047","notes":[{"category":"description","text":"Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: End-User Documentation (Apache Mina SSHD)).   The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (Apache MINA SSHD)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Database Portable Clusterware (Apache Mina SSHD) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer issues  (Apache Mina SSHD)).  Supported versions that are affected are Prior to 13.9.4.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Global Lifecycle Management NextGen OUI Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Global Lifecycle Management NextGen OUI Framework. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Global Lifecycle Management OPatchAuto product of Oracle Global Lifecycle Management (component: Database extensions  (Apache Mina SSHD)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: RDA - Remote Diagnostic Agent (Apache Mina SSHD)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in takeover of Middleware Common Libraries and Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Diagnostic Assistant (Apache Mina SSHD)).   The supported version that is affected is 2.12.43. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise OSS Support Tools.  Successful attacks of this vulnerability can result in takeover of OSS Support Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: RDA - Remote Diagnostic Agent (Apache MINA SSHD)).   The supported version that is affected is 22.4.22.10.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise OSS Support Tools.  Successful attacks of this vulnerability can result in takeover of OSS Support Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Services Tools Bundle (Apache Mina SSHD)).   The supported version that is affected is 22.2.22.4.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise OSS Support Tools.  Successful attacks of this vulnerability can result in takeover of OSS Support Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle SQLcl (Apache Mina SSHD) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4647V-14.1.1.0.0","P-1330(Diagnostic Assistant)V-2.12.43","P-12738V-Prior to 13.9.4.2.11","P-1330(RDA - Remote Diagnostic Agent)V-22.4.22.10.18","P-4647V-12.2.1.4.0","P-2545V-14.1.1.0.0","P-1330(Services Tools Bundle)V-22.2.22.4.5"],"known_not_affected":["P-5(Oracle Database Portable Clusterware)V-21c","P-13824V-19c","P-14250V-22.3.0","P-12752V-DB: Prior to 12.2.0.1.35","P-13824V-21c","P-14250V-22.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4647V-14.1.1.0.0","P-12738V-Prior to 13.9.4.2.11","P-4647V-12.2.1.4.0","P-2545V-14.1.1.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14250V-22.3.0","P-14250V-22.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919017.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5(Oracle Database Portable Clusterware)V-21c","P-13824V-19c","P-12752V-DB: Prior to 12.2.0.1.35","P-13824V-21c"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1330(Diagnostic Assistant)V-2.12.43","P-1330(RDA - Remote Diagnostic Agent)V-22.4.22.10.18","P-1330(Services Tools Bundle)V-22.2.22.4.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919775.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-4647V-14.1.1.0.0","P-1330(Diagnostic Assistant)V-2.12.43","P-12738V-Prior to 13.9.4.2.11","P-1330(RDA - Remote Diagnostic Agent)V-22.4.22.10.18","P-4647V-12.2.1.4.0","P-2545V-14.1.1.0.0","P-1330(Services Tools Bundle)V-22.2.22.4.5"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-5(Oracle Database Portable Clusterware)V-21c","P-13824V-19c","P-14250V-22.3.0","P-12752V-DB: Prior to 12.2.0.1.35","P-13824V-21c","P-14250V-22.4.0"]}]},{"cve":"CVE-2023-21824","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Customer, Config, Pricing Manager).  Supported versions that are affected are 12.0.0.3.0-12.0.0.7.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications BRM - Elastic Charging Engine executes to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications BRM - Elastic Charging Engine accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9742V-12.0.0.3.0-12.0.0.7.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9742V-12.0.0.3.0-12.0.0.7.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916540.1"}],"scores":[{"cvss_v3":{"baseScore":4.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-9742V-12.0.0.3.0-12.0.0.7.0"]}]},{"cve":"CVE-2023-21825","notes":[{"category":"description","text":"Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Supplier Management).  Supported versions that are affected are 12.2.6-12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupplier Portal.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle iSupplier Portal accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-208V-12.2.6-12.2.8"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-208V-12.2.6-12.2.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2484000.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"products":["P-208V-12.2.6-12.2.8"]}]},{"cve":"CVE-2023-21826","notes":[{"category":"description","text":"Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Reporting).   The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Hospitality Reporting and Analytics.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hospitality Reporting and Analytics accessible data as well as  unauthorized update, insert or delete access to some of Oracle Hospitality Reporting and Analytics accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Reporting and Analytics. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-11599V-9.1.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11599V-9.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2913273.1"}],"scores":[{"cvss_v3":{"baseScore":7.6,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:H","version":"3.1"},"products":["P-11599V-9.1.0"]}]},{"acknowledgments":[{"names":["Okan Basegmez"]}],"cve":"CVE-2023-21827","notes":[{"category":"description","text":"Vulnerability in the Oracle Database Data Redaction component of Oracle Database Server.  Supported versions that are affected are 19c and  21c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database Data Redaction.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Database Data Redaction accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5(Oracle Database Data Redaction)V-19c","P-5(Oracle Database Data Redaction)V-21c"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5(Oracle Database Data Redaction)V-19c","P-5(Oracle Database Data Redaction)V-21c"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"}],"scores":[{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"products":["P-5(Oracle Database Data Redaction)V-19c","P-5(Oracle Database Data Redaction)V-21c"]}]},{"cve":"CVE-2023-21828","notes":[{"category":"description","text":"Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Reporting).   The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Hospitality Reporting and Analytics.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Reporting and Analytics accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hospitality Reporting and Analytics accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-11599V-9.1.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11599V-9.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2913273.1"}],"scores":[{"cvss_v3":{"baseScore":8.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"products":["P-11599V-9.1.0"]}]},{"acknowledgments":[{"names":["Michael Kutz"]}],"cve":"CVE-2023-21829","notes":[{"category":"description","text":"Vulnerability in the Oracle Database RDBMS Security component of Oracle Database Server.  Supported versions that are affected are 19c and  21c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database RDBMS Security.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Database RDBMS Security accessible data as well as  unauthorized read access to a subset of Oracle Database RDBMS Security accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5(Oracle Database RDBMS Security)V-19c","P-5(Oracle Database RDBMS Security)V-21c"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5(Oracle Database RDBMS Security)V-19c","P-5(Oracle Database RDBMS Security)V-21c"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"}],"scores":[{"cvss_v3":{"baseScore":6.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N","version":"3.1"},"products":["P-5(Oracle Database RDBMS Security)V-19c","P-5(Oracle Database RDBMS Security)V-21c"]}]},{"acknowledgments":[{"names":["thiscodecc"],"organization":"MoyunSec TopBreaker Labs"}],"cve":"CVE-2023-21830","notes":[{"category":"description","text":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization).  Supported versions that are affected are Oracle Java SE: 8u351, 8u351-perf; Oracle GraalVM Enterprise Edition: 20.3.8 and  21.3.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-13497V-Oracle GraalVM Enterprise Edition:20.3.8","P-13497V-Oracle GraalVM Enterprise Edition:21.3.4","P-856V-Oracle Java SE:8u351-perf","P-856V-Oracle Java SE:8u351"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-856V-Oracle Java SE:8u351","P-13497V-Oracle GraalVM Enterprise Edition:20.3.8","P-13497V-Oracle GraalVM Enterprise Edition:21.3.4","P-856V-Oracle Java SE:8u351-perf"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917310.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"products":["P-856V-Oracle Java SE:8u351","P-13497V-Oracle GraalVM Enterprise Edition:20.3.8","P-13497V-Oracle GraalVM Enterprise Edition:21.3.4","P-856V-Oracle Java SE:8u351-perf"]}]},{"cve":"CVE-2023-21831","notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise CS Academic Advisement product of Oracle PeopleSoft (component: Advising Notes).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Academic Advisement.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise CS Academic Advisement accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5181V-9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5181V-9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915481.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"products":["P-5181V-9.2"]}]},{"acknowledgments":[{"names":["4ra1n"],"organization":"X-Ray Security Team from Chaitin Tech"}],"cve":"CVE-2023-21832","notes":[{"category":"description","text":"Vulnerability in the Oracle BI Publisher component of Oracle Analytics.  Supported versions that are affected are 5.9.0.0.0, 6.4.0.0.0 and  12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker having Security privilege with network access via multiple protocols to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1479V-6.4.0.0.0","P-1479V-5.9.0.0.0","P-1479V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1479V-6.4.0.0.0","P-1479V-5.9.0.0.0","P-1479V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917214.2"}],"scores":[{"cvss_v3":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-1479V-6.4.0.0.0","P-1479V-5.9.0.0.0","P-1479V-12.2.1.4.0"]}]},{"acknowledgments":[{"names":["Nour Ehab Abd Eldayem"],"organization":"Cysiv"}],"cve":"CVE-2023-21834","notes":[{"category":"description","text":"Vulnerability in the Oracle Self-Service Human Resources product of Oracle E-Business Suite (component: Workflow, Approval, Work Force Management).  Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Self-Service Human Resources.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Self-Service Human Resources accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1566V-12.2.3-12.2.12"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1566V-12.2.3-12.2.12"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2484000.1"}],"scores":[{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"products":["P-1566V-12.2.3-12.2.12"]}]},{"acknowledgments":[{"names":["Juraj Somorovsky"],"organization":"Paderborn University"},{"names":["Marcel Maehren"],"organization":"Ruhr-University Bochum"},{"names":["Nurullah Erinola"],"organization":"Ruhr-University Bochum"},{"names":["Robert Merget"],"organization":"Ruhr-University Bochum"}],"cve":"CVE-2023-21835","notes":[{"category":"description","text":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE).  Supported versions that are affected are Oracle Java SE: 11.0.17, 17.0.5, 19.0.1; Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and  22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via DTLS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-856V-Oracle Java SE:17.0.5","P-13497V-Oracle GraalVM Enterprise Edition:20.3.8","P-13497V-Oracle GraalVM Enterprise Edition:21.3.4","P-856V-Oracle Java SE:11.0.17","P-856V-Oracle Java SE:19.0.1","P-13497V-Oracle GraalVM Enterprise Edition:22.3.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-856V-Oracle Java SE:17.0.5","P-13497V-Oracle GraalVM Enterprise Edition:20.3.8","P-13497V-Oracle GraalVM Enterprise Edition:21.3.4","P-856V-Oracle Java SE:11.0.17","P-856V-Oracle Java SE:19.0.1","P-13497V-Oracle GraalVM Enterprise Edition:22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917310.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["P-856V-Oracle Java SE:17.0.5","P-13497V-Oracle GraalVM Enterprise Edition:20.3.8","P-13497V-Oracle GraalVM Enterprise Edition:21.3.4","P-856V-Oracle Java SE:11.0.17","P-856V-Oracle Java SE:19.0.1","P-13497V-Oracle GraalVM Enterprise Edition:22.3.0"]}]},{"cve":"CVE-2023-21836","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"acknowledgments":[{"names":["thiscodecc"],"organization":"MoyunSec TopBreaker Labs and Bing Liu"}],"cve":"CVE-2023-21837","notes":[{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0","P-5242V-14.1.1.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"]}]},{"acknowledgments":[{"names":["r00t4dm working with Trend Micro Zero Day Initiative"]}],"cve":"CVE-2023-21838","notes":[{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0","P-5242V-14.1.1.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"]}]},{"acknowledgments":[{"names":["0xrumbe, Lamber, M1s5p"],"organization":"ThreatBook Labs"},{"names":["0xrumble"]},{"names":["4ra1n"],"organization":"X-Ray Security Team from Chaitin Tech"},{"names":["Lamber"]},{"names":["M1s5p"]},{"names":["thiscodecc"],"organization":"MoyunSec TopBreaker Labs and Bing Liu"},{"names":["Y4tacker"]},{"names":["Yu Wang"],"organization":"BMH Security Team"}],"cve":"CVE-2023-21839","notes":[{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0","P-5242V-14.1.1.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"]}]},{"cve":"CVE-2023-21840","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS).  Supported versions that are affected are 5.7.40 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-5.7.40 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-5.7.40 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478V-5.7.40 and prior"]}]},{"acknowledgments":[{"names":["Liboheng"],"organization":"Tophant Starlight laboratory"}],"cve":"CVE-2023-21841","notes":[{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0","P-5242V-14.1.1.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"]}]},{"cve":"CVE-2023-21842","notes":[{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0","P-5242V-14.1.1.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.3.0","P-5242V-12.2.1.4.0"]}]},{"acknowledgments":[{"names":["Markus Loewe"]}],"cve":"CVE-2023-21843","notes":[{"category":"description","text":"Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Sound).  Supported versions that are affected are Oracle Java SE: 8u351, 8u351-perf, 11.0.17, 17.0.5, 19.0.1; Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and  22.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-856V-Oracle Java SE:8u351","P-856V-Oracle Java SE:17.0.5","P-13497V-Oracle GraalVM Enterprise Edition:20.3.8","P-13497V-Oracle GraalVM Enterprise Edition:21.3.4","P-856V-Oracle Java SE:8u351-perf","P-856V-Oracle Java SE:11.0.17","P-856V-Oracle Java SE:19.0.1","P-13497V-Oracle GraalVM Enterprise Edition:22.3.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-856V-Oracle Java SE:8u351","P-856V-Oracle Java SE:17.0.5","P-13497V-Oracle GraalVM Enterprise Edition:20.3.8","P-13497V-Oracle GraalVM Enterprise Edition:21.3.4","P-856V-Oracle Java SE:8u351-perf","P-856V-Oracle Java SE:11.0.17","P-856V-Oracle Java SE:19.0.1","P-13497V-Oracle GraalVM Enterprise Edition:22.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917310.1"}],"scores":[{"cvss_v3":{"baseScore":3.7,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"products":["P-856V-Oracle Java SE:8u351","P-856V-Oracle Java SE:17.0.5","P-13497V-Oracle GraalVM Enterprise Edition:20.3.8","P-13497V-Oracle GraalVM Enterprise Edition:21.3.4","P-856V-Oracle Java SE:8u351-perf","P-856V-Oracle Java SE:11.0.17","P-856V-Oracle Java SE:19.0.1","P-13497V-Oracle GraalVM Enterprise Edition:22.3.0"]}]},{"cve":"CVE-2023-21844","notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search).  Supported versions that are affected are 8.59 and  8.60. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.60","P-5085V-8.59"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.59","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915481.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-5085V-8.59","P-5085V-8.60"]}]},{"cve":"CVE-2023-21845","notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor).   The supported version that is affected is 8.60. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085(Panel Processor)V-8.60"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085(Panel Processor)V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915481.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-5085(Panel Processor)V-8.60"]}]},{"acknowledgments":[{"names":["4ra1n"],"organization":"X-Ray Security Team from Chaitin Tech"}],"cve":"CVE-2023-21846","notes":[{"category":"description","text":"Vulnerability in the Oracle BI Publisher component of Oracle Analytics.  Supported versions that are affected are 5.9.0.0.0, 6.4.0.0.0 and  12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker having Security privilege with network access via multiple protocols to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1479V-6.4.0.0.0","P-1479V-5.9.0.0.0","P-1479V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1479V-6.4.0.0.0","P-1479V-5.9.0.0.0","P-1479V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917214.2"}],"scores":[{"cvss_v3":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-1479V-6.4.0.0.0","P-1479V-5.9.0.0.0","P-1479V-12.2.1.4.0"]}]},{"acknowledgments":[{"names":["Adam Willard"]}],"cve":"CVE-2023-21847","notes":[{"category":"description","text":"Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Download).  Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Web Applications Desktop Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Web Applications Desktop Integrator accessible data as well as  unauthorized read access to a subset of Oracle Web Applications Desktop Integrator accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1171V-12.2.3-12.2.12"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1171V-12.2.3-12.2.12"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2484000.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-1171V-12.2.3-12.2.12"]}]},{"cve":"CVE-2023-21848","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: Admin Configuration).   The supported version that is affected is 3.0.3.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Convergence.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Convergence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8501V-3.0.3.1.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8501V-3.0.3.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2916529.1"}],"scores":[{"cvss_v3":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-8501V-3.0.3.1.0"]}]},{"cve":"CVE-2023-21849","notes":[{"category":"description","text":"Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Java utils).  Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications DBA.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Applications DBA accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-166V-12.2.3-12.2.12"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-166V-12.2.3-12.2.12"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2484000.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-166V-12.2.3-12.2.12"]}]},{"cve":"CVE-2023-21850","notes":[{"category":"description","text":"Vulnerability in the Oracle Demantra Demand Management product of Oracle Supply Chain (component: E-Business Collections).  Supported versions that are affected are 12.1 and  12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Demantra Demand Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Demantra Demand Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2100V-12.2","P-2100V-12.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2100V-12.2","P-2100V-12.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2915508.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-2100V-12.2","P-2100V-12.1"]}]},{"cve":"CVE-2023-21851","notes":[{"category":"description","text":"Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration).  Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Marketing accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-229V-12.2.3-12.2.12"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-229V-12.2.3-12.2.12"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2484000.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-229V-12.2.3-12.2.12"]}]},{"cve":"CVE-2023-21852","notes":[{"category":"description","text":"Vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (component: Setup).  Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Learning Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Learning Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-937V-12.2.3-12.2.12"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-937V-12.2.3-12.2.12"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2484000.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-937V-12.2.3-12.2.12"]}]},{"cve":"CVE-2023-21853","notes":[{"category":"description","text":"Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Synchronization).  Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Mobile Field Service.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Mobile Field Service accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-753V-12.2.3-12.2.12"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-753V-12.2.3-12.2.12"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2484000.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-753V-12.2.3-12.2.12"]}]},{"cve":"CVE-2023-21854","notes":[{"category":"description","text":"Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Core Components).  Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Sales Offline accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1009V-12.2.3-12.2.12"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1009V-12.2.3-12.2.12"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2484000.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-1009V-12.2.3-12.2.12"]}]},{"cve":"CVE-2023-21855","notes":[{"category":"description","text":"Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Business Suite (component: Pocket Outlook Sync(PocketPC)).  Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales for Handhelds.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Sales for Handhelds accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-186V-12.2.3-12.2.12"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-186V-12.2.3-12.2.12"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2484000.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-186V-12.2.3-12.2.12"]}]},{"cve":"CVE-2023-21856","notes":[{"category":"description","text":"Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports).  Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSetup.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle iSetup accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-841V-12.2.3-12.2.12"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-841V-12.2.3-12.2.12"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2484000.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-841V-12.2.3-12.2.12"]}]},{"cve":"CVE-2023-21857","notes":[{"category":"description","text":"Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Auomated Test Suite).  Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Common Architecture.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HCM Common Architecture accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2021V-12.2.3-12.2.12"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2021V-12.2.3-12.2.12"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2484000.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-2021V-12.2.3-12.2.12"]}]},{"cve":"CVE-2023-21858","notes":[{"category":"description","text":"Vulnerability in the Oracle Collaborative Planning product of Oracle E-Business Suite (component: Installation).  Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Collaborative Planning.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Collaborative Planning accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1037V-12.2.3-12.2.12"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1037V-12.2.3-12.2.12"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2484000.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-1037V-12.2.3-12.2.12"]}]},{"cve":"CVE-2023-21859","notes":[{"category":"description","text":"Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Access Manager executes to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5565V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5565V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":4.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-5565V-12.2.1.4.0"]}]},{"cve":"CVE-2023-21860","notes":[{"category":"description","text":"Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: Internal Operations).  Supported versions that are affected are 7.4.38 and prior, 7.5.28 and prior, 7.6.24 and prior and  8.0.31 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8479V-7.4.38 and prior","P-8479V-7.6.24 and prior","P-8479V-7.5.28 and prior","P-8479V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8479V-7.4.38 and prior","P-8479V-8.0.31 and prior","P-8479V-7.6.24 and prior","P-8479V-7.5.28 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":6.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-8479V-7.4.38 and prior","P-8479V-8.0.31 and prior","P-8479V-7.6.24 and prior","P-8479V-7.5.28 and prior"]}]},{"acknowledgments":[{"names":["AnhNH"],"organization":"Sacombank"},{"names":["ChauUHM"],"organization":"Sacombank"},{"names":["TungHT"],"organization":"Sacombank"}],"cve":"CVE-2023-21861","notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Analytics.  Supported versions that are affected are 5.9.0.0.0 and  6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker having Visual Analyzer privilege with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-6.4.0.0.0","P-2025V-5.9.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-5.9.0.0.0","P-2025V-6.4.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917214.2"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-2025V-5.9.0.0.0","P-2025V-6.4.0.0.0"]}]},{"cve":"CVE-2023-21862","notes":[{"category":"description","text":"Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: XML Security component).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Services Manager.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Web Services Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Web Services Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1775V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1775V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":8.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N","version":"3.1"},"products":["P-1775V-12.2.1.4.0"]}]},{"cve":"CVE-2023-21863","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"cve":"CVE-2023-21864","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.30 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.30 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478V-8.0.30 and prior"]}]},{"cve":"CVE-2023-21865","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.30 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.30 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478V-8.0.30 and prior"]}]},{"cve":"CVE-2023-21866","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.28 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.28 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478V-8.0.28 and prior"]}]},{"cve":"CVE-2023-21867","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"cve":"CVE-2023-21868","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"cve":"CVE-2023-21869","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"cve":"CVE-2023-21870","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"cve":"CVE-2023-21871","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"acknowledgments":[{"names":["Zu-Ming Jiang"]}],"cve":"CVE-2023-21872","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.29 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.29 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"products":["P-8478V-8.0.29 and prior"]}]},{"cve":"CVE-2023-21873","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"cve":"CVE-2023-21874","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling).  Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.30 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.30 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":2.7,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["P-8478V-8.0.30 and prior"]}]},{"cve":"CVE-2023-21875","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption).  Supported versions that are affected are 8.0.31 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.9 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":5.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"cve":"CVE-2023-21876","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"cve":"CVE-2023-21877","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"acknowledgments":[{"names":["Zu-Ming Jiang"]}],"cve":"CVE-2023-21878","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"acknowledgments":[{"names":["Zu-Ming Jiang"]}],"cve":"CVE-2023-21879","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"acknowledgments":[{"names":["Zu-Ming Jiang"]}],"cve":"CVE-2023-21880","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"acknowledgments":[{"names":["Zu-Ming Jiang"]}],"cve":"CVE-2023-21881","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"cve":"CVE-2023-21882","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 2.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":2.7,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"acknowledgments":[{"names":["Jie Liang"],"organization":"WingTecher Lab"},{"names":["Jingzhou Fu"],"organization":"WingTecher Lab"},{"names":["Zhiyong Wu"],"organization":"WingTecher Lab"}],"cve":"CVE-2023-21883","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"acknowledgments":[{"names":["Siqi Chen"],"organization":"Shanghai Jiao Tong University"}],"cve":"CVE-2023-21884","notes":[{"category":"description","text":"Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are Prior to 6.1.42 and  prior to 7.0.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8370V-prior to 7.0.6","P-8370V-Prior to 6.1.42"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8370V-Prior to 6.1.42","P-8370V-prior to 7.0.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919776.1"}],"scores":[{"cvss_v3":{"baseScore":4.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8370V-Prior to 6.1.42","P-8370V-prior to 7.0.6"]}]},{"acknowledgments":[{"names":["Aobo Wang"],"organization":"Chaitin Security Research Lab"},{"names":["Kun Yang"],"organization":"Chaitin Security Research Lab"}],"cve":"CVE-2023-21885","notes":[{"category":"description","text":"Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are Prior to 6.1.42 and  prior to 7.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle VM VirtualBox accessible data.  Note: Applies to Windows only. CVSS 3.1 Base Score 3.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8370V-prior to 7.0.6","P-8370V-Prior to 6.1.42"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8370V-Prior to 6.1.42","P-8370V-prior to 7.0.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919776.1"}],"scores":[{"cvss_v3":{"baseScore":3.8,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","version":"3.1"},"products":["P-8370V-Prior to 6.1.42","P-8370V-prior to 7.0.6"]}]},{"acknowledgments":[{"names":["Exist (exist91240480) working with Trend Micro Zero Day Initiative"]}],"cve":"CVE-2023-21886","notes":[{"category":"description","text":"Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are Prior to 6.1.42 and  prior to 7.0.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8370V-prior to 7.0.6","P-8370V-Prior to 6.1.42"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8370V-Prior to 6.1.42","P-8370V-prior to 7.0.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919776.1"}],"scores":[{"cvss_v3":{"baseScore":8.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-8370V-Prior to 6.1.42","P-8370V-prior to 7.0.6"]}]},{"cve":"CVE-2023-21887","notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: GIS).  Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478V-8.0.31 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478V-8.0.31 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917170.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478V-8.0.31 and prior"]}]},{"acknowledgments":[{"names":["Johnathon Wilson"],"organization":"NCC Group"}],"cve":"CVE-2023-21888","notes":[{"category":"description","text":"Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: WebUI).  Supported versions that are affected are 18.8.0-18.8.15, 19.12.0-19.12.15, 20.12.0-20.12.10 and  21.12.0-21.12.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Gateway.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Gateway, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera Gateway accessible data as well as  unauthorized read access to a subset of Primavera Gateway accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10605V-20.12.0-20.12.10","P-10605V-19.12.0-19.12.15","P-10605V-18.8.0-18.8.15","P-10605V-21.12.0-21.12.8"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10605V-19.12.0-19.12.15","P-10605V-18.8.0-18.8.15","P-10605V-21.12.0-21.12.8","P-10605V-20.12.0-20.12.10"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917469.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-10605V-19.12.0-19.12.15","P-10605V-18.8.0-18.8.15","P-10605V-21.12.0-21.12.8","P-10605V-20.12.0-20.12.10"]}]},{"acknowledgments":[{"names":["Aobo Wang"],"organization":"Chaitin Security Research Lab"},{"names":["Kun Yang"],"organization":"Chaitin Security Research Lab"}],"cve":"CVE-2023-21889","notes":[{"category":"description","text":"Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are Prior to 6.1.42 and  prior to 7.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8370V-prior to 7.0.6","P-8370V-Prior to 6.1.42"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8370V-Prior to 6.1.42","P-8370V-prior to 7.0.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919776.1"}],"scores":[{"cvss_v3":{"baseScore":3.8,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","version":"3.1"},"products":["P-8370V-Prior to 6.1.42","P-8370V-prior to 7.0.6"]}]},{"acknowledgments":[{"names":["Peter Mularien, Nightcrawler Security, LLC working with Trend Micro Zero Day Initiative"]}],"cve":"CVE-2023-21890","notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core).  Supported versions that are affected are 7.1.0 and  8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to compromise Oracle Communications Converged Application Server.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5382V-7.1.0","P-5382V-8.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5382V-8.0.0","P-5382V-7.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919079.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-5382V-8.0.0","P-5382V-7.1.0"]}]},{"acknowledgments":[{"names":["AnhNH"],"organization":"Sacombank"},{"names":["ChauUHM"],"organization":"Sacombank"},{"names":["TungHT"],"organization":"Sacombank"}],"cve":"CVE-2023-21891","notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Analytics.  Supported versions that are affected are 5.9.0.0.0 and  6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker having Visual Analyzer privilege with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-6.4.0.0.0","P-2025V-5.9.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-5.9.0.0.0","P-2025V-6.4.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917214.2"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-2025V-5.9.0.0.0","P-2025V-6.4.0.0.0"]}]},{"acknowledgments":[{"names":["AnhNH"],"organization":"Sacombank"},{"names":["ChauUHM"],"organization":"Sacombank"},{"names":["TungHT"],"organization":"Sacombank"}],"cve":"CVE-2023-21892","notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Analytics.  Supported versions that are affected are 5.9.0.0.0 and  6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker having Visual Analyzer privilege with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-6.4.0.0.0","P-2025V-5.9.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-5.9.0.0.0","P-2025V-6.4.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917214.2"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-2025V-5.9.0.0.0","P-2025V-6.4.0.0.0"]}]},{"cve":"CVE-2023-21893","notes":[{"category":"description","text":"Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server.  Supported versions that are affected are 19c and  21c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCPS to compromise Oracle Data Provider for .NET.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Data Provider for .NET.  Note: Applies also to Database client-only on Windows platform. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1321V-19c","P-1321V-21c"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1321V-21c","P-1321V-19c"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2906899.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-1321V-21c","P-1321V-19c"]}]},{"acknowledgments":[{"names":["Dhiraj Mishra"]}],"cve":"CVE-2023-21894","notes":[{"category":"description","text":"Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer issues).  Supported versions that are affected are Prior to 13.9.4.2.11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Global Lifecycle Management NextGen OUI Framework executes to compromise Oracle Global Lifecycle Management NextGen OUI Framework.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Global Lifecycle Management NextGen OUI Framework. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-12738V-Prior to 13.9.4.2.11"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-12738V-Prior to 13.9.4.2.11"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2917213.2"}],"scores":[{"cvss_v3":{"baseScore":7.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-12738V-Prior to 13.9.4.2.11"]}]},{"acknowledgments":[{"names":["Aobo Wang"],"organization":"Chaitin Security Research Lab"},{"names":["Kun Yang"],"organization":"Chaitin Security Research Lab"}],"cve":"CVE-2023-21898","notes":[{"category":"description","text":"Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are Prior to 6.1.42 and  prior to 7.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox.  Note: Applies to VirtualBox VMs running Windows 7 and later. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8370V-prior to 7.0.6","P-8370V-Prior to 6.1.42"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8370V-Prior to 6.1.42","P-8370V-prior to 7.0.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919776.1"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8370V-Prior to 6.1.42","P-8370V-prior to 7.0.6"]}]},{"acknowledgments":[{"names":["Aobo Wang"],"organization":"Chaitin Security Research Lab"},{"names":["Kun Yang"],"organization":"Chaitin Security Research Lab"}],"cve":"CVE-2023-21899","notes":[{"category":"description","text":"Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are Prior to 6.1.42 and  prior to 7.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox.  Note: Applies to VirtualBox VMs running Windows 7 and later. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8370V-prior to 7.0.6","P-8370V-Prior to 6.1.42"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8370V-Prior to 6.1.42","P-8370V-prior to 7.0.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2919776.1"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8370V-Prior to 6.1.42","P-8370V-prior to 7.0.6"]}]},{"cve":"CVE-2023-21900","notes":[{"category":"description","text":"Vulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch).  Supported versions that are affected are 10 and  11. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise Oracle Solaris.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Solaris accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Solaris. CVSS 3.1 Base Score 4.0 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10006V-10","P-10006V-11"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10006V-10","P-10006V-11"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2920776.1"}],"scores":[{"cvss_v3":{"baseScore":4.0,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:L","version":"3.1"},"products":["P-10006V-10","P-10006V-11"]}]}]}