{"document":{"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"text":"Copyright © Oracle. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp"}},"publisher":{"category":"vendor","name":"Oracle","namespace":"https://www.oracle.com"},"references":[{"summary":"URL to html version of Advisory","url":"https://www.oracle.com/security-alerts/cpujan2025.html"},{"category":"self","summary":"URL to CSAF version of Advisory","url":"https://www.oracle.com/docs/tech/security-alerts/cpujan2025csaf.json"}],"title":"Oracle Critical Patch Update Advisory - January 2025 - Oracle CSAF","tracking":{"current_release_date":"2025-02-11T15:00:00-07:00","id":"CPUJan2025csaf","initial_release_date":"2025-01-21T13:00:00-07:00","revision_history":[{"date":"2025-01-21T13:00:00-07:00","number":"1","summary":"Initial Release"},{"date":"2025-02-11T15:00:00-07:00","number":"2","summary":"Rev 2. Updated version information for CVE-2024-35195 and CVE-2024-49766."}],"status":"final","version":"2"}},"product_tree":{"branches":[{"branches":[{"branches":[{"branches":[{"category":"product_version_range","name":"Oracle Analytics Desktop Version Prior to 8.1.0","product":{"name":"Oracle Analytics Desktop Version Prior to 8.1.0","product_id":"P-12791V-Prior to 8.1.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:analytics_desktop:prior_to_8.1.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Analytics Desktop"},{"branches":[{"category":"product_version","name":"Oracle BI Publisher Version 7.0.0.0.0","product":{"name":"Oracle BI Publisher Version 7.0.0.0.0","product_id":"P-1479V-7.0.0.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:bi_publisher:7.0.0.0.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle BI Publisher Version 7.6.0.0.0","product":{"name":"Oracle BI Publisher Version 7.6.0.0.0","product_id":"P-1479V-7.6.0.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:bi_publisher:7.6.0.0.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle BI Publisher"},{"branches":[{"category":"product_version","name":"Oracle Business Intelligence Enterprise Edition Version 12.2.1.4.0","product":{"name":"Oracle Business Intelligence Enterprise Edition Version 12.2.1.4.0","product_id":"P-2025V-12.2.1.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*"}}},{"category":"product_version","name":"Oracle Business Intelligence Enterprise Edition Version 7.0.0.0.0","product":{"name":"Oracle Business Intelligence Enterprise Edition Version 7.0.0.0.0","product_id":"P-2025V-7.0.0.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:business_intelligence:7.0.0.0.0:*:*:*:enterprise:*:*:*"}}},{"category":"product_version","name":"Oracle Business Intelligence Enterprise Edition Version 7.6.0.0.0","product":{"name":"Oracle Business Intelligence Enterprise Edition Version 7.6.0.0.0","product_id":"P-2025V-7.6.0.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:business_intelligence:7.6.0.0.0:*:*:*:enterprise:*:*:*"}}}],"category":"product_name","name":"Oracle Business Intelligence Enterprise Edition"}],"category":"product_family","name":"Oracle Analytics"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Application Express Version 23.2","product":{"name":"Oracle Application Express Version 23.2","product_id":"P-1348V-23.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:application_express:23.2:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Application Express Version 24.1","product":{"name":"Oracle Application Express Version 24.1","product_id":"P-1348V-24.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:application_express:24.1:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Application Express"}],"category":"product_family","name":"Oracle Application Express"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Big Data Spatial and Graph Version 3.07","product":{"name":"Oracle Big Data Spatial and Graph Version 3.07","product_id":"P-11528V-3.07","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:big_data_spatial_and_graph:3.07:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Big Data Spatial and Graph"}],"category":"product_family","name":"Oracle Big Data Spatial and Graph"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Blockchain Platform Version 21.1.2","product":{"name":"Oracle Blockchain Platform Version 21.1.2","product_id":"P-13444V-21.1.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:blockchain_platform:21.1.2:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Blockchain Platform Version 24.1.3","product":{"name":"Oracle Blockchain Platform Version 24.1.3","product_id":"P-13444V-24.1.3","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:blockchain_platform:24.1.3:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Blockchain Platform"}],"category":"product_family","name":"Oracle Blockchain Platform"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Commerce Guided Search Version 11.3.2","product":{"name":"Oracle Commerce Guided Search Version 11.3.2","product_id":"P-9633V-11.3.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:commerce_guided_search:11.3.2:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Commerce Guided Search"}],"category":"product_family","name":"Oracle Commerce"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Automated Test Suite Version 24.2.0","product":{"name":"Oracle Communications Cloud Native Core Automated Test Suite Version 24.2.0","product_id":"P-14488V-24.2.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:24.2.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Automated Test Suite"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Binding Support Function Version 24.2.0","product":{"name":"Oracle Communications Cloud Native Core Binding Support Function Version 24.2.0","product_id":"P-14121V-24.2.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:24.2.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Binding Support Function Version 24.2.1","product":{"name":"Oracle Communications Cloud Native Core Binding Support Function Version 24.2.1","product_id":"P-14121V-24.2.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:24.2.1:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Binding Support Function"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Certificate Management Version 24.2.1","product":{"name":"Oracle Communications Cloud Native Core Certificate Management Version 24.2.1","product_id":"P-14868V-24.2.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_certificate_management:24.2.1:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Certificate Management"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Console Version 24.2.1","product":{"name":"Oracle Communications Cloud Native Core Console Version 24.2.1","product_id":"P-14250V-24.2.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_console:24.2.1:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Console"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core DBTier Version 24.1.0","product":{"name":"Oracle Communications Cloud Native Core DBTier Version 24.1.0","product_id":"P-14974V-24.1.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_dbtier:24.1.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Cloud Native Core DBTier Version 24.2.0","product":{"name":"Oracle Communications Cloud Native Core DBTier Version 24.2.0","product_id":"P-14974V-24.2.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_dbtier:24.2.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Cloud Native Core DBTier"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 24.2.0","product":{"name":"Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 24.2.0","product_id":"P-14125V-24.2.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:24.2.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 24.3.0","product":{"name":"Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 24.3.0","product_id":"P-14125V-24.3.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:24.3.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Network Function Cloud Native Environment"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Network Repository Function Version 24.2.2","product":{"name":"Oracle Communications Cloud Native Core Network Repository Function Version 24.2.2","product_id":"P-14118V-24.2.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:24.2.2:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Network Repository Function"},{"branches":[{"category":"product_version_range","name":"Oracle Communications Cloud Native Core Policy Version 24.2.0-24.2.2","product":{"name":"Oracle Communications Cloud Native Core Policy Version 24.2.0-24.2.2","product_id":"P-14277V-24.2.0-24.2.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_policy:24.2.0-24.2.2:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Policy"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 23.4.0","product":{"name":"Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 23.4.0","product_id":"P-14123V-23.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:23.4.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 24.2.0","product":{"name":"Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 24.2.0","product_id":"P-14123V-24.2.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:24.2.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 24.2.1","product":{"name":"Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 24.2.1","product_id":"P-14123V-24.2.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:24.2.1:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 24.2.2","product":{"name":"Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 24.2.2","product_id":"P-14123V-24.2.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:24.2.2:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Security Edge Protection Proxy"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Service Communication Proxy Version 24.2.0","product":{"name":"Oracle Communications Cloud Native Core Service Communication Proxy Version 24.2.0","product_id":"P-14117V-24.2.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:24.2.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Service Communication Proxy Version 24.3.0","product":{"name":"Oracle Communications Cloud Native Core Service Communication Proxy Version 24.3.0","product_id":"P-14117V-24.3.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:24.3.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Service Communication Proxy"},{"branches":[{"category":"product_version","name":"Oracle Communications Cloud Native Core Unified Data Repository Version 23.4.4","product":{"name":"Oracle Communications Cloud Native Core Unified Data Repository Version 23.4.4","product_id":"P-14119V-23.4.4","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:23.4.4:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Unified Data Repository Version 24.1.1","product":{"name":"Oracle Communications Cloud Native Core Unified Data Repository Version 24.1.1","product_id":"P-14119V-24.1.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:24.1.1:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Unified Data Repository Version 24.2.2","product":{"name":"Oracle Communications Cloud Native Core Unified Data Repository Version 24.2.2","product_id":"P-14119V-24.2.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:24.2.2:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Unified Data Repository Version 24.2.3","product":{"name":"Oracle Communications Cloud Native Core Unified Data Repository Version 24.2.3","product_id":"P-14119V-24.2.3","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:24.2.3:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Cloud Native Core Unified Data Repository Version 24.3.0","product":{"name":"Oracle Communications Cloud Native Core Unified Data Repository Version 24.3.0","product_id":"P-14119V-24.3.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:24.3.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Cloud Native Core Unified Data Repository"},{"branches":[{"category":"product_version","name":"Oracle Communications Converged Application Server Version 8.0","product":{"name":"Oracle Communications Converged Application Server Version 8.0","product_id":"P-5382V-8.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_converged_application_server:8.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Converged Application Server Version 8.1","product":{"name":"Oracle Communications Converged Application Server Version 8.1","product_id":"P-5382V-8.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_converged_application_server:8.1:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Converged Application Server"},{"branches":[{"category":"product_version","name":"Oracle Communications Diameter Signaling Router Version 8.2.3.0.0","product":{"name":"Oracle Communications Diameter Signaling Router Version 8.2.3.0.0","product_id":"P-10899V-8.2.3.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_diameter_signaling_router:8.2.3.0.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Diameter Signaling Router Version 8.6.0.4.0","product":{"name":"Oracle Communications Diameter Signaling Router Version 8.6.0.4.0","product_id":"P-10899V-8.6.0.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_diameter_signaling_router:8.6.0.4.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Diameter Signaling Router Version 9.0","product":{"name":"Oracle Communications Diameter Signaling Router Version 9.0","product_id":"P-10899V-9.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_diameter_signaling_router:9.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Diameter Signaling Router Version 9.0.0.0.0","product":{"name":"Oracle Communications Diameter Signaling Router Version 9.0.0.0.0","product_id":"P-10899V-9.0.0.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_diameter_signaling_router:9.0.0.0.0:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Communications Diameter Signaling Router Version 9.0.0.0.0-9.0.2.0.0","product":{"name":"Oracle Communications Diameter Signaling Router Version 9.0.0.0.0-9.0.2.0.0","product_id":"P-10899V-9.0.0.0.0-9.0.2.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_diameter_signaling_router:9.0.0.0.0-9.0.2.0.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Diameter Signaling Router"},{"branches":[{"category":"product_version","name":"Oracle Communications EAGLE Element Management System Version 47.0.0.0.0","product":{"name":"Oracle Communications EAGLE Element Management System Version 47.0.0.0.0","product_id":"P-11125V-47.0.0.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_eagle_element_management_system:47.0.0.0.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications EAGLE Element Management System"},{"branches":[{"category":"product_version","name":"Oracle Communications Network Analytics Data Director Version 24.1.0","product":{"name":"Oracle Communications Network Analytics Data Director Version 24.1.0","product_id":"P-14547V-24.1.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_network_analytics_data_director:24.1.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Network Analytics Data Director Version 24.2.0","product":{"name":"Oracle Communications Network Analytics Data Director Version 24.2.0","product_id":"P-14547V-24.2.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_network_analytics_data_director:24.2.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Network Analytics Data Director"},{"branches":[{"category":"product_version","name":"Oracle Communications Operations Monitor Version 5.1","product":{"name":"Oracle Communications Operations Monitor Version 5.1","product_id":"P-10761V-5.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_operations_monitor:5.1:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Operations Monitor Version 5.2","product":{"name":"Oracle Communications Operations Monitor Version 5.2","product_id":"P-10761V-5.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_operations_monitor:5.2:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Operations Monitor"},{"branches":[{"category":"product_version","name":"Oracle Communications Policy Management Version 15.0.0.0.0","product":{"name":"Oracle Communications Policy Management Version 15.0.0.0.0","product_id":"P-10900V-15.0.0.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_policy_management:15.0.0.0.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Policy Management"},{"branches":[{"category":"product_version","name":"Oracle Communications Session Border Controller Version 9.2.0","product":{"name":"Oracle Communications Session Border Controller Version 9.2.0","product_id":"P-10750V-9.2.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_session_border_controller:9.2.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Session Border Controller Version 9.3.0","product":{"name":"Oracle Communications Session Border Controller Version 9.3.0","product_id":"P-10750V-9.3.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_session_border_controller:9.3.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Session Border Controller"},{"branches":[{"category":"product_version","name":"Oracle Communications User Data Repository Version 12.11","product":{"name":"Oracle Communications User Data Repository Version 12.11","product_id":"P-11108V-12.11","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_user_data_repository:12.11:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications User Data Repository Version 14.0","product":{"name":"Oracle Communications User Data Repository Version 14.0","product_id":"P-11108V-14.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_user_data_repository:14.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications User Data Repository Version 15.0","product":{"name":"Oracle Communications User Data Repository Version 15.0","product_id":"P-11108V-15.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_user_data_repository:15.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications User Data Repository"},{"branches":[{"category":"product_version","name":"Oracle Enterprise Communications Broker Version 4.1.0","product":{"name":"Oracle Enterprise Communications Broker Version 4.1.0","product_id":"P-10758V-4.1.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:enterprise_communications_broker:4.1.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Enterprise Communications Broker Version 4.2.0","product":{"name":"Oracle Enterprise Communications Broker Version 4.2.0","product_id":"P-10758V-4.2.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:enterprise_communications_broker:4.2.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Enterprise Communications Broker"},{"branches":[{"category":"product_version","name":"Oracle Enterprise Session Border Controller Version 9.2.0","product":{"name":"Oracle Enterprise Session Border Controller Version 9.2.0","product_id":"P-10757V-9.2.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:enterprise_session_border_controller:9.2.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Enterprise Session Border Controller Version 9.3.0","product":{"name":"Oracle Enterprise Session Border Controller Version 9.3.0","product_id":"P-10757V-9.3.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:enterprise_session_border_controller:9.3.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Enterprise Session Border Controller"},{"branches":[{"category":"product_version_range","name":"Oracle SD-WAN Edge Version 9.1.1.0-9.1.1.8","product":{"name":"Oracle SD-WAN Edge Version 9.1.1.0-9.1.1.8","product_id":"P-13940V-9.1.1.0-9.1.1.8","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:sd-wan_edge:9.1.1.0-9.1.1.8:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle SD-WAN Edge Version 9.1.1.5-9.1.1.8","product":{"name":"Oracle SD-WAN Edge Version 9.1.1.5-9.1.1.8","product_id":"P-13940V-9.1.1.5-9.1.1.8","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:sd-wan_edge:9.1.1.5-9.1.1.8:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle SD-WAN Edge Version 9.1.1.5-9.1.1.9","product":{"name":"Oracle SD-WAN Edge Version 9.1.1.5-9.1.1.9","product_id":"P-13940V-9.1.1.5-9.1.1.9","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:sd-wan_edge:9.1.1.5-9.1.1.9:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle SD-WAN Edge"}],"category":"product_family","name":"Oracle Communications"},{"branches":[{"branches":[{"category":"product_version_range","name":"Oracle Communications BRM - Elastic Charging Engine Version 12.0.0.4-12.0.0.8","product":{"name":"Oracle Communications BRM - Elastic Charging Engine Version 12.0.0.4-12.0.0.8","product_id":"P-9742V-12.0.0.4-12.0.0.8","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:12.0.0.4-12.0.0.8:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications BRM - Elastic Charging Engine Version 15.0.0.0","product":{"name":"Oracle Communications BRM - Elastic Charging Engine Version 15.0.0.0","product_id":"P-9742V-15.0.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.0.0.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications BRM - Elastic Charging Engine Version 15.0.1.0","product":{"name":"Oracle Communications BRM - Elastic Charging Engine Version 15.0.1.0","product_id":"P-9742V-15.0.1.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.0.1.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications BRM - Elastic Charging Engine"},{"branches":[{"category":"product_version_range","name":"Oracle Communications Billing and Revenue Management(Billing Care) Version 12.0.0.4-12.0.0.8","product":{"name":"Oracle Communications Billing and Revenue Management(Billing Care) Version 12.0.0.4-12.0.0.8","product_id":"P-2136(Billing Care)V-12.0.0.4-12.0.0.8","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.4-12.0.0.8:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Communications Billing and Revenue Management(Platform) Version 12.0.0.4-12.0.0.8","product":{"name":"Oracle Communications Billing and Revenue Management(Platform) Version 12.0.0.4-12.0.0.8","product_id":"P-2136(Platform)V-12.0.0.4-12.0.0.8","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.4-12.0.0.8:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Communications Billing and Revenue Management(Billing Care) Version 15.0.0.0-15.0.0.1","product":{"name":"Oracle Communications Billing and Revenue Management(Billing Care) Version 15.0.0.0-15.0.0.1","product_id":"P-2136(Billing Care)V-15.0.0.0-15.0.0.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.0.0.0-15.0.0.1:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Communications Billing and Revenue Management(Platform) Version 15.0.0.0-15.0.0.1","product":{"name":"Oracle Communications Billing and Revenue Management(Platform) Version 15.0.0.0-15.0.0.1","product_id":"P-2136(Platform)V-15.0.0.0-15.0.0.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.0.0.0-15.0.0.1:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Billing and Revenue Management"},{"branches":[{"category":"product_version","name":"Oracle Communications Convergence Version 3.0.2.0.0","product":{"name":"Oracle Communications Convergence Version 3.0.2.0.0","product_id":"P-8501V-3.0.2.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_convergence:3.0.2.0.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Convergence Version 3.0.3.0.0","product":{"name":"Oracle Communications Convergence Version 3.0.3.0.0","product_id":"P-8501V-3.0.3.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_convergence:3.0.3.0.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Convergence Version 3.0.3.3.0","product":{"name":"Oracle Communications Convergence Version 3.0.3.3.0","product_id":"P-8501V-3.0.3.3.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_convergence:3.0.3.3.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Convergence"},{"branches":[{"category":"product_version","name":"Oracle Communications Messaging Server Version 8.1.0.26","product":{"name":"Oracle Communications Messaging Server Version 8.1.0.26","product_id":"P-8496V-8.1.0.26","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_messaging_server:8.1.0.26:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Messaging Server"},{"branches":[{"category":"product_version","name":"Oracle Communications Offline Mediation Controller Version 12.0.0.8","product":{"name":"Oracle Communications Offline Mediation Controller Version 12.0.0.8","product_id":"P-2269V-12.0.0.8","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.8:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Offline Mediation Controller Version 15.0.0.0","product":{"name":"Oracle Communications Offline Mediation Controller Version 15.0.0.0","product_id":"P-2269V-15.0.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_offline_mediation_controller:15.0.0.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Offline Mediation Controller Version 15.0.1.0","product":{"name":"Oracle Communications Offline Mediation Controller Version 15.0.1.0","product_id":"P-2269V-15.0.1.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_offline_mediation_controller:15.0.1.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Offline Mediation Controller"},{"branches":[{"category":"product_version","name":"Oracle Communications Order and Service Management Version 7.4.0","product":{"name":"Oracle Communications Order and Service Management Version 7.4.0","product_id":"P-2270V-7.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_order_and_service_management:7.4.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Order and Service Management Version 7.4.1","product":{"name":"Oracle Communications Order and Service Management Version 7.4.1","product_id":"P-2270V-7.4.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_order_and_service_management:7.4.1:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Order and Service Management Version 7.5.0","product":{"name":"Oracle Communications Order and Service Management Version 7.5.0","product_id":"P-2270V-7.5.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_order_and_service_management:7.5.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Order and Service Management"},{"branches":[{"category":"product_version","name":"Oracle Communications Service Catalog and Design Version 8.0.0.3","product":{"name":"Oracle Communications Service Catalog and Design Version 8.0.0.3","product_id":"P-2283V-8.0.0.3","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_service_catalog_and_design:8.0.0.3:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Service Catalog and Design Version 8.1.0.1","product":{"name":"Oracle Communications Service Catalog and Design Version 8.1.0.1","product_id":"P-2283V-8.1.0.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_service_catalog_and_design:8.1.0.1:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Service Catalog and Design"},{"branches":[{"category":"product_version_range","name":"Oracle Communications Unified Assurance Version 6.0.0-6.0.5","product":{"name":"Oracle Communications Unified Assurance Version 6.0.0-6.0.5","product_id":"P-14597V-6.0.0-6.0.5","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_unified_assurance:6.0.0-6.0.5:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Communications Unified Assurance Version 6.0.1-6.0.5","product":{"name":"Oracle Communications Unified Assurance Version 6.0.1-6.0.5","product_id":"P-14597V-6.0.1-6.0.5","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_unified_assurance:6.0.1-6.0.5:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Communications Unified Assurance Version 6.0.4-6.0.5","product":{"name":"Oracle Communications Unified Assurance Version 6.0.4-6.0.5","product_id":"P-14597V-6.0.4-6.0.5","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_unified_assurance:6.0.4-6.0.5:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Unified Assurance"},{"branches":[{"category":"product_version","name":"Oracle Communications Unified Inventory Management Version 7.4.1","product":{"name":"Oracle Communications Unified Inventory Management Version 7.4.1","product_id":"P-4516V-7.4.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.1:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Unified Inventory Management Version 7.4.2","product":{"name":"Oracle Communications Unified Inventory Management Version 7.4.2","product_id":"P-4516V-7.4.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.2:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Unified Inventory Management Version 7.5.1","product":{"name":"Oracle Communications Unified Inventory Management Version 7.5.1","product_id":"P-4516V-7.5.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_unified_inventory_management:7.5.1:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Communications Unified Inventory Management Version 7.6.0","product":{"name":"Oracle Communications Unified Inventory Management Version 7.6.0","product_id":"P-4516V-7.6.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:communications_unified_inventory_management:7.6.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Communications Unified Inventory Management"}],"category":"product_family","name":"Oracle Communications Applications"},{"branches":[{"branches":[{"category":"product_version_range","name":"Primavera Gateway Version 20.12.0-20.12.15","product":{"name":"Primavera Gateway Version 20.12.0-20.12.15","product_id":"P-10605V-20.12.0-20.12.15","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:primavera_gateway:20.12.0-20.12.15:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Primavera Gateway Version 21.12.0-21.12.13","product":{"name":"Primavera Gateway Version 21.12.0-21.12.13","product_id":"P-10605V-21.12.0-21.12.13","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:primavera_gateway:21.12.0-21.12.13:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Primavera Gateway"},{"branches":[{"category":"product_version_range","name":"Primavera P6 Enterprise Project Portfolio Management Version 20.12.1.0-20.12.21.5","product":{"name":"Primavera P6 Enterprise Project Portfolio Management Version 20.12.1.0-20.12.21.5","product_id":"P-5579V-20.12.1.0-20.12.21.5","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:20.12.1.0-20.12.21.5:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Primavera P6 Enterprise Project Portfolio Management Version 21.12.1.0-21.12.20.0","product":{"name":"Primavera P6 Enterprise Project Portfolio Management Version 21.12.1.0-21.12.20.0","product_id":"P-5579V-21.12.1.0-21.12.20.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:21.12.1.0-21.12.20.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Primavera P6 Enterprise Project Portfolio Management Version 22.12.1.0","product":{"name":"Primavera P6 Enterprise Project Portfolio Management Version 22.12.1.0","product_id":"P-5579V-22.12.1.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:22.12.1.0:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Primavera P6 Enterprise Project Portfolio Management Version 22.12.1.0-22.12.16.0","product":{"name":"Primavera P6 Enterprise Project Portfolio Management Version 22.12.1.0-22.12.16.0","product_id":"P-5579V-22.12.1.0-22.12.16.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:22.12.1.0-22.12.16.0:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Primavera P6 Enterprise Project Portfolio Management Version 23.12.1.0-23.12.10.0","product":{"name":"Primavera P6 Enterprise Project Portfolio Management Version 23.12.1.0-23.12.10.0","product_id":"P-5579V-23.12.1.0-23.12.10.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:23.12.1.0-23.12.10.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Primavera P6 Enterprise Project Portfolio Management"},{"branches":[{"category":"product_version_range","name":"Primavera Unifier Version 20.12.0-20.12.16","product":{"name":"Primavera Unifier Version 20.12.0-20.12.16","product_id":"P-10354V-20.12.0-20.12.16","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:primavera_unifier:20.12.0-20.12.16:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Primavera Unifier Version 21.12.0-21.12.17","product":{"name":"Primavera Unifier Version 21.12.0-21.12.17","product_id":"P-10354V-21.12.0-21.12.17","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:primavera_unifier:21.12.0-21.12.17:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Primavera Unifier Version 22.12.0-22.12.15","product":{"name":"Primavera Unifier Version 22.12.0-22.12.15","product_id":"P-10354V-22.12.0-22.12.15","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:primavera_unifier:22.12.0-22.12.15:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Primavera Unifier Version 23.12.0-23.12.12","product":{"name":"Primavera Unifier Version 23.12.0-23.12.12","product_id":"P-10354V-23.12.0-23.12.12","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:primavera_unifier:23.12.0-23.12.12:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Primavera Unifier Version 24.12.0","product":{"name":"Primavera Unifier Version 24.12.0","product_id":"P-10354V-24.12.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:primavera_unifier:24.12.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Primavera Unifier"}],"category":"product_family","name":"Oracle Construction and Engineering"},{"branches":[{"branches":[{"category":"product_version","name":"Database Migration Assistant for Unicode Version 19.1","product":{"name":"Database Migration Assistant for Unicode Version 19.1","product_id":"P-2550V-19.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:database_migration_assistant_for_unicode:19.1:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Database Migration Assistant for Unicode"},{"branches":[{"category":"product_version_range","name":"Oracle Database Server(Java VM) Version 19.3-19.25","product":{"name":"Oracle Database Server(Java VM) Version 19.3-19.25","product_id":"P-5(Java VM)V-19.3-19.25","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:database_-_java_vm:19.3-19.25:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Database Server(Oracle Database Data Mining) Version 19.3-19.25","product":{"name":"Oracle Database Server(Oracle Database Data Mining) Version 19.3-19.25","product_id":"P-5(Oracle Database Data Mining)V-19.3-19.25","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:database_-_data_mining:19.3-19.25:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Database Server(Oracle Database Grid) Version 19.3-19.25","product":{"name":"Oracle Database Server(Oracle Database Grid) Version 19.3-19.25","product_id":"P-5(Oracle Database Grid)V-19.3-19.25","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:database_-_grid:19.3-19.25:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Database Server(Oracle Spatial and Graph Mapviewer) Version 19.3-19.25","product":{"name":"Oracle Database Server(Oracle Spatial and Graph Mapviewer) Version 19.3-19.25","product_id":"P-619(Oracle Spatial and Graph Mapviewer)V-19.3-19.25","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:database_-_e_spatial_and_graph_mapviewer:19.3-19.25:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Database Server(Oracle Spatial and Graph Spatial Web Services) Version 19.3-19.25","product":{"name":"Oracle Database Server(Oracle Spatial and Graph Spatial Web Services) Version 19.3-19.25","product_id":"P-619(Oracle Spatial and Graph Spatial Web Services)V-19.3-19.25","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:database_-_e_spatial_and_graph_spatial_web_services:19.3-19.25:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Database Server(Java VM) Version 21.3-21.16","product":{"name":"Oracle Database Server(Java VM) Version 21.3-21.16","product_id":"P-5(Java VM)V-21.3-21.16","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:database_-_java_vm:21.3-21.16:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Database Server(Oracle Database Data Mining) Version 21.3-21.16","product":{"name":"Oracle Database Server(Oracle Database Data Mining) Version 21.3-21.16","product_id":"P-5(Oracle Database Data Mining)V-21.3-21.16","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:database_-_data_mining:21.3-21.16:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Database Server(Oracle Database Grid) Version 21.3-21.16","product":{"name":"Oracle Database Server(Oracle Database Grid) Version 21.3-21.16","product_id":"P-5(Oracle Database Grid)V-21.3-21.16","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:database_-_grid:21.3-21.16:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Database Server(Oracle Spatial and Graph Mapviewer) Version 21.3-21.16","product":{"name":"Oracle Database Server(Oracle Spatial and Graph Mapviewer) Version 21.3-21.16","product_id":"P-619(Oracle Spatial and Graph Mapviewer)V-21.3-21.16","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:database_-_e_spatial_and_graph_mapviewer:21.3-21.16:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Database Server(Oracle Spatial and Graph Spatial Web Services) Version 21.3-21.16","product":{"name":"Oracle Database Server(Oracle Spatial and Graph Spatial Web Services) Version 21.3-21.16","product_id":"P-619(Oracle Spatial and Graph Spatial Web Services)V-21.3-21.16","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:database_-_e_spatial_and_graph_spatial_web_services:21.3-21.16:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Database Server(Oracle Spatial and Graph) Version 21.3-21.16","product":{"name":"Oracle Database Server(Oracle Spatial and Graph) Version 21.3-21.16","product_id":"P-619(Oracle Spatial and Graph)V-21.3-21.16","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:database_-_e_spatial_and_graph:21.3-21.16:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Database Server(GraalVM Multilingual Engine) Version 21.4-21.16","product":{"name":"Oracle Database Server(GraalVM Multilingual Engine) Version 21.4-21.16","product_id":"P-5(GraalVM Multilingual Engine)V-21.4-21.16","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:database_-_graalvm_multilingual_engine:21.4-21.16:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Database Server(Oracle Database Workload Manager) Version 21.4-21.16","product":{"name":"Oracle Database Server(Oracle Database Workload Manager) Version 21.4-21.16","product_id":"P-5(Oracle Database Workload Manager)V-21.4-21.16","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:database_-_workload_manager:21.4-21.16:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Database Server(Java VM) Version 23.4-23.6","product":{"name":"Oracle Database Server(Java VM) Version 23.4-23.6","product_id":"P-5(Java VM)V-23.4-23.6","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:database_-_java_vm:23.4-23.6:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Database Server(GraalVM Multilingual Engine) Version 23.5-23.6","product":{"name":"Oracle Database Server(GraalVM Multilingual Engine) Version 23.5-23.6","product_id":"P-5(GraalVM Multilingual Engine)V-23.5-23.6","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:database_-_graalvm_multilingual_engine:23.5-23.6:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Database Server"},{"branches":[{"category":"product_version_range","name":"Oracle Graal Development Kit for Micronaut Version 23.5-23.6","product":{"name":"Oracle Graal Development Kit for Micronaut Version 23.5-23.6","product_id":"P-14599V-23.5-23.6","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:graal_development_kit_for_micronaut:23.5-23.6:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Graal Development Kit for Micronaut"}],"category":"product_family","name":"Oracle Database Server"},{"branches":[{"branches":[{"category":"product_version_range","name":"Oracle Advanced Outbound Telephony Version 12.2.3-12.2.10","product":{"name":"Oracle Advanced Outbound Telephony Version 12.2.3-12.2.10","product_id":"P-785V-12.2.3-12.2.10","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:advanced_outbound_telephony:12.2.3-12.2.10:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Advanced Outbound Telephony"},{"branches":[{"category":"product_version_range","name":"Oracle Customer Care Version 12.2.5-12.2.13","product":{"name":"Oracle Customer Care Version 12.2.5-12.2.13","product_id":"P-105V-12.2.5-12.2.13","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:customer_care:12.2.5-12.2.13:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Customer Care"},{"branches":[{"category":"product_version_range","name":"Oracle Project Foundation Version 12.2.3-12.2.13","product":{"name":"Oracle Project Foundation Version 12.2.3-12.2.13","product_id":"P-1293V-12.2.3-12.2.13","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:project_foundation:12.2.3-12.2.13:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Project Foundation"},{"branches":[{"category":"product_version_range","name":"Oracle Workflow Version 12.2.3-12.2.14","product":{"name":"Oracle Workflow Version 12.2.3-12.2.14","product_id":"P-174V-12.2.3-12.2.14","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:workflow:12.2.3-12.2.14:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Workflow"}],"category":"product_family","name":"Oracle E-Business Suite"},{"branches":[{"branches":[{"category":"product_version","name":"Enterprise Manager for MySQL Database Version 13.5.2.0.0","product":{"name":"Enterprise Manager for MySQL Database Version 13.5.2.0.0","product_id":"P-11166V-13.5.2.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:enterprise_manager_for_mysql_database:13.5.2.0.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Enterprise Manager for MySQL Database"},{"branches":[{"category":"product_version","name":"Oracle Application Testing Suite Version 13.3.0.1","product":{"name":"Oracle Application Testing Suite Version 13.3.0.1","product_id":"P-4622V-13.3.0.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Application Testing Suite"},{"branches":[{"category":"product_version","name":"Oracle Enterprise Manager Base Platform Version 13.5.0.0","product":{"name":"Oracle Enterprise Manager Base Platform Version 13.5.0.0","product_id":"P-1370V-13.5.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5.0.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Enterprise Manager Base Platform"}],"category":"product_family","name":"Oracle Enterprise Manager"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Essbase Version 21.7","product":{"name":"Oracle Essbase Version 21.7","product_id":"P-4379V-21.7","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:essbase:21.7:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Essbase"}],"category":"product_family","name":"Oracle Essbase"},{"branches":[{"branches":[{"category":"product_version_range","name":"Oracle Banking Corporate Lending Process Management Version 14.4.0.0.0-14.7.0.0.0","product":{"name":"Oracle Banking Corporate Lending Process Management Version 14.4.0.0.0-14.7.0.0.0","product_id":"P-13701V-14.4.0.0.0-14.7.0.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.4.0.0.0-14.7.0.0.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Banking Corporate Lending Process Management"},{"branches":[{"category":"product_version","name":"Oracle Banking Liquidity Management Version 14.7.5.0.0","product":{"name":"Oracle Banking Liquidity Management Version 14.7.5.0.0","product_id":"P-13304V-14.7.5.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:banking_liquidity_management:14.7.5.0.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Banking Liquidity Management"},{"branches":[{"category":"product_version_range","name":"Oracle Banking Origination Version 14.5.0.0.0-14.7.0.0.0","product":{"name":"Oracle Banking Origination Version 14.5.0.0.0-14.7.0.0.0","product_id":"P-14325V-14.5.0.0.0-14.7.0.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:banking_origination:14.5.0.0.0-14.7.0.0.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Banking Origination"},{"branches":[{"category":"product_version","name":"Oracle Financial Services Analytical Applications Infrastructure Version 8.0.7.8","product":{"name":"Oracle Financial Services Analytical Applications Infrastructure Version 8.0.7.8","product_id":"P-5680V-8.0.7.8","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.7.8:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Financial Services Analytical Applications Infrastructure Version 8.0.8.6","product":{"name":"Oracle Financial Services Analytical Applications Infrastructure Version 8.0.8.6","product_id":"P-5680V-8.0.8.6","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.8.6:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2.5","product":{"name":"Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2.5","product_id":"P-5680V-8.1.2.5","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.2.5:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Financial Services Analytical Applications Infrastructure"},{"branches":[{"category":"product_version","name":"Oracle Financial Services Behavior Detection Platform Version 8.0.8.1","product":{"name":"Oracle Financial Services Behavior Detection Platform Version 8.0.8.1","product_id":"P-9190V-8.0.8.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.0.8.1:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Financial Services Behavior Detection Platform Version 8.1.2.7","product":{"name":"Oracle Financial Services Behavior Detection Platform Version 8.1.2.7","product_id":"P-9190V-8.1.2.7","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.2.7:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Financial Services Behavior Detection Platform Version 8.1.2.8","product":{"name":"Oracle Financial Services Behavior Detection Platform Version 8.1.2.8","product_id":"P-9190V-8.1.2.8","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.2.8:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Financial Services Behavior Detection Platform"},{"branches":[{"category":"product_version","name":"Oracle Financial Services Compliance Studio Version 8.1.2.5","product":{"name":"Oracle Financial Services Compliance Studio Version 8.1.2.5","product_id":"P-14392V-8.1.2.5","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:financial_services_compliance_studio:8.1.2.5:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Financial Services Compliance Studio Version 8.1.2.6","product":{"name":"Oracle Financial Services Compliance Studio Version 8.1.2.6","product_id":"P-14392V-8.1.2.6","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:financial_services_compliance_studio:8.1.2.6:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Financial Services Compliance Studio"},{"branches":[{"category":"product_version","name":"Oracle Financial Services Enterprise Case Management Version 8.0.8.2","product":{"name":"Oracle Financial Services Enterprise Case Management Version 8.0.8.2","product_id":"P-13545V-8.0.8.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.0.8.2:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Financial Services Enterprise Case Management Version 8.1.2.7","product":{"name":"Oracle Financial Services Enterprise Case Management Version 8.1.2.7","product_id":"P-13545V-8.1.2.7","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.2.7:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Financial Services Enterprise Case Management Version 8.1.2.8","product":{"name":"Oracle Financial Services Enterprise Case Management Version 8.1.2.8","product_id":"P-13545V-8.1.2.8","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.2.8:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Financial Services Enterprise Case Management"},{"branches":[{"category":"product_version","name":"Oracle Financial Services Model Management and Governance Version 8.1.2.6","product":{"name":"Oracle Financial Services Model Management and Governance Version 8.1.2.6","product_id":"P-14276V-8.1.2.6","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:financial_services_model_management_and_governance:8.1.2.6:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Financial Services Model Management and Governance Version 8.1.2.7","product":{"name":"Oracle Financial Services Model Management and Governance Version 8.1.2.7","product_id":"P-14276V-8.1.2.7","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:financial_services_model_management_and_governance:8.1.2.7:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Financial Services Model Management and Governance Version 8.1.3.0","product":{"name":"Oracle Financial Services Model Management and Governance Version 8.1.3.0","product_id":"P-14276V-8.1.3.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:financial_services_model_management_and_governance:8.1.3.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Financial Services Model Management and Governance"},{"branches":[{"category":"product_version","name":"Oracle Financial Services Regulatory Reporting Version 8.1.2.7","product":{"name":"Oracle Financial Services Regulatory Reporting Version 8.1.2.7","product_id":"P-9142V-8.1.2.7","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:financial_services_regulatory_reporting:8.1.2.7:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Financial Services Regulatory Reporting Version 8.1.2.8","product":{"name":"Oracle Financial Services Regulatory Reporting Version 8.1.2.8","product_id":"P-9142V-8.1.2.8","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:financial_services_regulatory_reporting:8.1.2.8:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Financial Services Regulatory Reporting"},{"branches":[{"category":"product_version_range","name":"Oracle Financial Services Revenue Management and Billing Version 2.9.0.0.0-7.0.0.0.0","product":{"name":"Oracle Financial Services Revenue Management and Billing Version 2.9.0.0.0-7.0.0.0.0","product_id":"P-5322V-2.9.0.0.0-7.0.0.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:financial_services_revenue_management_and_billing:2.9.0.0.0-7.0.0.0.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Financial Services Revenue Management and Billing"},{"branches":[{"category":"product_version","name":"Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition Version 8.0.8","product":{"name":"Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition Version 8.0.8","product_id":"P-13789V-8.0.8","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:financial_services_trade-based_anti_money_laundering:8.0.8:*:*:*:enterprise:*:*:*"}}}],"category":"product_name","name":"Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition"}],"category":"product_family","name":"Oracle Financial Services Applications"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Business Activity Monitoring Version 12.2.1.4.0","product":{"name":"Oracle Business Activity Monitoring Version 12.2.1.4.0","product_id":"P-1675V-12.2.1.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:business_activity_monitoring:12.2.1.4.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Business Activity Monitoring"},{"branches":[{"category":"product_version","name":"Oracle Business Process Management Suite Version 12.2.1.4.0","product":{"name":"Oracle Business Process Management Suite Version 12.2.1.4.0","product_id":"P-5325V-12.2.1.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Business Process Management Suite"},{"branches":[{"category":"product_version","name":"Oracle Coherence Version 12.2.1.4.0","product":{"name":"Oracle Coherence Version 12.2.1.4.0","product_id":"P-2545V-12.2.1.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Coherence Version 14.1.1.0.0","product":{"name":"Oracle Coherence Version 14.1.1.0.0","product_id":"P-2545V-14.1.1.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Coherence"},{"branches":[{"category":"product_version","name":"Oracle Fusion Middleware MapViewer Version 12.2.1.4.0","product":{"name":"Oracle Fusion Middleware MapViewer Version 12.2.1.4.0","product_id":"P-1215V-12.2.1.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:fusion_middleware_mapviewer:12.2.1.4.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Fusion Middleware MapViewer"},{"branches":[{"category":"product_version","name":"Oracle HTTP Server(Core) Version 12.2.1.4.0","product":{"name":"Oracle HTTP Server(Core) Version 12.2.1.4.0","product_id":"P-1042(Core)V-12.2.1.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle HTTP Server(Mod_Security) Version 12.2.1.4.0","product":{"name":"Oracle HTTP Server(Mod_Security) Version 12.2.1.4.0","product_id":"P-1042(Mod_Security)V-12.2.1.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle HTTP Server(Mod_rewrite, Core) Version 12.2.1.4.0","product":{"name":"Oracle HTTP Server(Mod_rewrite, Core) Version 12.2.1.4.0","product_id":"P-1042(Mod_rewrite, Core)V-12.2.1.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle HTTP Server"},{"branches":[{"category":"product_version","name":"Oracle Identity Manager Version 12.2.1.4.0","product":{"name":"Oracle Identity Manager Version 12.2.1.4.0","product_id":"P-1980V-12.2.1.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Identity Manager"},{"branches":[{"category":"product_version","name":"Oracle Managed File Transfer Version 12.2.1.4.0","product":{"name":"Oracle Managed File Transfer Version 12.2.1.4.0","product_id":"P-10198V-12.2.1.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:managed_file_transfer:12.2.1.4.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Managed File Transfer"},{"branches":[{"category":"product_version","name":"Oracle Middleware Common Libraries and Tools Version 12.2.1.4.0","product":{"name":"Oracle Middleware Common Libraries and Tools Version 12.2.1.4.0","product_id":"P-4647V-12.2.1.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.4.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Middleware Common Libraries and Tools"},{"branches":[{"category":"product_version","name":"Oracle Outside In Technology Version 8.5.7","product":{"name":"Oracle Outside In Technology Version 8.5.7","product_id":"P-2276V-8.5.7","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:outside_in_technology:8.5.7:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Outside In Technology"},{"branches":[{"category":"product_version","name":"Oracle Security Service Version 12.2.1.4.0","product":{"name":"Oracle Security Service Version 12.2.1.4.0","product_id":"P-991V-12.2.1.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:security_service:12.2.1.4.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Security Service"},{"branches":[{"category":"product_version","name":"Oracle WebCenter Portal Version 12.2.1.4.0","product":{"name":"Oracle WebCenter Portal Version 12.2.1.4.0","product_id":"P-1696V-12.2.1.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle WebCenter Portal"},{"branches":[{"category":"product_version","name":"Oracle WebLogic Server Version 12.2.1.4.0","product":{"name":"Oracle WebLogic Server Version 12.2.1.4.0","product_id":"P-5242V-12.2.1.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle WebLogic Server Version 14.1.1.0.0","product":{"name":"Oracle WebLogic Server Version 14.1.1.0.0","product_id":"P-5242V-14.1.1.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle WebLogic Server Version 14.1.2.0.0","product":{"name":"Oracle WebLogic Server Version 14.1.2.0.0","product_id":"P-5242V-14.1.2.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle WebLogic Server"}],"category":"product_family","name":"Oracle Fusion Middleware"},{"branches":[{"branches":[{"category":"product_version_range","name":"Oracle GoldenGate Version 19.1.0.0.0-19.25.0.0.241015","product":{"name":"Oracle GoldenGate Version 19.1.0.0.0-19.25.0.0.241015","product_id":"P-5757V-19.1.0.0.0-19.25.0.0.241015","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:goldengate:19.1.0.0.0-19.25.0.0.241015:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle GoldenGate Version 21.3-21.16","product":{"name":"Oracle GoldenGate Version 21.3-21.16","product_id":"P-5757V-21.3-21.16","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:goldengate:21.3-21.16:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle GoldenGate Version 23.4-23.6","product":{"name":"Oracle GoldenGate Version 23.4-23.6","product_id":"P-5757V-23.4-23.6","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:goldengate:23.4-23.6:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle GoldenGate"},{"branches":[{"category":"product_version_range","name":"Oracle GoldenGate Big Data and Application Adapters Version 19.1.0.0.0-19.1.0.0.18","product":{"name":"Oracle GoldenGate Big Data and Application Adapters Version 19.1.0.0.0-19.1.0.0.18","product_id":"P-5760V-19.1.0.0.0-19.1.0.0.18","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:goldengate_big_data_and_application_adapters:19.1.0.0.0-19.1.0.0.18:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle GoldenGate Big Data and Application Adapters Version 21.3.0.0.0-21.16.0.0.0","product":{"name":"Oracle GoldenGate Big Data and Application Adapters Version 21.3.0.0.0-21.16.0.0.0","product_id":"P-5760V-21.3.0.0.0-21.16.0.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:goldengate_big_data_and_application_adapters:21.3.0.0.0-21.16.0.0.0:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle GoldenGate Big Data and Application Adapters Version 23.4-23.6","product":{"name":"Oracle GoldenGate Big Data and Application Adapters Version 23.4-23.6","product_id":"P-5760V-23.4-23.6","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:goldengate_big_data_and_application_adapters:23.4-23.6:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle GoldenGate Big Data and Application Adapters"},{"branches":[{"category":"product_version","name":"Oracle GoldenGate Studio Version 12.2.0.4.0","product":{"name":"Oracle GoldenGate Studio Version 12.2.0.4.0","product_id":"P-10945V-12.2.0.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:goldengate_studio:12.2.0.4.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle GoldenGate Studio"},{"branches":[{"category":"product_version_range","name":"Oracle GoldenGate Veridata Version 12.2.1.4.0-12.2.1.4.240430","product":{"name":"Oracle GoldenGate Veridata Version 12.2.1.4.0-12.2.1.4.240430","product_id":"P-5758V-12.2.1.4.0-12.2.1.4.240430","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:goldengate_veridata:12.2.1.4.0-12.2.1.4.240430:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle GoldenGate Veridata"}],"category":"product_family","name":"Oracle GoldenGate"},{"branches":[{"branches":[{"category":"product_version","name":"Graph Server and Client Version 23.4.4","product":{"name":"Graph Server and Client Version 23.4.4","product_id":"P-14069V-23.4.4","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:graph_server_and_client:23.4.4:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Graph Server and Client Version 24.4.0","product":{"name":"Graph Server and Client Version 24.4.0","product_id":"P-14069V-24.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:graph_server_and_client:24.4.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Graph Server and Client"}],"category":"product_family","name":"Oracle Graph Server and Client"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Life Sciences Argus Safety Version 8.2.3","product":{"name":"Oracle Life Sciences Argus Safety Version 8.2.3","product_id":"P-5710V-8.2.3","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:life_sciences_argus_safety:8.2.3:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Life Sciences Argus Safety"},{"branches":[{"category":"product_version_range","name":"Oracle Life Sciences Empirica Signal Version Prior to 9.2.3","product":{"name":"Oracle Life Sciences Empirica Signal Version Prior to 9.2.3","product_id":"P-9646V-Prior to 9.2.3","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:life_sciences_empirica_signal:prior_to_9.2.3:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Life Sciences Empirica Signal"}],"category":"product_family","name":"Oracle Health Sciences Applications"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Hospitality OPERA 5 Version 5.6.19.20","product":{"name":"Oracle Hospitality OPERA 5 Version 5.6.19.20","product_id":"P-11580V-5.6.19.20","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:hospitality_opera_5:5.6.19.20:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Hospitality OPERA 5 Version 5.6.25.8","product":{"name":"Oracle Hospitality OPERA 5 Version 5.6.25.8","product_id":"P-11580V-5.6.25.8","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:hospitality_opera_5:5.6.25.8:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Hospitality OPERA 5 Version 5.6.26.6","product":{"name":"Oracle Hospitality OPERA 5 Version 5.6.26.6","product_id":"P-11580V-5.6.26.6","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:hospitality_opera_5:5.6.26.6:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Hospitality OPERA 5 Version 5.6.27.1","product":{"name":"Oracle Hospitality OPERA 5 Version 5.6.27.1","product_id":"P-11580V-5.6.27.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:hospitality_opera_5:5.6.27.1:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Hospitality OPERA 5"}],"category":"product_family","name":"Oracle Hospitality Applications"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Hyperion Data Relationship Management Version 11.2.19.0.000","product":{"name":"Oracle Hyperion Data Relationship Management Version 11.2.19.0.000","product_id":"P-4375V-11.2.19.0.000","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.19.0.000:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Hyperion Data Relationship Management"}],"category":"product_family","name":"Oracle Hyperion"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Documaker Version 12.7.1","product":{"name":"Oracle Documaker Version 12.7.1","product_id":"P-5477V-12.7.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:documaker:12.7.1:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Documaker Version 12.7.2","product":{"name":"Oracle Documaker Version 12.7.2","product_id":"P-5477V-12.7.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:documaker:12.7.2:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Documaker Version 13.0.0","product":{"name":"Oracle Documaker Version 13.0.0","product_id":"P-5477V-13.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:documaker:13.0.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Documaker"}],"category":"product_family","name":"Oracle Insurance Applications"},{"branches":[{"branches":[{"category":"product_version_range","name":"JD Edwards EnterpriseOne Orchestrator Version Prior to 9.2.9.0","product":{"name":"JD Edwards EnterpriseOne Orchestrator Version Prior to 9.2.9.0","product_id":"P-11681V-Prior to 9.2.9.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:prior_to_9.2.9.0:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"JD Edwards EnterpriseOne Orchestrator Version Prior to 9.2.9.2","product":{"name":"JD Edwards EnterpriseOne Orchestrator Version Prior to 9.2.9.2","product_id":"P-11681V-Prior to 9.2.9.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:jd_edwards_enterpriseone_orchestrator:prior_to_9.2.9.2:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"JD Edwards EnterpriseOne Orchestrator"},{"branches":[{"category":"product_version_range","name":"JD Edwards EnterpriseOne Tools Version Prior to 9.2.9.0","product":{"name":"JD Edwards EnterpriseOne Tools Version Prior to 9.2.9.0","product_id":"P-4781V-Prior to 9.2.9.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:prior_to_9.2.9.0:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"JD Edwards EnterpriseOne Tools(Web Runtime SEC) Version Prior to 9.2.9.2","product":{"name":"JD Edwards EnterpriseOne Tools(Web Runtime SEC) Version Prior to 9.2.9.2","product_id":"P-4781(Web Runtime SEC)V-Prior to 9.2.9.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:prior_to_9.2.9.2:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"JD Edwards EnterpriseOne Tools Version Prior to 9.2.9.2","product":{"name":"JD Edwards EnterpriseOne Tools Version Prior to 9.2.9.2","product_id":"P-4781V-Prior to 9.2.9.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:prior_to_9.2.9.2:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"JD Edwards EnterpriseOne Tools"}],"category":"product_family","name":"Oracle JD Edwards"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Java SE Version Oracle GraalVM Enterprise Edition:20.3.16","product":{"name":"Oracle Java SE Version Oracle GraalVM Enterprise Edition:20.3.16","product_id":"P-856V-Oracle GraalVM Enterprise Edition:20.3.16","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:graalvm:20.3.16:*:*:*:enterprise:*:*:*"}}},{"category":"product_version","name":"Oracle Java SE Version Oracle GraalVM Enterprise Edition:21.3.12","product":{"name":"Oracle Java SE Version Oracle GraalVM Enterprise Edition:21.3.12","product_id":"P-856V-Oracle GraalVM Enterprise Edition:21.3.12","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:graalvm:21.3.12:*:*:*:enterprise:*:*:*"}}},{"category":"product_version","name":"Oracle Java SE Version Oracle GraalVM for JDK:17.0.13","product":{"name":"Oracle Java SE Version Oracle GraalVM for JDK:17.0.13","product_id":"P-856V-Oracle GraalVM for JDK:17.0.13","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:graalvm_for_jdk:17.0.13:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Java SE Version Oracle GraalVM for JDK:21.0.5","product":{"name":"Oracle Java SE Version Oracle GraalVM for JDK:21.0.5","product_id":"P-856V-Oracle GraalVM for JDK:21.0.5","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:graalvm_for_jdk:21.0.5:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Java SE Version Oracle GraalVM for JDK:23.0.1","product":{"name":"Oracle Java SE Version Oracle GraalVM for JDK:23.0.1","product_id":"P-856V-Oracle GraalVM for JDK:23.0.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:graalvm_for_jdk:23.0.1:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Java SE Version Oracle Java SE:11.0.25","product":{"name":"Oracle Java SE Version Oracle Java SE:11.0.25","product_id":"P-856V-Oracle Java SE:11.0.25","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:java_se:11.0.25:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Java SE Version Oracle Java SE:17.0.13","product":{"name":"Oracle Java SE Version Oracle Java SE:17.0.13","product_id":"P-856V-Oracle Java SE:17.0.13","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:java_se:17.0.13:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Java SE Version Oracle Java SE:21.0.5","product":{"name":"Oracle Java SE Version Oracle Java SE:21.0.5","product_id":"P-856V-Oracle Java SE:21.0.5","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:java_se:21.0.5:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Java SE Version Oracle Java SE:23.0.1","product":{"name":"Oracle Java SE Version Oracle Java SE:23.0.1","product_id":"P-856V-Oracle Java SE:23.0.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:java_se:23.0.1:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Java SE Version Oracle Java SE:8u431","product":{"name":"Oracle Java SE Version Oracle Java SE:8u431","product_id":"P-856V-Oracle Java SE:8u431","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:java_se:8u431:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Java SE Version Oracle Java SE:8u431-perf","product":{"name":"Oracle Java SE Version Oracle Java SE:8u431-perf","product_id":"P-856V-Oracle Java SE:8u431-perf","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:java_se:8u431:*:*:*:enterprise_performance:*:*:*"}}}],"category":"product_name","name":"Oracle Java SE"}],"category":"product_family","name":"Oracle Java SE"},{"branches":[{"branches":[{"category":"product_version_range","name":"MySQL Cluster Version 7.6.32 and prior","product":{"name":"MySQL Cluster Version 7.6.32 and prior","product_id":"P-8479V-7.6.32 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_cluster:7.6.32_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Cluster Version 8.0.40 and prior","product":{"name":"MySQL Cluster Version 8.0.40 and prior","product_id":"P-8479V-8.0.40 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_cluster:8.0.40_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Cluster Version 8.4.3 and prior","product":{"name":"MySQL Cluster Version 8.4.3 and prior","product_id":"P-8479V-8.4.3 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_cluster:8.4.3_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Cluster Version 9.1.0 and prior","product":{"name":"MySQL Cluster Version 9.1.0 and prior","product_id":"P-8479V-9.1.0 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_cluster:9.1.0_and_prior:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"MySQL Cluster"},{"branches":[{"category":"product_version_range","name":"MySQL Connectors(Connector/Python) Version 9.1.0 and prior","product":{"name":"MySQL Connectors(Connector/Python) Version 9.1.0 and prior","product_id":"P-8576(Connector/Python)V-9.1.0 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_connector\\/python:9.1.0_and_prior:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"MySQL Connectors"},{"branches":[{"category":"product_version_range","name":"MySQL Enterprise Backup Version 8.0.40 and prior","product":{"name":"MySQL Enterprise Backup Version 8.0.40 and prior","product_id":"P-4629V-8.0.40 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_enterprise_backup:8.0.40_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Enterprise Backup Version 8.4.3 and prior","product":{"name":"MySQL Enterprise Backup Version 8.4.3 and prior","product_id":"P-4629V-8.4.3 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_enterprise_backup:8.4.3_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Enterprise Backup Version 9.1.0 and prior","product":{"name":"MySQL Enterprise Backup Version 9.1.0 and prior","product_id":"P-4629V-9.1.0 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_enterprise_backup:9.1.0_and_prior:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"MySQL Enterprise Backup"},{"branches":[{"category":"product_version_range","name":"MySQL Enterprise Firewall(Firewall) Version 8.0.40 and prior","product":{"name":"MySQL Enterprise Firewall(Firewall) Version 8.0.40 and prior","product_id":"P-8478(Firewall)V-8.0.40 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_enterprise_firewall:8.0.40_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Enterprise Firewall(Firewall) Version 8.4.3 and prior","product":{"name":"MySQL Enterprise Firewall(Firewall) Version 8.4.3 and prior","product_id":"P-8478(Firewall)V-8.4.3 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_enterprise_firewall:8.4.3_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Enterprise Firewall(Firewall) Version 9.1.0 and prior","product":{"name":"MySQL Enterprise Firewall(Firewall) Version 9.1.0 and prior","product_id":"P-8478(Firewall)V-9.1.0 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_enterprise_firewall:9.1.0_and_prior:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"MySQL Enterprise Firewall"},{"branches":[{"category":"product_version_range","name":"MySQL Server(Server: Optimizer) Version 8.0.36 and prior","product":{"name":"MySQL Server(Server: Optimizer) Version 8.0.36 and prior","product_id":"P-8478(Server: Optimizer)V-8.0.36 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.0.36_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: DDL) Version 8.0.39 and prior","product":{"name":"MySQL Server(Server: DDL) Version 8.0.39 and prior","product_id":"P-8478(Server: DDL)V-8.0.39 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.0.39_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Optimizer) Version 8.0.39 and prior","product":{"name":"MySQL Server(Server: Optimizer) Version 8.0.39 and prior","product_id":"P-8478(Server: Optimizer)V-8.0.39 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.0.39_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Packaging) Version 8.0.39 and prior","product":{"name":"MySQL Server(Server: Packaging) Version 8.0.39 and prior","product_id":"P-8478(Server: Packaging)V-8.0.39 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.0.39_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Performance Schema) Version 8.0.39 and prior","product":{"name":"MySQL Server(Server: Performance Schema) Version 8.0.39 and prior","product_id":"P-8478(Server: Performance Schema)V-8.0.39 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.0.39_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Security: Privileges) Version 8.0.39 and prior","product":{"name":"MySQL Server(Server: Security: Privileges) Version 8.0.39 and prior","product_id":"P-8478(Server: Security: Privileges)V-8.0.39 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.0.39_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Thread Pooling) Version 8.0.39 and prior","product":{"name":"MySQL Server(Server: Thread Pooling) Version 8.0.39 and prior","product_id":"P-8478(Server: Thread Pooling)V-8.0.39 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.0.39_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(InnoDB) Version 8.0.40 and prior","product":{"name":"MySQL Server(InnoDB) Version 8.0.40 and prior","product_id":"P-8478(InnoDB)V-8.0.40 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.0.40_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Components Services) Version 8.0.40 and prior","product":{"name":"MySQL Server(Server: Components Services) Version 8.0.40 and prior","product_id":"P-8478(Server: Components Services)V-8.0.40 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.0.40_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Information Schema) Version 8.0.40 and prior","product":{"name":"MySQL Server(Server: Information Schema) Version 8.0.40 and prior","product_id":"P-8478(Server: Information Schema)V-8.0.40 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.0.40_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Optimizer) Version 8.0.40 and prior","product":{"name":"MySQL Server(Server: Optimizer) Version 8.0.40 and prior","product_id":"P-8478(Server: Optimizer)V-8.0.40 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.0.40_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Options) Version 8.0.40 and prior","product":{"name":"MySQL Server(Server: Options) Version 8.0.40 and prior","product_id":"P-8478(Server: Options)V-8.0.40 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.0.40_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Packaging) Version 8.0.40 and prior","product":{"name":"MySQL Server(Server: Packaging) Version 8.0.40 and prior","product_id":"P-8478(Server: Packaging)V-8.0.40 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.0.40_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Parser) Version 8.0.40 and prior","product":{"name":"MySQL Server(Server: Parser) Version 8.0.40 and prior","product_id":"P-8478(Server: Parser)V-8.0.40 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.0.40_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Security: Privileges) Version 8.0.40 and prior","product":{"name":"MySQL Server(Server: Security: Privileges) Version 8.0.40 and prior","product_id":"P-8478(Server: Security: Privileges)V-8.0.40 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.0.40_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"MySQL Server(Server: Optimizer) Version 8.4.0","product":{"name":"MySQL Server(Server: Optimizer) Version 8.4.0","product_id":"P-8478(Server: Optimizer)V-8.4.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.4.0:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: DDL) Version 8.4.2 and prior","product":{"name":"MySQL Server(Server: DDL) Version 8.4.2 and prior","product_id":"P-8478(Server: DDL)V-8.4.2 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.4.2_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Optimizer) Version 8.4.2 and prior","product":{"name":"MySQL Server(Server: Optimizer) Version 8.4.2 and prior","product_id":"P-8478(Server: Optimizer)V-8.4.2 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.4.2_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Packaging) Version 8.4.2 and prior","product":{"name":"MySQL Server(Server: Packaging) Version 8.4.2 and prior","product_id":"P-8478(Server: Packaging)V-8.4.2 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.4.2_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Performance Schema) Version 8.4.2 and prior","product":{"name":"MySQL Server(Server: Performance Schema) Version 8.4.2 and prior","product_id":"P-8478(Server: Performance Schema)V-8.4.2 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.4.2_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Security: Privileges) Version 8.4.2 and prior","product":{"name":"MySQL Server(Server: Security: Privileges) Version 8.4.2 and prior","product_id":"P-8478(Server: Security: Privileges)V-8.4.2 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.4.2_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Thread Pooling) Version 8.4.2 and prior","product":{"name":"MySQL Server(Server: Thread Pooling) Version 8.4.2 and prior","product_id":"P-8478(Server: Thread Pooling)V-8.4.2 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.4.2_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(InnoDB) Version 8.4.3 and prior","product":{"name":"MySQL Server(InnoDB) Version 8.4.3 and prior","product_id":"P-8478(InnoDB)V-8.4.3 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.4.3_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Components Services) Version 8.4.3 and prior","product":{"name":"MySQL Server(Server: Components Services) Version 8.4.3 and prior","product_id":"P-8478(Server: Components Services)V-8.4.3 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.4.3_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: DDL) Version 8.4.3 and prior","product":{"name":"MySQL Server(Server: DDL) Version 8.4.3 and prior","product_id":"P-8478(Server: DDL)V-8.4.3 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.4.3_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Information Schema) Version 8.4.3 and prior","product":{"name":"MySQL Server(Server: Information Schema) Version 8.4.3 and prior","product_id":"P-8478(Server: Information Schema)V-8.4.3 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.4.3_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Optimizer) Version 8.4.3 and prior","product":{"name":"MySQL Server(Server: Optimizer) Version 8.4.3 and prior","product_id":"P-8478(Server: Optimizer)V-8.4.3 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.4.3_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Options) Version 8.4.3 and prior","product":{"name":"MySQL Server(Server: Options) Version 8.4.3 and prior","product_id":"P-8478(Server: Options)V-8.4.3 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.4.3_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Packaging) Version 8.4.3 and prior","product":{"name":"MySQL Server(Server: Packaging) Version 8.4.3 and prior","product_id":"P-8478(Server: Packaging)V-8.4.3 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.4.3_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Parser) Version 8.4.3 and prior","product":{"name":"MySQL Server(Server: Parser) Version 8.4.3 and prior","product_id":"P-8478(Server: Parser)V-8.4.3 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.4.3_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Security: Privileges) Version 8.4.3 and prior","product":{"name":"MySQL Server(Server: Security: Privileges) Version 8.4.3 and prior","product_id":"P-8478(Server: Security: Privileges)V-8.4.3 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:8.4.3_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: DDL) Version 9.0.1 and prior","product":{"name":"MySQL Server(Server: DDL) Version 9.0.1 and prior","product_id":"P-8478(Server: DDL)V-9.0.1 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:9.0.1_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Optimizer) Version 9.0.1 and prior","product":{"name":"MySQL Server(Server: Optimizer) Version 9.0.1 and prior","product_id":"P-8478(Server: Optimizer)V-9.0.1 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:9.0.1_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Packaging) Version 9.0.1 and prior","product":{"name":"MySQL Server(Server: Packaging) Version 9.0.1 and prior","product_id":"P-8478(Server: Packaging)V-9.0.1 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:9.0.1_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Performance Schema) Version 9.0.1 and prior","product":{"name":"MySQL Server(Server: Performance Schema) Version 9.0.1 and prior","product_id":"P-8478(Server: Performance Schema)V-9.0.1 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:9.0.1_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Security: Privileges) Version 9.0.1 and prior","product":{"name":"MySQL Server(Server: Security: Privileges) Version 9.0.1 and prior","product_id":"P-8478(Server: Security: Privileges)V-9.0.1 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:9.0.1_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Thread Pooling) Version 9.0.1 and prior","product":{"name":"MySQL Server(Server: Thread Pooling) Version 9.0.1 and prior","product_id":"P-8478(Server: Thread Pooling)V-9.0.1 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:9.0.1_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(InnoDB) Version 9.1.0 and prior","product":{"name":"MySQL Server(InnoDB) Version 9.1.0 and prior","product_id":"P-8478(InnoDB)V-9.1.0 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:9.1.0_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Components Services) Version 9.1.0 and prior","product":{"name":"MySQL Server(Server: Components Services) Version 9.1.0 and prior","product_id":"P-8478(Server: Components Services)V-9.1.0 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:9.1.0_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: DDL) Version 9.1.0 and prior","product":{"name":"MySQL Server(Server: DDL) Version 9.1.0 and prior","product_id":"P-8478(Server: DDL)V-9.1.0 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:9.1.0_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Information Schema) Version 9.1.0 and prior","product":{"name":"MySQL Server(Server: Information Schema) Version 9.1.0 and prior","product_id":"P-8478(Server: Information Schema)V-9.1.0 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:9.1.0_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Optimizer) Version 9.1.0 and prior","product":{"name":"MySQL Server(Server: Optimizer) Version 9.1.0 and prior","product_id":"P-8478(Server: Optimizer)V-9.1.0 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:9.1.0_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Options) Version 9.1.0 and prior","product":{"name":"MySQL Server(Server: Options) Version 9.1.0 and prior","product_id":"P-8478(Server: Options)V-9.1.0 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:9.1.0_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Packaging) Version 9.1.0 and prior","product":{"name":"MySQL Server(Server: Packaging) Version 9.1.0 and prior","product_id":"P-8478(Server: Packaging)V-9.1.0 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:9.1.0_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Parser) Version 9.1.0 and prior","product":{"name":"MySQL Server(Server: Parser) Version 9.1.0 and prior","product_id":"P-8478(Server: Parser)V-9.1.0 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:9.1.0_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Server(Server: Security: Privileges) Version 9.1.0 and prior","product":{"name":"MySQL Server(Server: Security: Privileges) Version 9.1.0 and prior","product_id":"P-8478(Server: Security: Privileges)V-9.1.0 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_server:9.1.0_and_prior:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"MySQL Server"},{"branches":[{"category":"product_version_range","name":"MySQL Shell(Shell General / Core Client) Version 8.0.40 and prior","product":{"name":"MySQL Shell(Shell General / Core Client) Version 8.0.40 and prior","product_id":"P-8478(Shell General / Core Client)V-8.0.40 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_shell:8.0.40_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Shell(Shell General / Core Client) Version 8.4.3 and prior","product":{"name":"MySQL Shell(Shell General / Core Client) Version 8.4.3 and prior","product_id":"P-8478(Shell General / Core Client)V-8.4.3 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_shell:8.4.3_and_prior:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"MySQL Shell(Shell General / Core Client) Version 9.1.0 and prior","product":{"name":"MySQL Shell(Shell General / Core Client) Version 9.1.0 and prior","product_id":"P-8478(Shell General / Core Client)V-9.1.0 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:mysql_shell:9.1.0_and_prior:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"MySQL Shell"}],"category":"product_family","name":"Oracle MySQL"},{"branches":[{"branches":[{"category":"product_version","name":"PeopleSoft Enterprise CC Common Application Objects Version 9.2","product":{"name":"PeopleSoft Enterprise CC Common Application Objects Version 9.2","product_id":"P-8911V-9.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:peoplesoft_enterprise_cc_common_application_objects:9.2:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"PeopleSoft Enterprise CC Common Application Objects"},{"branches":[{"category":"product_version","name":"PeopleSoft Enterprise FIN Cash Management Version 9.2","product":{"name":"PeopleSoft Enterprise FIN Cash Management Version 9.2","product_id":"P-4979V-9.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:peoplesoft_enterprise_fin_cash_management:9.2:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"PeopleSoft Enterprise FIN Cash Management"},{"branches":[{"category":"product_version","name":"PeopleSoft Enterprise FIN eSettlements Version 9.2","product":{"name":"PeopleSoft Enterprise FIN eSettlements Version 9.2","product_id":"P-4987V-9.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:peoplesoft_enterprise_fin_esettlements:9.2:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"PeopleSoft Enterprise FIN eSettlements"},{"branches":[{"category":"product_version","name":"PeopleSoft Enterprise PeopleTools Version 8.60","product":{"name":"PeopleSoft Enterprise PeopleTools Version 8.60","product_id":"P-5085V-8.60","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.60:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"PeopleSoft Enterprise PeopleTools Version 8.61","product":{"name":"PeopleSoft Enterprise PeopleTools Version 8.61","product_id":"P-5085V-8.61","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.61:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"PeopleSoft Enterprise PeopleTools"},{"branches":[{"category":"product_version","name":"PeopleSoft Enterprise SCM Purchasing Version 9.2","product":{"name":"PeopleSoft Enterprise SCM Purchasing Version 9.2","product_id":"P-5133V-9.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:peoplesoft_enterprise_scm_purchasing:9.2:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"PeopleSoft Enterprise SCM Purchasing"}],"category":"product_family","name":"Oracle PeopleSoft"},{"branches":[{"branches":[{"category":"product_version_range","name":"Oracle Policy Automation Version 12.2.18-12.2.36","product":{"name":"Oracle Policy Automation Version 12.2.18-12.2.36","product_id":"P-5624V-12.2.18-12.2.36","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:policy_automation:12.2.18-12.2.36:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Policy Automation"}],"category":"product_family","name":"Oracle Policy Automation"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle REST Data Services Version 23.3.0.289.1830","product":{"name":"Oracle REST Data Services Version 23.3.0.289.1830","product_id":"P-9456V-23.3.0.289.1830","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:rest_data_services:23.3.0.289.1830:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle REST Data Services Version 23.3.1.305.1055","product":{"name":"Oracle REST Data Services Version 23.3.1.305.1055","product_id":"P-9456V-23.3.1.305.1055","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:rest_data_services:23.3.1.305.1055:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle REST Data Services Version 23.4.0.346.1619","product":{"name":"Oracle REST Data Services Version 23.4.0.346.1619","product_id":"P-9456V-23.4.0.346.1619","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:rest_data_services:23.4.0.346.1619:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle REST Data Services Version 23.4.1.038.1857","product":{"name":"Oracle REST Data Services Version 23.4.1.038.1857","product_id":"P-9456V-23.4.1.038.1857","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:rest_data_services:23.4.1.038.1857:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle REST Data Services Version 24.1.0.108.0942","product":{"name":"Oracle REST Data Services Version 24.1.0.108.0942","product_id":"P-9456V-24.1.0.108.0942","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:rest_data_services:24.1.0.108.0942:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle REST Data Services Version 24.1.1.120.1228","product":{"name":"Oracle REST Data Services Version 24.1.1.120.1228","product_id":"P-9456V-24.1.1.120.1228","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:rest_data_services:24.1.1.120.1228:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle REST Data Services Version 24.1.2.163.1158","product":{"name":"Oracle REST Data Services Version 24.1.2.163.1158","product_id":"P-9456V-24.1.2.163.1158","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:rest_data_services:24.1.2.163.1158:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle REST Data Services Version 24.2.0","product":{"name":"Oracle REST Data Services Version 24.2.0","product_id":"P-9456V-24.2.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:rest_data_services:24.2.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle REST Data Services Version 24.2.0.169.2208","product":{"name":"Oracle REST Data Services Version 24.2.0.169.2208","product_id":"P-9456V-24.2.0.169.2208","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:rest_data_services:24.2.0.169.2208:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle REST Data Services Version 24.2.1.180.1634","product":{"name":"Oracle REST Data Services Version 24.2.1.180.1634","product_id":"P-9456V-24.2.1.180.1634","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:rest_data_services:24.2.1.180.1634:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle REST Data Services Version 24.2.2.187.1943","product":{"name":"Oracle REST Data Services Version 24.2.2.187.1943","product_id":"P-9456V-24.2.2.187.1943","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:rest_data_services:24.2.2.187.1943:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle REST Data Services Version 24.3.0","product":{"name":"Oracle REST Data Services Version 24.3.0","product_id":"P-9456V-24.3.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:rest_data_services:24.3.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle REST Data Services"}],"category":"product_family","name":"Oracle REST Data Services"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Retail Financial Integration Version 14.1.3.2","product":{"name":"Oracle Retail Financial Integration Version 14.1.3.2","product_id":"P-10722V-14.1.3.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:retail_financial_integration:14.1.3.2:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Retail Financial Integration Version 15.0.3.1","product":{"name":"Oracle Retail Financial Integration Version 15.0.3.1","product_id":"P-10722V-15.0.3.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:retail_financial_integration:15.0.3.1:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Retail Financial Integration Version 16.0.3.0","product":{"name":"Oracle Retail Financial Integration Version 16.0.3.0","product_id":"P-10722V-16.0.3.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:retail_financial_integration:16.0.3.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Retail Financial Integration Version 19.0.1.0","product":{"name":"Oracle Retail Financial Integration Version 19.0.1.0","product_id":"P-10722V-19.0.1.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:retail_financial_integration:19.0.1.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Retail Financial Integration"},{"branches":[{"category":"product_version","name":"Oracle Retail Integration Bus Version 14.1.3.2","product":{"name":"Oracle Retail Integration Bus Version 14.1.3.2","product_id":"P-1807V-14.1.3.2","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:retail_integration_bus:14.1.3.2:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Retail Integration Bus Version 15.0.3.1","product":{"name":"Oracle Retail Integration Bus Version 15.0.3.1","product_id":"P-1807V-15.0.3.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:retail_integration_bus:15.0.3.1:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Retail Integration Bus Version 16.0.3.0","product":{"name":"Oracle Retail Integration Bus Version 16.0.3.0","product_id":"P-1807V-16.0.3.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:retail_integration_bus:16.0.3.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Retail Integration Bus Version 19.0.1.0","product":{"name":"Oracle Retail Integration Bus Version 19.0.1.0","product_id":"P-1807V-19.0.1.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:retail_integration_bus:19.0.1.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Retail Integration Bus"}],"category":"product_family","name":"Oracle Retail Applications"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Secure Backup Version 18.1.0.1.0","product":{"name":"Oracle Secure Backup Version 18.1.0.1.0","product_id":"P-1522V-18.1.0.1.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:secure_backup:18.1.0.1.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Secure Backup Version 18.1.0.2.0","product":{"name":"Oracle Secure Backup Version 18.1.0.2.0","product_id":"P-1522V-18.1.0.2.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:secure_backup:18.1.0.2.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Secure Backup Version 19.1.0.0.0","product":{"name":"Oracle Secure Backup Version 19.1.0.0.0","product_id":"P-1522V-19.1.0.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:secure_backup:19.1.0.0.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Secure Backup"}],"category":"product_family","name":"Oracle Secure Backup"},{"branches":[{"branches":[{"category":"product_version_range","name":"Siebel CRM End User Version 24.11 and prior","product":{"name":"Siebel CRM End User Version 24.11 and prior","product_id":"P-9011V-24.11 and prior","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:siebel_crm_end_user:24.11_and_prior:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Siebel CRM End User"}],"category":"product_family","name":"Oracle Siebel CRM"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Agile Engineering Data Management Version 6.2.1","product":{"name":"Oracle Agile Engineering Data Management Version 6.2.1","product_id":"P-4436V-6.2.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Agile Engineering Data Management"},{"branches":[{"category":"product_version","name":"Oracle Agile PLM Framework Version 9.3.6","product":{"name":"Oracle Agile PLM Framework Version 9.3.6","product_id":"P-4461V-9.3.6","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:agile_plm_framework:9.3.6:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Agile PLM Framework"}],"category":"product_family","name":"Oracle Supply Chain"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle Solaris Version 11","product":{"name":"Oracle Solaris Version 11","product_id":"P-10006V-11","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:solaris:11:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Solaris"}],"category":"product_family","name":"Oracle Systems"},{"branches":[{"branches":[{"category":"product_version","name":"Oracle TimesTen In-Memory Database Version 18.1","product":{"name":"Oracle TimesTen In-Memory Database Version 18.1","product_id":"P-1870V-18.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:timesten_in-memory_database:18.1:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle TimesTen In-Memory Database Version 22.1","product":{"name":"Oracle TimesTen In-Memory Database Version 22.1","product_id":"P-1870V-22.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:timesten_in-memory_database:22.1:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle TimesTen In-Memory Database"}],"category":"product_family","name":"Oracle TimesTen In-Memory Database"},{"branches":[{"branches":[{"category":"product_version_range","name":"Oracle Utilities Application Framework Version 24.1.0.0.0-24.3.0.0.0","product":{"name":"Oracle Utilities Application Framework Version 24.1.0.0.0-24.3.0.0.0","product_id":"P-2245V-24.1.0.0.0-24.3.0.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:utilities_application_framework:24.1.0.0.0-24.3.0.0.0:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Utilities Application Framework Version 4.3.0.3.0-4.3.0.6.0","product":{"name":"Oracle Utilities Application Framework Version 4.3.0.3.0-4.3.0.6.0","product_id":"P-2245V-4.3.0.3.0-4.3.0.6.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:utilities_application_framework:4.3.0.3.0-4.3.0.6.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Utilities Application Framework Version 4.4.0.0.0","product":{"name":"Oracle Utilities Application Framework Version 4.4.0.0.0","product_id":"P-2245V-4.4.0.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:utilities_application_framework:4.4.0.0.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Utilities Application Framework Version 4.4.0.2.0","product":{"name":"Oracle Utilities Application Framework Version 4.4.0.2.0","product_id":"P-2245V-4.4.0.2.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:utilities_application_framework:4.4.0.2.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Utilities Application Framework Version 4.4.0.3.0","product":{"name":"Oracle Utilities Application Framework Version 4.4.0.3.0","product_id":"P-2245V-4.4.0.3.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:utilities_application_framework:4.4.0.3.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Utilities Application Framework Version 4.5.0.0.0","product":{"name":"Oracle Utilities Application Framework Version 4.5.0.0.0","product_id":"P-2245V-4.5.0.0.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:utilities_application_framework:4.5.0.0.0:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Utilities Application Framework Version 4.5.0.1.1","product":{"name":"Oracle Utilities Application Framework Version 4.5.0.1.1","product_id":"P-2245V-4.5.0.1.1","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:utilities_application_framework:4.5.0.1.1:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Utilities Application Framework Version 4.5.0.1.3","product":{"name":"Oracle Utilities Application Framework Version 4.5.0.1.3","product_id":"P-2245V-4.5.0.1.3","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:utilities_application_framework:4.5.0.1.3:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Utilities Application Framework"},{"branches":[{"category":"product_version","name":"Oracle Utilities Network Management System Version 2.5.0.1.14","product":{"name":"Oracle Utilities Network Management System Version 2.5.0.1.14","product_id":"P-2241V-2.5.0.1.14","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:utilities_network_management_system:2.5.0.1.14:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Utilities Network Management System Version 2.5.0.1.15","product":{"name":"Oracle Utilities Network Management System Version 2.5.0.1.15","product_id":"P-2241V-2.5.0.1.15","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:utilities_network_management_system:2.5.0.1.15:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Utilities Network Management System Version 2.5.0.2.9","product":{"name":"Oracle Utilities Network Management System Version 2.5.0.2.9","product_id":"P-2241V-2.5.0.2.9","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:utilities_network_management_system:2.5.0.2.9:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Utilities Network Management System Version 2.6.0.1.5","product":{"name":"Oracle Utilities Network Management System Version 2.6.0.1.5","product_id":"P-2241V-2.6.0.1.5","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:utilities_network_management_system:2.6.0.1.5:*:*:*:*:*:*:*"}}},{"category":"product_version","name":"Oracle Utilities Network Management System Version 2.6.0.1.7","product":{"name":"Oracle Utilities Network Management System Version 2.6.0.1.7","product_id":"P-2241V-2.6.0.1.7","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:utilities_network_management_system:2.6.0.1.7:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Utilities Network Management System"},{"branches":[{"category":"product_version_range","name":"Oracle Utilities Testing Accelerator Version 6.0.0.1.0-6.0.0.3.0","product":{"name":"Oracle Utilities Testing Accelerator Version 6.0.0.1.0-6.0.0.3.0","product_id":"P-13784V-6.0.0.1.0-6.0.0.3.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.1.0-6.0.0.3.0:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle Utilities Testing Accelerator Version 7.0.0.0.0-7.0.0.1.0","product":{"name":"Oracle Utilities Testing Accelerator Version 7.0.0.0.0-7.0.0.1.0","product_id":"P-13784V-7.0.0.0.0-7.0.0.1.0","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:utilities_testing_accelerator:7.0.0.0.0-7.0.0.1.0:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle Utilities Testing Accelerator"}],"category":"product_family","name":"Oracle Utilities Applications"},{"branches":[{"branches":[{"category":"product_version_range","name":"Oracle VM VirtualBox Version Prior to 7.0.24","product":{"name":"Oracle VM VirtualBox Version Prior to 7.0.24","product_id":"P-8370V-Prior to 7.0.24","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:vm_virtualbox:prior_to_7.0.24:*:*:*:*:*:*:*"}}},{"category":"product_version_range","name":"Oracle VM VirtualBox Version prior to 7.1.6","product":{"name":"Oracle VM VirtualBox Version prior to 7.1.6","product_id":"P-8370V-prior to 7.1.6","product_identification_helper":{"cpe":"cpe:2.3:a:oracle:vm_virtualbox:prior_to_7.1.6:*:*:*:*:*:*:*"}}}],"category":"product_name","name":"Oracle VM VirtualBox"}],"category":"product_family","name":"Oracle Virtualization"}],"category":"vendor","name":"Oracle"}]},"vulnerabilities":[{"cve":"CVE-2016-1000027","ids":[{"system_name":"Oracle Bug ID of Oracle BI Publisher","text":"37243652"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Development Operations (Spring Framework)).  Supported versions that are affected are 7.0.0.0.0 and  7.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1479V-7.0.0.0.0","P-1479V-7.6.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1479V-7.0.0.0.0","P-1479V-7.6.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-1479V-7.0.0.0.0","P-1479V-7.6.0.0.0"]}]},{"cve":"CVE-2019-11065","ids":[{"system_name":"Oracle Bug ID of Siebel CRM End User","text":"37281899"}],"notes":[{"category":"description","text":"Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI (Gradle)).  Supported versions that are affected are 24.11 and prior. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM End User executes to compromise Siebel CRM End User.  While the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9011V-24.11 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9011V-24.11 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065150.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","version":"3.1"},"products":["P-9011V-24.11 and prior"]}]},{"cve":"CVE-2019-12415","ids":[{"system_name":"Oracle Bug ID of Oracle Business Process Management Suite","text":"30765549"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Runtime Engine (Apache POI)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Process Management Suite executes to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Process Management Suite accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5325V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5325V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-5325V-12.2.1.4.0"]}]},{"cve":"CVE-2019-15052","ids":[{"system_name":"Oracle Bug ID of Siebel CRM End User","text":"37281899"}],"notes":[{"category":"description","text":"Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI (Gradle)).  Supported versions that are affected are 24.11 and prior. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM End User executes to compromise Siebel CRM End User.  While the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9011V-24.11 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9011V-24.11 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065150.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","version":"3.1"},"products":["P-9011V-24.11 and prior"]}]},{"cve":"CVE-2019-16370","ids":[{"system_name":"Oracle Bug ID of Siebel CRM End User","text":"37281899"}],"notes":[{"category":"description","text":"Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI (Gradle)).  Supported versions that are affected are 24.11 and prior. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM End User executes to compromise Siebel CRM End User.  While the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9011V-24.11 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9011V-24.11 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065150.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","version":"3.1"},"products":["P-9011V-24.11 and prior"]}]},{"cve":"CVE-2020-11979","ids":[{"system_name":"Oracle Bug ID of Siebel CRM End User","text":"37281899"}],"notes":[{"category":"description","text":"Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI (Gradle)).  Supported versions that are affected are 24.11 and prior. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM End User executes to compromise Siebel CRM End User.  While the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9011V-24.11 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9011V-24.11 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065150.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","version":"3.1"},"products":["P-9011V-24.11 and prior"]}]},{"cve":"CVE-2020-13956","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36965166"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Apache HttpClient)).  Supported versions that are affected are 7.0.0.0.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.0.0.0.0","P-2025V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-12.2.1.4.0","P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"products":["P-2025V-12.2.1.4.0","P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2020-22218","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"37135293"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: File Processing (libssh2)).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-5085V-8.61","P-5085V-8.60"]}]},{"cve":"CVE-2020-2849","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36981651"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Jinja)).   The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2020-28975","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36981845"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (scikit-learn)).   The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2020-7760","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"35006610"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Content Storage Service (CodeMirror)).   The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2021-23926","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"37333455"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security (Apache XMLBeans)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","version":"3.1"},"products":["P-2025V-12.2.1.4.0"]}]},{"cve":"CVE-2021-29428","ids":[{"system_name":"Oracle Bug ID of Siebel CRM End User","text":"37281899"}],"notes":[{"category":"description","text":"Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI (Gradle)).  Supported versions that are affected are 24.11 and prior. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM End User executes to compromise Siebel CRM End User.  While the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9011V-24.11 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9011V-24.11 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065150.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","version":"3.1"},"products":["P-9011V-24.11 and prior"]}]},{"cve":"CVE-2021-29429","ids":[{"system_name":"Oracle Bug ID of Siebel CRM End User","text":"37281899"}],"notes":[{"category":"description","text":"Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI (Gradle)).  Supported versions that are affected are 24.11 and prior. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM End User executes to compromise Siebel CRM End User.  While the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9011V-24.11 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9011V-24.11 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065150.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","version":"3.1"},"products":["P-9011V-24.11 and prior"]}]},{"cve":"CVE-2021-32751","ids":[{"system_name":"Oracle Bug ID of Siebel CRM End User","text":"37281899"}],"notes":[{"category":"description","text":"Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI (Gradle)).  Supported versions that are affected are 24.11 and prior. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM End User executes to compromise Siebel CRM End User.  While the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9011V-24.11 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9011V-24.11 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065150.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","version":"3.1"},"products":["P-9011V-24.11 and prior"]}]},{"cve":"CVE-2021-33813","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"35419228"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Web Catalog (JDOM)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-2025V-12.2.1.4.0"]}]},{"cve":"CVE-2021-37519","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_present","product_ids":["P-8478(Server: Packaging)V-8.0.40 and prior","P-8478(Server: Packaging)V-8.4.2 and prior"]}],"ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"35098363"}],"notes":[{"category":"description","text":"Security-in-Depth issue in the MySQL Server product of Oracle MySQL (component: Server: Packaging (memcached)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-8478(Server: Packaging)V-8.4.2 and prior","P-8478(Server: Packaging)V-8.0.40 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Packaging)V-8.0.40 and prior","P-8478(Server: Packaging)V-8.4.2 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-8478(Server: Packaging)V-8.0.40 and prior","P-8478(Server: Packaging)V-8.4.2 and prior"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.","product_ids":["P-8478(Server: Packaging)V-8.0.40 and prior","P-8478(Server: Packaging)V-8.4.2 and prior"]}]},{"cve":"CVE-2022-26345","ids":[{"system_name":"Oracle Bug ID of Oracle Database Server","text":"36775810"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Database Data Mining (Intel oneAPI Toolkit OpenMP) component of Oracle Database Server.  Supported versions that are affected are 19.3-19.25 and  21.3-21.16. Difficult to exploit vulnerability allows low privileged attacker having Authenticated User privilege with logon to the infrastructure where Oracle Database Data Mining (Intel oneAPI Toolkit OpenMP) executes to compromise Oracle Database Data Mining (Intel oneAPI Toolkit OpenMP).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Database Data Mining (Intel oneAPI Toolkit OpenMP). CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5(Oracle Database Data Mining)V-21.3-21.16","P-5(Oracle Database Data Mining)V-19.3-19.25"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5(Oracle Database Data Mining)V-21.3-21.16","P-5(Oracle Database Data Mining)V-19.3-19.25"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":6.7,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-5(Oracle Database Data Mining)V-21.3-21.16","P-5(Oracle Database Data Mining)V-19.3-19.25"]}]},{"cve":"CVE-2022-34169","ids":[{"system_name":"Oracle Bug ID of Oracle Financial Services Compliance Studio","text":"36243057"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Apache Xalan-Java)).   The supported version that is affected is 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14392V-8.1.2.5"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14392V-8.1.2.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065911.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-14392V-8.1.2.5"]}]},{"cve":"CVE-2022-40150","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"37257535"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security (Jettison)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-2025V-12.2.1.4.0"]}]},{"cve":"CVE-2022-41727","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Unified Assurance","text":"37261931"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Golang Go)).  Supported versions that are affected are 6.0.0-6.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14597V-6.0.0-6.0.5"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-6.0.0-6.0.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064020.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14597V-6.0.0-6.0.5"]}]},{"cve":"CVE-2023-24998","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"37053000"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Apache Commons FileUpload)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-2025V-12.2.1.4.0"]}]},{"cve":"CVE-2023-25399","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"37144321"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (SciPy)).  Supported versions that are affected are 7.0.0.0.0 and  7.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2023-26031","ids":[{"system_name":"Oracle Bug ID of Oracle Financial Services Compliance Studio","text":"36083378"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Apache Hadoop)).   The supported version that is affected is 8.1.2.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Compliance Studio. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14392V-8.1.2.5"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14392V-8.1.2.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065911.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-14392V-8.1.2.5"]}]},{"cve":"CVE-2023-27043","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Blockchain Platform","text":"37059329"}],"notes":[{"category":"description","text":"Security-in-Depth issue in Oracle Blockchain Platform (component: Blockchain Cloud Service Console (Python)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-13444V-21.1.2","P-13444V-24.1.3"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13444V-21.1.2","P-13444V-24.1.3"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}]},{"cve":"CVE-2023-29407","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Unified Assurance","text":"37261931"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Golang Go)).  Supported versions that are affected are 6.0.0-6.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14597V-6.0.0-6.0.5"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-6.0.0-6.0.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064020.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14597V-6.0.0-6.0.5"]}]},{"cve":"CVE-2023-29408","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Unified Assurance","text":"37261931"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Golang Go)).  Supported versions that are affected are 6.0.0-6.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14597V-6.0.0-6.0.5"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-6.0.0-6.0.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064020.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14597V-6.0.0-6.0.5"]}]},{"cve":"CVE-2023-2976","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36975754"},{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36587813"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics SEC (Google Guava)).  Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Google Guava)).   The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.0","P-2025V-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":7.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.0"]},{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2023-29824","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"37144321"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (SciPy)).  Supported versions that are affected are 7.0.0.0.0 and  7.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2023-32732","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36974392"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (gRPC)).   The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2023-33201","ids":[{"system_name":"Oracle Bug ID of Oracle Commerce Guided Search","text":"35761793"},{"system_name":"Oracle Bug ID of Oracle Financial Services Model Management and Governance","text":"35761831"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Workbench (Bouncy Castle Java Library)).   The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Commerce Guided Search accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Bouncy Castle Java Library)).  Supported versions that are affected are 8.1.2.6, 8.1.2.7 and  8.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Financial Services Model Management and Governance accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14276V-8.1.2.7","P-14276V-8.1.3.0","P-9633V-11.3.2","P-14276V-8.1.2.6"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9633V-11.3.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065159.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14276V-8.1.2.7","P-14276V-8.1.3.0","P-14276V-8.1.2.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066624.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"products":["P-14276V-8.1.2.7","P-9633V-11.3.2","P-14276V-8.1.3.0","P-14276V-8.1.2.6"]}]},{"cve":"CVE-2023-33202","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"37144471"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Bouncy Castle Java Library)).   The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2023-33953","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36975754"},{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36974392"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (gRPC)).   The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Google Guava)).   The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2023-35946","ids":[{"system_name":"Oracle Bug ID of Siebel CRM End User","text":"37281899"}],"notes":[{"category":"description","text":"Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI (Gradle)).  Supported versions that are affected are 24.11 and prior. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM End User executes to compromise Siebel CRM End User.  While the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9011V-24.11 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9011V-24.11 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065150.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","version":"3.1"},"products":["P-9011V-24.11 and prior"]}]},{"cve":"CVE-2023-35947","ids":[{"system_name":"Oracle Bug ID of Siebel CRM End User","text":"37281899"}],"notes":[{"category":"description","text":"Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI (Gradle)).  Supported versions that are affected are 24.11 and prior. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM End User executes to compromise Siebel CRM End User.  While the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9011V-24.11 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9011V-24.11 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065150.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","version":"3.1"},"products":["P-9011V-24.11 and prior"]}]},{"cve":"CVE-2023-36730","ids":[{"system_name":"Oracle Bug ID of Oracle GoldenGate","text":"37356077"}],"notes":[{"category":"description","text":"Vulnerability in Oracle GoldenGate (component: Install (Microsoft ODBC Driver)).  Supported versions that are affected are 21.3-21.16 and 23.4-23.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5757V-21.3-21.16","P-5757V-23.4-23.6"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5757V-21.3-21.16","P-5757V-23.4-23.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-5757V-21.3-21.16","P-5757V-23.4-23.6"]}]},{"cve":"CVE-2023-36785","ids":[{"system_name":"Oracle Bug ID of Oracle GoldenGate","text":"37356077"}],"notes":[{"category":"description","text":"Vulnerability in Oracle GoldenGate (component: Install (Microsoft ODBC Driver)).  Supported versions that are affected are 21.3-21.16 and 23.4-23.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5757V-21.3-21.16","P-5757V-23.4-23.6"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5757V-21.3-21.16","P-5757V-23.4-23.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-5757V-21.3-21.16","P-5757V-23.4-23.6"]}]},{"cve":"CVE-2023-38552","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36533858"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Node.js)).  Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools as well as  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":8.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.2"]}]},{"cve":"CVE-2023-38709","ids":[{"system_name":"Oracle Bug ID of Oracle HTTP Server","text":"37042942"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Mod_rewrite, Core (Apache HTTP Server)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data as well as  unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1042(Mod_rewrite, Core)V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042(Mod_rewrite, Core)V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"products":["P-1042(Mod_rewrite, Core)V-12.2.1.4.0"]}]},{"cve":"CVE-2023-39017","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_cannot_be_controlled_by_adversary","product_ids":["P-11681V-Prior to 9.2.9.0"]}],"ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Orchestrator","text":"35993939"}],"notes":[{"category":"description","text":"Security-in-Depth issue in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security (Quartz)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-11681V-Prior to 9.2.9.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11681V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-11681V-Prior to 9.2.9.0"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.","product_ids":["P-11681V-Prior to 9.2.9.0"]}]},{"cve":"CVE-2023-39410","ids":[{"system_name":"Oracle Bug ID of Oracle Banking Corporate Lending Process Management","text":"37107749"},{"system_name":"Oracle Bug ID of Oracle Business Process Management Suite","text":"37149355"},{"system_name":"Oracle Bug ID of Oracle Financial Services Model Management and Governance","text":"37107800"},{"system_name":"Oracle Bug ID of Oracle Banking Origination","text":"37107766"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Maintenance (Apache Avro)).  Supported versions that are affected are 14.5.0.0.0-14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Origination. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Avro)).  Supported versions that are affected are 8.1.2.6, 8.1.2.7 and  8.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Apache Avro)).  Supported versions that are affected are 14.4.0.0.0-14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Composer (Apache Avro)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Process Management Suite accessible data as well as  unauthorized read access to a subset of Oracle Business Process Management Suite accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Process Management Suite. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14276V-8.1.2.7","P-13701V-14.4.0.0.0-14.7.0.0.0","P-14276V-8.1.3.0","P-5325V-12.2.1.4.0","P-14325V-14.5.0.0.0-14.7.0.0.0","P-14276V-8.1.2.6"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13701V-14.4.0.0.0-14.7.0.0.0","P-14325V-14.5.0.0.0-14.7.0.0.0"],"url":"https://support.oracle.com"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14276V-8.1.2.7","P-14276V-8.1.3.0","P-14276V-8.1.2.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066624.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5325V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14276V-8.1.2.7","P-13701V-14.4.0.0.0-14.7.0.0.0","P-14325V-14.5.0.0.0-14.7.0.0.0","P-14276V-8.1.3.0","P-14276V-8.1.2.6"]},{"cvss_v3":{"baseScore":7.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"products":["P-5325V-12.2.1.4.0"]}]},{"cve":"CVE-2023-3961","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36675640"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Samba)).  Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMB to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.2"]}]},{"cve":"CVE-2023-40577","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment","text":"37033270"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (Golang Go)).  Supported versions that are affected are 24.2.0 and  24.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Cloud Native Core Network Function Cloud Native Environment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Network Function Cloud Native Environment accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Network Function Cloud Native Environment accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14125V-24.2.0","P-14125V-24.3.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14125V-24.2.0","P-14125V-24.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066005.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-14125V-24.2.0","P-14125V-24.3.0"]}]},{"cve":"CVE-2023-4091","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36675640"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Samba)).  Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMB to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.2"]}]},{"cve":"CVE-2023-42445","ids":[{"system_name":"Oracle Bug ID of Siebel CRM End User","text":"37281899"}],"notes":[{"category":"description","text":"Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI (Gradle)).  Supported versions that are affected are 24.11 and prior. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM End User executes to compromise Siebel CRM End User.  While the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9011V-24.11 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9011V-24.11 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065150.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","version":"3.1"},"products":["P-9011V-24.11 and prior"]}]},{"cve":"CVE-2023-42669","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36675640"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Samba)).  Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMB to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.2"]}]},{"cve":"CVE-2023-43804","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36981693"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (urllib3)).   The supported version that is affected is 7.0.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":4.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2023-4408","ids":[{"system_name":"Oracle Bug ID of Oracle SD-WAN Edge","text":"37033751"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Platform (BIND)).  Supported versions that are affected are 9.1.1.5-9.1.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via DNS to compromise Oracle SD-WAN Edge.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Edge. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-13940V-9.1.1.5-9.1.1.8"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13940V-9.1.1.5-9.1.1.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066026.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-13940V-9.1.1.5-9.1.1.8"]}]},{"cve":"CVE-2023-44387","ids":[{"system_name":"Oracle Bug ID of Siebel CRM End User","text":"37281899"}],"notes":[{"category":"description","text":"Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI (Gradle)).  Supported versions that are affected are 24.11 and prior. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM End User executes to compromise Siebel CRM End User.  While the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9011V-24.11 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9011V-24.11 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065150.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","version":"3.1"},"products":["P-9011V-24.11 and prior"]}]},{"cve":"CVE-2023-44483","ids":[{"system_name":"Oracle Bug ID of Oracle Outside In Technology","text":"36949168"},{"system_name":"Oracle Bug ID of Oracle Financial Services Compliance Studio","text":"35977824"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Apache Santuario XML Security For Java)).   The supported version that is affected is 8.1.2.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Compliance Studio accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Clean Content SDK (Apache Santuario XML Security For Java)).   The supported version that is affected is 8.5.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Outside In Technology accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14392V-8.1.2.6","P-2276V-8.5.7"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14392V-8.1.2.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065911.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2276V-8.5.7"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-14392V-8.1.2.6","P-2276V-8.5.7"]}]},{"cve":"CVE-2023-44487","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36974392"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (gRPC)).   The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2023-45803","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36981693"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (urllib3)).   The supported version that is affected is 7.0.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":4.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2023-46218","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Diameter Signaling Router","text":"36127647"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (curl)).   The supported version that is affected is 9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Diameter Signaling Router accessible data as well as  unauthorized read access to a subset of Oracle Communications Diameter Signaling Router accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10899V-9.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066025.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-10899V-9.0"]}]},{"cve":"CVE-2023-46219","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Diameter Signaling Router","text":"36127647"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (curl)).   The supported version that is affected is 9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Diameter Signaling Router accessible data as well as  unauthorized read access to a subset of Oracle Communications Diameter Signaling Router accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10899V-9.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066025.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-10899V-9.0"]}]},{"cve":"CVE-2023-46604","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Diameter Signaling Router","text":"36123740"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Patches (Apache ActiveMQ)).   The supported version that is affected is 8.2.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10899V-8.2.3.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-8.2.3.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066025.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-10899V-8.2.3.0.0"]}]},{"cve":"CVE-2023-4782","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"35842278"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Terraform)).  Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.2"]}]},{"cve":"CVE-2023-4785","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36974392"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (gRPC)).   The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2023-48795","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36223788"},{"system_name":"Oracle Bug ID of Database Migration Assistant for Unicode (Apache Mina SSHD)","text":"36223780"},{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"37135293"},{"system_name":"Oracle Bug ID of Oracle Financial Services Compliance Studio","text":"36223834"}],"notes":[{"category":"description","text":"Vulnerability in the Database Migration Assistant for Unicode (Apache Mina SSHD) component of Oracle Database Server.   The supported version that is affected is 19.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Database Migration Assistant for Unicode (Apache Mina SSHD).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Database Migration Assistant for Unicode (Apache Mina SSHD) accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure SEC (Apache Mina SSHD)).  Supported versions that are affected are Prior to 9.2.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Apache Mina SSHD)).   The supported version that is affected is 8.1.2.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: File Processing (libssh2)).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2550V-19.1","P-4781V-Prior to 9.2.9.0","P-5085V-8.61","P-5085V-8.60","P-14392V-8.1.2.5"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2550V-19.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14392V-8.1.2.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065911.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":5.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-14392V-8.1.2.5","P-2550V-19.1","P-4781V-Prior to 9.2.9.0"]},{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-5085V-8.61","P-5085V-8.60"]}]},{"cve":"CVE-2023-49582","ids":[{"system_name":"Oracle Bug ID of Oracle HTTP Server","text":"37067454"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (Apache Portable Runtime)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1042(Core)V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042(Core)V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-1042(Core)V-12.2.1.4.0"]}]},{"cve":"CVE-2023-50782","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36981631"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (OpenSSL)).   The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2023-50868","ids":[{"system_name":"Oracle Bug ID of Oracle SD-WAN Edge","text":"37033751"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Platform (BIND)).  Supported versions that are affected are 9.1.1.5-9.1.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via DNS to compromise Oracle SD-WAN Edge.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Edge. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-13940V-9.1.1.5-9.1.1.8"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13940V-9.1.1.5-9.1.1.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066026.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-13940V-9.1.1.5-9.1.1.8"]}]},{"cve":"CVE-2023-51074","ids":[{"system_name":"Oracle Bug ID of Oracle Financial Services Compliance Studio","text":"37397653"},{"system_name":"Oracle Bug ID of Oracle Financial Services Regulatory Reporting","text":"37397697"},{"system_name":"Oracle Bug ID of Oracle Application Testing Suite","text":"37397030"},{"system_name":"Oracle Bug ID of Oracle Financial Services Behavior Detection Platform","text":"37397648"},{"system_name":"Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition","text":"37397699"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Load Testing for Web Apps (JsonPath)).   The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Application Testing Suite. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (JsonPath)).  Supported versions that are affected are 8.0.8.1, 8.1.2.8 and  8.1.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (JsonPath)).   The supported version that is affected is 8.1.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Compliance Studio. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Regulatory Reporting product of Oracle Financial Services Applications (component: Platform (JsonPath)).  Supported versions that are affected are 8.1.2.7 and  8.1.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Regulatory Reporting.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Regulatory Reporting. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (JsonPath)).   The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4622V-13.3.0.1","P-14392V-8.1.2.6","P-9142V-8.1.2.8","P-13789V-8.0.8","P-9142V-8.1.2.7","P-9190V-8.1.2.7","P-9190V-8.0.8.1","P-9190V-8.1.2.8"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4622V-13.3.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056561.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9190V-8.1.2.7","P-9190V-8.0.8.1","P-9190V-8.1.2.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066717.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14392V-8.1.2.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065911.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9142V-8.1.2.8","P-9142V-8.1.2.7"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065882.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13789V-8.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066716.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["P-4622V-13.3.0.1","P-14392V-8.1.2.6","P-9142V-8.1.2.8","P-13789V-8.0.8","P-9142V-8.1.2.7","P-9190V-8.1.2.7","P-9190V-8.0.8.1","P-9190V-8.1.2.8"]}]},{"cve":"CVE-2023-51775","ids":[{"system_name":"Oracle Bug ID of Oracle Middleware Common Libraries and Tools","text":"36390560"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (jose4j)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4647V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4647V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-4647V-12.2.1.4.0"]}]},{"cve":"CVE-2023-52070","ids":[{"system_name":"Oracle Bug ID of Oracle Financial Services Revenue Management and Billing","text":"37033003"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Chatbot (JFreeChart)).  Supported versions that are affected are 2.9.0.0.0-7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Financial Services Revenue Management and Billing executes to compromise Oracle Financial Services Revenue Management and Billing.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Revenue Management and Billing. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5322V-2.9.0.0.0-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5322V-2.9.0.0.0-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064865.1"}],"scores":[{"cvss_v3":{"baseScore":8.4,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-5322V-2.9.0.0.0-7.0.0.0.0"]}]},{"cve":"CVE-2023-52428","ids":[{"system_name":"Oracle Bug ID of Oracle Graal Development Kit for Micronaut (Nimbus JOSE+JWT)","text":"37292494"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Graal Development Kit for Micronaut (Nimbus JOSE+JWT) component of Oracle Database Server.  Supported versions that are affected are 23.5-23.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Graal Development Kit for Micronaut (Nimbus JOSE+JWT).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Graal Development Kit for Micronaut (Nimbus JOSE+JWT). CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14599V-23.5-23.6"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14599V-23.5-23.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14599V-23.5-23.6"]}]},{"cve":"CVE-2023-5678","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36278300"},{"system_name":"Oracle Bug ID of Oracle Communications Session Border Controller","text":"36022397"},{"system_name":"Oracle Bug ID of Oracle Enterprise Communications Broker","text":"37403711"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Third Party (OpenSSL)).  Supported versions that are affected are 9.2.0 and  9.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Session Border Controller. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure SEC (OpenSSL)).  Supported versions that are affected are Prior to 9.2.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools as well as  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications (component: Third Party (OpenSSL)).  Supported versions that are affected are 4.1.0 and  4.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Communications Broker.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Communications Broker. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.0","P-10758V-4.2.0","P-10750V-9.2.0","P-10758V-4.1.0","P-10750V-9.3.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10750V-9.2.0","P-10750V-9.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065963.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10758V-4.2.0","P-10758V-4.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065964.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["P-10758V-4.2.0","P-10758V-4.1.0","P-10750V-9.2.0","P-10750V-9.3.0"]},{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.0"]}]},{"cve":"CVE-2023-5981","ids":[{"system_name":"Oracle Bug ID of Oracle Communications User Data Repository","text":"37218575"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Platform (GnuTLS)).  Supported versions that are affected are 12.11 and  14.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications User Data Repository.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications User Data Repository accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-11108V-12.11","P-11108V-14.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11108V-12.11","P-11108V-14.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066024.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-11108V-12.11","P-11108V-14.0"]}]},{"cve":"CVE-2023-6129","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36278300"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure SEC (OpenSSL)).  Supported versions that are affected are Prior to 9.2.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools as well as  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.0"]}]},{"cve":"CVE-2023-6597","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Diameter Signaling Router","text":"36627541"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (Python)).   The supported version that is affected is 9.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Diameter Signaling Router executes to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10899V-9.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-9.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066025.1"}],"scores":[{"cvss_v3":{"baseScore":6.2,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-10899V-9.0.0.0.0"]}]},{"cve":"CVE-2023-7256","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Operations Monitor","text":"37107949"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy","text":"37107934"},{"system_name":"Oracle Bug ID of Oracle SD-WAN Edge","text":"37107962"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: ATS Framework (libpcap)).   The supported version that is affected is 24.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Security Edge Protection Proxy executes to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (libpcap)).  Supported versions that are affected are 5.1 and  5.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Operations Monitor executes to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Internal Tools (libpcap)).  Supported versions that are affected are 9.1.1.5-9.1.1.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle SD-WAN Edge executes to compromise Oracle SD-WAN Edge.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Edge. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10761V-5.1","P-14123V-24.2.2","P-13940V-9.1.1.5-9.1.1.8","P-10761V-5.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10761V-5.1","P-10761V-5.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066003.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13940V-9.1.1.5-9.1.1.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066026.1"}],"scores":[{"cvss_v3":{"baseScore":4.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-10761V-5.1","P-13940V-9.1.1.5-9.1.1.8","P-10761V-5.2","P-14123V-24.2.2"]}]},{"cve":"CVE-2023-7272","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"37148166"},{"system_name":"Oracle Bug ID of Oracle WebLogic Server","text":"37202958"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Eclipse Parsson)).   The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.6 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Eclipse Parsson)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 8.6 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.0.0.0.0","P-5242V-12.2.1.4.0","P-5242V-14.1.1.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":8.6,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","version":"3.1"},"products":["P-5242V-14.1.1.0.0","P-2025V-7.0.0.0.0","P-5242V-12.2.1.4.0"]}]},{"cve":"CVE-2024-0232","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Messaging Server","text":"36487796"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications Applications (component: Security (SQLite)).   The supported version that is affected is 8.1.0.26. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Messaging Server executes to compromise Oracle Communications Messaging Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Messaging Server. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8496V-8.1.0.26"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8496V-8.1.0.26"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065603.1"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8496V-8.1.0.26"]}]},{"cve":"CVE-2024-0397","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"37059368"},{"system_name":"Oracle Bug ID of Oracle Communications Unified Assurance","text":"37059349"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Porting (Python)).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Python)).  Supported versions that are affected are 6.0.0-6.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60","P-14597V-6.0.0-6.0.5"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-6.0.0-6.0.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064020.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14597V-6.0.0-6.0.5","P-5085V-8.61","P-5085V-8.60"]}]},{"cve":"CVE-2024-0450","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Diameter Signaling Router","text":"36627541"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (Python)).   The supported version that is affected is 9.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Diameter Signaling Router executes to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10899V-9.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-9.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066025.1"}],"scores":[{"cvss_v3":{"baseScore":6.2,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-10899V-9.0.0.0.0"]}]},{"cve":"CVE-2024-0727","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36278300"},{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36981631"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure SEC (OpenSSL)).  Supported versions that are affected are Prior to 9.2.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools as well as  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (OpenSSL)).   The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.0","P-2025V-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.0"]},{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2024-11053","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_cannot_be_controlled_by_adversary","product_ids":["P-4379V-21.7"]}],"ids":[{"system_name":"Oracle Bug ID of MySQL Enterprise Backup","text":"37389562"},{"system_name":"Oracle Bug ID of MySQL Server","text":"37389565"},{"system_name":"Oracle Bug ID of Oracle Essbase","text":"37389589"}],"notes":[{"category":"description","text":"Security-in-Depth issue in Oracle Essbase (component: Essbase Web Platform (curl)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the MySQL Enterprise Backup product of Oracle MySQL (component: Enterprise Backup (curl)).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Enterprise Backup.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Enterprise Backup accessible data as well as  unauthorized access to critical data or complete access to all MySQL Enterprise Backup accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging (curl)).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Server accessible data as well as  unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4629V-8.4.3 and prior","P-8478(Server: Packaging)V-8.0.40 and prior","P-4629V-9.1.0 and prior","P-8478(Server: Packaging)V-9.1.0 and prior","P-8478(Server: Packaging)V-8.4.3 and prior","P-4629V-8.0.40 and prior"],"known_not_affected":["P-4379V-21.7"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4379V-21.7"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4629V-8.4.3 and prior","P-8478(Server: Packaging)V-8.0.40 and prior","P-4629V-9.1.0 and prior","P-8478(Server: Packaging)V-9.1.0 and prior","P-8478(Server: Packaging)V-8.4.3 and prior","P-4629V-8.0.40 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-4379V-21.7"]},{"cvss_v3":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"products":["P-4629V-8.4.3 and prior","P-8478(Server: Packaging)V-8.0.40 and prior","P-4629V-9.1.0 and prior","P-8478(Server: Packaging)V-9.1.0 and prior","P-8478(Server: Packaging)V-8.4.3 and prior","P-4629V-8.0.40 and prior"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.","product_ids":["P-4379V-21.7"]}]},{"cve":"CVE-2024-1135","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"37328896"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Pipeline Test Failures (Gunicorn)).   The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"products":["P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2024-1442","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Unified Assurance","text":"36628136"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Grafana)).  Supported versions that are affected are 6.0.0-6.0.5. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data as well as  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14597V-6.0.0-6.0.5"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-6.0.0-6.0.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064020.1"}],"scores":[{"cvss_v3":{"baseScore":6.0,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L","version":"3.1"},"products":["P-14597V-6.0.0-6.0.5"]}]},{"cve":"CVE-2024-21211","ids":[{"system_name":"Oracle Bug ID of Oracle Database Server","text":"37134889"}],"notes":[{"category":"description","text":"Vulnerability in the GraalVM Multilingual Engine component of Oracle Database Server.  Supported versions that are affected are 21.4-21.16 and  23.5-23.6. Difficult to exploit vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise GraalVM Multilingual Engine.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of GraalVM Multilingual Engine accessible data. CVSS 3.1 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5(GraalVM Multilingual Engine)V-21.4-21.16","P-5(GraalVM Multilingual Engine)V-23.5-23.6"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5(GraalVM Multilingual Engine)V-21.4-21.16","P-5(GraalVM Multilingual Engine)V-23.5-23.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":3.1,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"products":["P-5(GraalVM Multilingual Engine)V-21.4-21.16","P-5(GraalVM Multilingual Engine)V-23.5-23.6"]}]},{"cve":"CVE-2024-21245","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36793652"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC).  Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.0"]}]},{"cve":"CVE-2024-22018","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"36908308"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch (Node.js)).  Supported versions that are affected are 8.60 and  8.61. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 6.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H","version":"3.1"},"products":["P-5085V-8.61","P-5085V-8.60"]}]},{"cve":"CVE-2024-22019","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"36908308"},{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36533858"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch (Node.js)).  Supported versions that are affected are 8.60 and  8.61. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 6.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Node.js)).  Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools as well as  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60","P-4781V-Prior to 9.2.9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H","version":"3.1"},"products":["P-5085V-8.61","P-5085V-8.60"]},{"cvss_v3":{"baseScore":8.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.2"]}]},{"cve":"CVE-2024-22020","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"36908308"},{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36533858"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Node.js)).  Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools as well as  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch (Node.js)).  Supported versions that are affected are 8.60 and  8.61. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 6.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60","P-4781V-Prior to 9.2.9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":8.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.2"]},{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H","version":"3.1"},"products":["P-5085V-8.61","P-5085V-8.60"]}]},{"cve":"CVE-2024-22195","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function","text":"37160590"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy","text":"37160604"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Policy","text":"37160602"},{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36981651"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Jinja)).  Supported versions that are affected are 24.2.0-24.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: ATS Framework (Jinja)).  Supported versions that are affected are 24.2.0 and  24.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Jinja)).   The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Jinja)).  Supported versions that are affected are 24.2.0 and  24.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14277V-24.2.0-24.2.2","P-14121V-24.2.1","P-14123V-24.2.1","P-2025V-7.0.0.0.0","P-14123V-24.2.0","P-14121V-24.2.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-24.2.0-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066021.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-24.2.1","P-14123V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-24.2.1","P-14121V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066001.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-14277V-24.2.0-24.2.2","P-14121V-24.2.1","P-14123V-24.2.1","P-2025V-7.0.0.0.0","P-14123V-24.2.0","P-14121V-24.2.0"]}]},{"cve":"CVE-2024-22262","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-10945V-12.2.0.4.0","P-5758V-12.2.1.4.0-12.2.1.4.240430"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle GoldenGate Veridata","text":"36603536"},{"system_name":"Oracle Bug ID of Oracle GoldenGate Studio","text":"36603534"}],"notes":[{"category":"description","text":"Security-in-Depth issue in the Oracle GoldenGate Studio product of Oracle GoldenGate (component: General (Spring Framework)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle GoldenGate Veridata product of Oracle GoldenGate (component: General (Spring Framework)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-10945V-12.2.0.4.0","P-5758V-12.2.1.4.0-12.2.1.4.240430"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10945V-12.2.0.4.0","P-5758V-12.2.1.4.0-12.2.1.4.240430"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-10945V-12.2.0.4.0","P-5758V-12.2.1.4.0-12.2.1.4.240430"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-10945V-12.2.0.4.0","P-5758V-12.2.1.4.0-12.2.1.4.240430"]}]},{"cve":"CVE-2024-23635","ids":[{"system_name":"Oracle Bug ID of Oracle WebLogic Server","text":"37351284"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (AntiSamy)).   The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5242V-14.1.1.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-14.1.1.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":6.1,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-5242V-14.1.1.0.0"]}]},{"cve":"CVE-2024-23672","ids":[{"system_name":"Oracle Bug ID of Oracle Agile Engineering Data Management","text":"37085515"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Document Management (Apache Tomcat)).   The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Agile Engineering Data Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4436V-6.2.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4436V-6.2.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065151.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-4436V-6.2.1"]}]},{"cve":"CVE-2024-23807","ids":[{"system_name":"Oracle Bug ID of Oracle Agile Engineering Data Management","text":"36754719"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core (Apache Xerces-C++)).   The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.  Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4436V-6.2.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4436V-6.2.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065151.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-4436V-6.2.1"]}]},{"cve":"CVE-2024-24549","ids":[{"system_name":"Oracle Bug ID of Oracle Agile Engineering Data Management","text":"37085515"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Document Management (Apache Tomcat)).   The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Agile Engineering Data Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4436V-6.2.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4436V-6.2.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065151.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-4436V-6.2.1"]}]},{"cve":"CVE-2024-24786","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Unified Assurance","text":"37232060"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Google Protobuf-Java)).  Supported versions that are affected are 6.0.0-6.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14597V-6.0.0-6.0.5"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-6.0.0-6.0.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064020.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14597V-6.0.0-6.0.5"]}]},{"cve":"CVE-2024-24789","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-1870V-18.1","P-1870V-22.1"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle TimesTen In-Memory Database","text":"36827520"}],"notes":[{"category":"description","text":"Security-in-Depth issue in Oracle TimesTen In-Memory Database (component: TimesTen Install (Golang Go)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-1870V-18.1","P-1870V-22.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1870V-18.1","P-1870V-22.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-1870V-18.1","P-1870V-22.1"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-1870V-18.1","P-1870V-22.1"]}]},{"cve":"CVE-2024-24790","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-1870V-18.1","P-1870V-22.1"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle TimesTen In-Memory Database","text":"36827520"}],"notes":[{"category":"description","text":"Security-in-Depth issue in Oracle TimesTen In-Memory Database (component: TimesTen Install (Golang Go)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-1870V-18.1","P-1870V-22.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1870V-18.1","P-1870V-22.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-1870V-18.1","P-1870V-22.1"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-1870V-18.1","P-1870V-22.1"]}]},{"cve":"CVE-2024-24791","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-13444V-21.1.2","P-1870V-18.1","P-13444V-24.1.3","P-1870V-22.1"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Blockchain Platform","text":"36979437"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment","text":"37033270"},{"system_name":"Oracle Bug ID of Oracle TimesTen In-Memory Database","text":"36827520"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (Golang Go)).  Supported versions that are affected are 24.2.0 and  24.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Cloud Native Core Network Function Cloud Native Environment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Network Function Cloud Native Environment accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Network Function Cloud Native Environment accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle Blockchain Platform (component: Blockchain Cloud Service Console (Golang Go)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle TimesTen In-Memory Database (component: TimesTen Install (Golang Go)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14125V-24.2.0","P-14125V-24.3.0"],"known_not_affected":["P-13444V-21.1.2","P-13444V-24.1.3","P-1870V-22.1","P-1870V-18.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14125V-24.2.0","P-14125V-24.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066005.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13444V-21.1.2","P-1870V-18.1","P-13444V-24.1.3","P-1870V-22.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-14125V-24.2.0","P-14125V-24.3.0"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13444V-21.1.2","P-1870V-18.1","P-13444V-24.1.3","P-1870V-22.1"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-13444V-21.1.2","P-1870V-18.1","P-13444V-24.1.3","P-1870V-22.1"]}]},{"cve":"CVE-2024-2511","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"37044734"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security, Porting, Cloud Deployment Architecture (OpenSSL)).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","version":"3.1"},"products":["P-5085V-8.61","P-5085V-8.60"]}]},{"cve":"CVE-2024-25638","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Converged Application Server","text":"37356021"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function","text":"37356008"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy","text":"37356015"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Policy","text":"37356012"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function","text":"37356003"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Installer (dnsjava)).  Supported versions that are affected are 8.0 and  8.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Converged Application Server.  While the vulnerability is in Oracle Communications Converged Application Server, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Converged Application Server accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Converged Application Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 8.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Signaling (dnsjava)).  Supported versions that are affected are 24.2.0, 24.2.1 and  24.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  While the vulnerability is in Oracle Communications Cloud Native Core Security Edge Protection Proxy, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 8.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (dnsjava)).  Supported versions that are affected are 24.2.0-24.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  While the vulnerability is in Oracle Communications Cloud Native Core Policy, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 8.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (dnsjava)).  Supported versions that are affected are 24.2.0 and  24.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  While the vulnerability is in Oracle Communications Cloud Native Core Binding Support Function, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 8.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Install (dnsjava)).   The supported version that is affected is 24.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  While the vulnerability is in Oracle Communications Cloud Native Core Network Repository Function, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Repository Function accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 8.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14277V-24.2.0-24.2.2","P-14121V-24.2.1","P-5382V-8.0","P-5382V-8.1","P-14123V-24.2.1","P-14123V-24.2.2","P-14123V-24.2.0","P-14121V-24.2.0","P-14118V-24.2.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5382V-8.0","P-5382V-8.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066019.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-24.2.1","P-14123V-24.2.2","P-14123V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-24.2.0-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066021.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-24.2.1","P-14121V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066001.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14118V-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3067478.1"}],"scores":[{"cvss_v3":{"baseScore":8.9,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L","version":"3.1"},"products":["P-14277V-24.2.0-24.2.2","P-14121V-24.2.1","P-5382V-8.0","P-5382V-8.1","P-14123V-24.2.1","P-14123V-24.2.2","P-14123V-24.2.0","P-14121V-24.2.0","P-14118V-24.2.2"]}]},{"cve":"CVE-2024-25710","ids":[{"system_name":"Oracle Bug ID of Oracle Life Sciences Empirica Signal","text":"36354311"},{"system_name":"Oracle Bug ID of Oracle Communications Messaging Server","text":"36354235"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Health Sciences Applications (component: Platform (Apache Commons Compress)).  Supported versions that are affected are Prior to 9.2.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Life Sciences Empirica Signal executes to compromise Oracle Life Sciences Empirica Signal.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Life Sciences Empirica Signal. CVSS 3.1 Base Score 5.0 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications Applications (component: Security (Apache Commons Compress)).   The supported version that is affected is 8.1.0.26. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Messaging Server executes to compromise Oracle Communications Messaging Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Messaging Server. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9646V-Prior to 9.2.3","P-8496V-8.1.0.26"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9646V-Prior to 9.2.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065955.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8496V-8.1.0.26"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065603.1"}],"scores":[{"cvss_v3":{"baseScore":5.0,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-9646V-Prior to 9.2.3"]},{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8496V-8.1.0.26"]}]},{"cve":"CVE-2024-26130","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36981631"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (OpenSSL)).   The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2024-26308","ids":[{"system_name":"Oracle Bug ID of Oracle Life Sciences Empirica Signal","text":"36354311"},{"system_name":"Oracle Bug ID of Oracle Communications Messaging Server","text":"36354235"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications Applications (component: Security (Apache Commons Compress)).   The supported version that is affected is 8.1.0.26. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Messaging Server executes to compromise Oracle Communications Messaging Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Messaging Server. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Health Sciences Applications (component: Platform (Apache Commons Compress)).  Supported versions that are affected are Prior to 9.2.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Life Sciences Empirica Signal executes to compromise Oracle Life Sciences Empirica Signal.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Life Sciences Empirica Signal. CVSS 3.1 Base Score 5.0 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8496V-8.1.0.26","P-9646V-Prior to 9.2.3"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8496V-8.1.0.26"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065603.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9646V-Prior to 9.2.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065955.1"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8496V-8.1.0.26"]},{"cvss_v3":{"baseScore":5.0,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-9646V-Prior to 9.2.3"]}]},{"cve":"CVE-2024-27280","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"36827540"},{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36827530"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Ruby)).  Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cloud Deployment Architecture, Logstash (Ruby)).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60","P-4781V-Prior to 9.2.9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["P-5085V-8.61","P-5085V-8.60","P-4781V-Prior to 9.2.9.2"]}]},{"cve":"CVE-2024-27281","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"36827540"},{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36827530"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cloud Deployment Architecture, Logstash (Ruby)).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Ruby)).  Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60","P-4781V-Prior to 9.2.9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["P-5085V-8.61","P-5085V-8.60","P-4781V-Prior to 9.2.9.2"]}]},{"cve":"CVE-2024-27282","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"36827540"},{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36827530"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Ruby)).  Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cloud Deployment Architecture, Logstash (Ruby)).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60","P-4781V-Prior to 9.2.9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["P-5085V-8.61","P-5085V-8.60","P-4781V-Prior to 9.2.9.2"]}]},{"cve":"CVE-2024-27309","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Service Catalog and Design","text":"37332068"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications Applications (component: Solution Designer (Apache Kafka)).  Supported versions that are affected are 8.0.0.3 and  8.1.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Service Catalog and Design accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Service Catalog and Design accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2283V-8.0.0.3","P-2283V-8.1.0.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2283V-8.0.0.3","P-2283V-8.1.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064016.1"}],"scores":[{"cvss_v3":{"baseScore":7.4,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"products":["P-2283V-8.0.0.3","P-2283V-8.1.0.1"]}]},{"cve":"CVE-2024-27983","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36533858"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Node.js)).  Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools as well as  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":8.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.2"]}]},{"cve":"CVE-2024-28219","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy","text":"37202929"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function","text":"37202922"},{"system_name":"Oracle Bug ID of Oracle Financial Services Compliance Studio","text":"37202955"},{"system_name":"Oracle Bug ID of Oracle Banking Liquidity Management","text":"37202914"},{"system_name":"Oracle Bug ID of Oracle Communications Operations Monitor","text":"37202948"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Policy","text":"37202927"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common (Pillow)).   The supported version that is affected is 14.7.5.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Banking Liquidity Management executes to compromise Oracle Banking Liquidity Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Pillow)).  Supported versions that are affected are 24.2.0 and  24.2.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Binding Support Function executes to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Pillow)).  Supported versions that are affected are 24.2.0-24.2.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Install (Pillow)).   The supported version that is affected is 23.4.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Security Edge Protection Proxy executes to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (Pillow)).  Supported versions that are affected are 5.1 and  5.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Operations Monitor executes to compromise Oracle Communications Operations Monitor.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Pillow)).   The supported version that is affected is 8.1.2.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Financial Services Compliance Studio executes to compromise Oracle Financial Services Compliance Studio.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Compliance Studio. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14121V-24.2.1","P-14277V-24.2.0-24.2.2","P-10761V-5.1","P-14392V-8.1.2.6","P-10761V-5.2","P-13304V-14.7.5.0.0","P-14121V-24.2.0","P-14123V-23.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13304V-14.7.5.0.0"],"url":"https://support.oracle.com"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-24.2.1","P-14121V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066001.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-24.2.0-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066021.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-23.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10761V-5.1","P-10761V-5.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066003.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14392V-8.1.2.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065911.1"}],"scores":[{"cvss_v3":{"baseScore":6.7,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-14121V-24.2.1","P-14277V-24.2.0-24.2.2","P-10761V-5.1","P-14392V-8.1.2.6","P-10761V-5.2","P-13304V-14.7.5.0.0","P-14121V-24.2.0","P-14123V-23.4.0"]}]},{"cve":"CVE-2024-28757","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Blockchain Platform","text":"37059329"}],"notes":[{"category":"description","text":"Security-in-Depth issue in Oracle Blockchain Platform (component: Blockchain Cloud Service Console (Python)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-13444V-21.1.2","P-13444V-24.1.3"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13444V-21.1.2","P-13444V-24.1.3"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}]},{"cve":"CVE-2024-28834","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Network Analytics Data Director","text":"37218564"},{"system_name":"Oracle Bug ID of Oracle Communications User Data Repository","text":"37218575"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (GnuTLS)).   The supported version that is affected is 24.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Network Analytics Data Director accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Platform (GnuTLS)).  Supported versions that are affected are 12.11 and  14.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications User Data Repository.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications User Data Repository accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-11108V-14.0","P-11108V-12.11","P-14547V-24.1.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14547V-24.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066023.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11108V-12.11","P-11108V-14.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066024.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-11108V-12.11","P-14547V-24.1.0","P-11108V-14.0"]}]},{"cve":"CVE-2024-28835","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Network Analytics Data Director","text":"37218564"},{"system_name":"Oracle Bug ID of Oracle Communications User Data Repository","text":"37218575"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (GnuTLS)).   The supported version that is affected is 24.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Network Analytics Data Director accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Platform (GnuTLS)).  Supported versions that are affected are 12.11 and  14.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications User Data Repository.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications User Data Repository accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-11108V-14.0","P-11108V-12.11","P-14547V-24.1.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14547V-24.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066023.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11108V-12.11","P-11108V-14.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066024.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-11108V-12.11","P-14547V-24.1.0","P-11108V-14.0"]}]},{"cve":"CVE-2024-28849","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Unified Assurance","text":"36917973"},{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"36917980"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Commons Configuration)).  Supported versions that are affected are 6.0.1-6.0.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards (follow-redirects)).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14597V-6.0.1-6.0.5","P-5085V-8.61","P-5085V-8.60"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-6.0.1-6.0.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-14597V-6.0.1-6.0.5","P-5085V-8.61","P-5085V-8.60"]}]},{"cve":"CVE-2024-29025","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Service Catalog and Design","text":"37332162"},{"system_name":"Oracle Bug ID of Oracle Communications Messaging Server","text":"36628199"},{"system_name":"Oracle Bug ID of Oracle BI Publisher","text":"37147990"},{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"36628231"},{"system_name":"Oracle Bug ID of Oracle Utilities Testing Accelerator","text":"36628229"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Netty)).  Supported versions that are affected are 6.0.0.1.0-6.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Utilities Testing Accelerator. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications Applications (component: Security (Netty)).   The supported version that is affected is 8.1.0.26. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Messaging Server. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch (Netty)).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications Applications (component: Solution Designer (Netty)).  Supported versions that are affected are 8.0.0.3 and  8.1.0.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Service Catalog and Design executes to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services (Snowflake JDBC)).  Supported versions that are affected are 7.0.0.0.0 and  7.6.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1479V-7.0.0.0.0","P-2283V-8.0.0.3","P-8496V-8.1.0.26","P-1479V-7.6.0.0.0","P-2283V-8.1.0.1","P-13784V-6.0.0.1.0-6.0.0.3.0","P-5085V-8.61","P-5085V-8.60"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13784V-6.0.0.1.0-6.0.0.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066725.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8496V-8.1.0.26"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065603.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2283V-8.0.0.3","P-2283V-8.1.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1479V-7.0.0.0.0","P-1479V-7.6.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["P-8496V-8.1.0.26","P-13784V-6.0.0.1.0-6.0.0.3.0","P-5085V-8.61","P-5085V-8.60"]},{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-2283V-8.0.0.3","P-2283V-8.1.0.1"]},{"cvss_v3":{"baseScore":5.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"products":["P-1479V-7.0.0.0.0","P-1479V-7.6.0.0.0"]}]},{"cve":"CVE-2024-29041","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36452353"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Express.js)).  Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":6.1,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.2"]}]},{"cve":"CVE-2024-29131","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"37194685"},{"system_name":"Oracle Bug ID of Oracle Communications Unified Assurance","text":"37222769"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security (Apache Commons Configuration)).  Supported versions that are affected are 7.0.0.0.0 and  7.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Microservices (Apache Commons Configuration)).  Supported versions that are affected are 6.0.0-6.0.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0","P-14597V-6.0.0-6.0.5"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-6.0.0-6.0.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064020.1"}],"scores":[{"cvss_v3":{"baseScore":7.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"products":["P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0"]},{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-14597V-6.0.0-6.0.5"]}]},{"cve":"CVE-2024-29133","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Unified Assurance","text":"37222769"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Microservices (Apache Commons Configuration)).  Supported versions that are affected are 6.0.0-6.0.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14597V-6.0.0-6.0.5"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-6.0.0-6.0.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064020.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-14597V-6.0.0-6.0.5"]}]},{"cve":"CVE-2024-2961","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-13444V-21.1.2"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Blockchain Platform","text":"36904043"},{"system_name":"Oracle Bug ID of Oracle Communications Diameter Signaling Router","text":"36904063"}],"notes":[{"category":"description","text":"Security-in-Depth issue in Oracle Blockchain Platform (component: Blockchain Cloud Service Console (glibc)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (glibc)).  Supported versions that are affected are 9.0.0.0.0-9.0.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Diameter Signaling Router accessible data as well as  unauthorized read access to a subset of Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10899V-9.0.0.0.0-9.0.2.0.0"],"known_not_affected":["P-13444V-21.1.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13444V-21.1.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-9.0.0.0.0-9.0.2.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066025.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13444V-21.1.2"]},{"cvss_v3":{"baseScore":7.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"products":["P-10899V-9.0.0.0.0-9.0.2.0.0"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-13444V-21.1.2"]}]},{"cve":"CVE-2024-29857","ids":[{"system_name":"Oracle Bug ID of Oracle WebLogic Server","text":"36933626"},{"system_name":"Oracle Bug ID of Oracle Enterprise Manager Base Platform","text":"36961362"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Bouncy Castle Java Library)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen (Bouncy Castle Java Library)).   The supported version that is affected is 13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5242V-12.2.1.4.0","P-5242V-14.1.1.0.0","P-1370V-13.5.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1370V-13.5.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056561.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-5242V-14.1.1.0.0","P-1370V-13.5.0.0","P-5242V-12.2.1.4.0"]}]},{"cve":"CVE-2024-30171","ids":[{"system_name":"Oracle Bug ID of Oracle WebLogic Server","text":"36933626"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Bouncy Castle Java Library)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.4.0"]}]},{"cve":"CVE-2024-30172","ids":[{"system_name":"Oracle Bug ID of Oracle WebLogic Server","text":"36933626"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Bouncy Castle Java Library)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.4.0"]}]},{"cve":"CVE-2024-33599","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-13444V-21.1.2"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Blockchain Platform","text":"36904043"},{"system_name":"Oracle Bug ID of Oracle Communications Diameter Signaling Router","text":"36904063"}],"notes":[{"category":"description","text":"Security-in-Depth issue in Oracle Blockchain Platform (component: Blockchain Cloud Service Console (glibc)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (glibc)).  Supported versions that are affected are 9.0.0.0.0-9.0.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Diameter Signaling Router accessible data as well as  unauthorized read access to a subset of Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10899V-9.0.0.0.0-9.0.2.0.0"],"known_not_affected":["P-13444V-21.1.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13444V-21.1.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-9.0.0.0.0-9.0.2.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066025.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13444V-21.1.2"]},{"cvss_v3":{"baseScore":7.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"products":["P-10899V-9.0.0.0.0-9.0.2.0.0"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-13444V-21.1.2"]}]},{"cve":"CVE-2024-33600","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-13444V-21.1.2"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Blockchain Platform","text":"36904043"},{"system_name":"Oracle Bug ID of Oracle Communications Diameter Signaling Router","text":"36904063"}],"notes":[{"category":"description","text":"Security-in-Depth issue in Oracle Blockchain Platform (component: Blockchain Cloud Service Console (glibc)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (glibc)).  Supported versions that are affected are 9.0.0.0.0-9.0.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Diameter Signaling Router accessible data as well as  unauthorized read access to a subset of Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10899V-9.0.0.0.0-9.0.2.0.0"],"known_not_affected":["P-13444V-21.1.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13444V-21.1.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-9.0.0.0.0-9.0.2.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066025.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13444V-21.1.2"]},{"cvss_v3":{"baseScore":7.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"products":["P-10899V-9.0.0.0.0-9.0.2.0.0"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-13444V-21.1.2"]}]},{"cve":"CVE-2024-33601","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-13444V-21.1.2"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Blockchain Platform","text":"36904043"},{"system_name":"Oracle Bug ID of Oracle Communications Diameter Signaling Router","text":"36904063"}],"notes":[{"category":"description","text":"Security-in-Depth issue in Oracle Blockchain Platform (component: Blockchain Cloud Service Console (glibc)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (glibc)).  Supported versions that are affected are 9.0.0.0.0-9.0.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Diameter Signaling Router accessible data as well as  unauthorized read access to a subset of Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10899V-9.0.0.0.0-9.0.2.0.0"],"known_not_affected":["P-13444V-21.1.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13444V-21.1.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-9.0.0.0.0-9.0.2.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066025.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13444V-21.1.2"]},{"cvss_v3":{"baseScore":7.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"products":["P-10899V-9.0.0.0.0-9.0.2.0.0"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-13444V-21.1.2"]}]},{"cve":"CVE-2024-33602","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-13444V-21.1.2"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Blockchain Platform","text":"36904043"},{"system_name":"Oracle Bug ID of Oracle Communications Diameter Signaling Router","text":"36904063"}],"notes":[{"category":"description","text":"Security-in-Depth issue in Oracle Blockchain Platform (component: Blockchain Cloud Service Console (glibc)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (glibc)).  Supported versions that are affected are 9.0.0.0.0-9.0.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Diameter Signaling Router accessible data as well as  unauthorized read access to a subset of Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10899V-9.0.0.0.0-9.0.2.0.0"],"known_not_affected":["P-13444V-21.1.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13444V-21.1.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-9.0.0.0.0-9.0.2.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066025.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13444V-21.1.2"]},{"cvss_v3":{"baseScore":7.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"products":["P-10899V-9.0.0.0.0-9.0.2.0.0"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-13444V-21.1.2"]}]},{"cve":"CVE-2024-34064","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Operations Monitor","text":"37160621"},{"system_name":"Oracle Bug ID of Oracle Banking Origination","text":"37160588"},{"system_name":"Oracle Bug ID of Oracle Banking Liquidity Management","text":"37160584"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository","text":"37160609"},{"system_name":"Oracle Bug ID of Oracle Banking Corporate Lending Process Management","text":"37160581"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy","text":"37160606"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function","text":"37160590"},{"system_name":"Oracle Bug ID of Oracle Financial Services Compliance Studio","text":"37160626"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy","text":"37160604"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Policy","text":"37160602"},{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36981651"},{"system_name":"Oracle Bug ID of Oracle Communications User Data Repository","text":"37160623"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Jinja)).   The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Jinja)).  Supported versions that are affected are 14.4.0.0.0-14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Corporate Lending Process Management accessible data as well as  unauthorized read access to a subset of Oracle Banking Corporate Lending Process Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Jinja)).   The supported version that is affected is 8.1.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Compliance Studio accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Compliance Studio accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Platform (Jinja)).   The supported version that is affected is 14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications User Data Repository.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications User Data Repository accessible data as well as  unauthorized read access to a subset of Oracle Communications User Data Repository accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (Jinja)).  Supported versions that are affected are 5.1 and  5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Operations Monitor accessible data as well as  unauthorized read access to a subset of Oracle Communications Operations Monitor accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: ATS Framework (Jinja)).  Supported versions that are affected are 23.4.4, 24.1.1, 24.2.2 and  24.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Unified Data Repository accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Unified Data Repository accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Jinja)).  Supported versions that are affected are 24.2.0 and  24.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Service Communication Proxy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Service Communication Proxy accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: ATS Framework (Jinja)).  Supported versions that are affected are 24.2.0 and  24.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Jinja)).  Supported versions that are affected are 24.2.0-24.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Jinja)).  Supported versions that are affected are 24.2.0 and  24.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Maintenance (Jinja)).  Supported versions that are affected are 14.5.0.0.0-14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Origination accessible data as well as  unauthorized read access to a subset of Oracle Banking Origination accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common (Jinja)).   The supported version that is affected is 14.7.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Liquidity Management accessible data as well as  unauthorized read access to a subset of Oracle Banking Liquidity Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14119V-23.4.4","P-14277V-24.2.0-24.2.2","P-14121V-24.2.1","P-13304V-14.7.5.0.0","P-14123V-24.2.1","P-14123V-24.2.0","P-13701V-14.4.0.0.0-14.7.0.0.0","P-14392V-8.1.2.6","P-10761V-5.1","P-14119V-24.2.2","P-14119V-24.3.0","P-14119V-24.1.1","P-14117V-24.2.0","P-14117V-24.3.0","P-10761V-5.2","P-14325V-14.5.0.0.0-14.7.0.0.0","P-2025V-7.0.0.0.0","P-11108V-14.0","P-14121V-24.2.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13701V-14.4.0.0.0-14.7.0.0.0","P-14325V-14.5.0.0.0-14.7.0.0.0","P-13304V-14.7.5.0.0"],"url":"https://support.oracle.com"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14392V-8.1.2.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065911.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11108V-14.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066024.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10761V-5.1","P-10761V-5.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066003.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14119V-23.4.4","P-14119V-24.2.2","P-14119V-24.3.0","P-14119V-24.1.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066908.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14117V-24.2.0","P-14117V-24.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066004.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-24.2.1","P-14123V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-24.2.0-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066021.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-24.2.1","P-14121V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066001.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-14119V-23.4.4","P-14277V-24.2.0-24.2.2","P-14121V-24.2.1","P-13304V-14.7.5.0.0","P-14123V-24.2.1","P-14123V-24.2.0","P-13701V-14.4.0.0.0-14.7.0.0.0","P-14392V-8.1.2.6","P-10761V-5.1","P-14119V-24.2.2","P-14119V-24.3.0","P-14119V-24.1.1","P-14117V-24.2.0","P-14117V-24.3.0","P-10761V-5.2","P-14325V-14.5.0.0.0-14.7.0.0.0","P-2025V-7.0.0.0.0","P-11108V-14.0","P-14121V-24.2.0"]}]},{"cve":"CVE-2024-34447","ids":[{"system_name":"Oracle Bug ID of Oracle WebLogic Server","text":"36933626"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Bouncy Castle Java Library)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.4.0"]}]},{"cve":"CVE-2024-34750","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_cannot_be_controlled_by_adversary","product_ids":["P-14121V-24.2.1","P-14277V-24.2.0-24.2.2","P-14121V-24.2.0"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Financial Services Model Management and Governance","text":"37085541"},{"system_name":"Oracle Bug ID of Oracle Managed File Transfer","text":"37085511"},{"system_name":"Oracle Bug ID of Oracle SD-WAN Edge","text":"37085555"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function","text":"37394271"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Policy","text":"37085527"},{"system_name":"Oracle Bug ID of Oracle Agile Engineering Data Management","text":"37085515"},{"system_name":"Oracle Bug ID of Oracle Communications EAGLE Element Management System","text":"37085529"},{"system_name":"Oracle Bug ID of Oracle Communications Diameter Signaling Router","text":"37085528"},{"system_name":"Oracle Bug ID of Oracle Utilities Testing Accelerator","text":"37085561"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Tomcat)).  Supported versions that are affected are 8.1.2.6, 8.1.2.7 and  8.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Security (Apache Tomcat)).   The supported version that is affected is 47.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications EAGLE Element Management System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications EAGLE Element Management System. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Patches (Apache Tomcat)).   The supported version that is affected is 8.6.0.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Document Management (Apache Tomcat)).   The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Agile Engineering Data Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server (Apache Tomcat)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Managed File Transfer.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Managed File Transfer. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Apache Tomcat)).  Supported versions that are affected are 6.0.0.1.0-6.0.0.3.0 and  7.0.0.0.0-7.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Testing Accelerator. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Platform (Apache Tomcat)).  Supported versions that are affected are 9.1.1.0-9.1.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle SD-WAN Edge.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Edge. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14276V-8.1.2.7","P-10899V-8.6.0.4.0","P-11125V-47.0.0.0.0","P-10198V-12.2.1.4.0","P-13784V-6.0.0.1.0-6.0.0.3.0","P-14276V-8.1.3.0","P-13784V-7.0.0.0.0-7.0.0.1.0","P-4436V-6.2.1","P-13940V-9.1.1.0-9.1.1.8","P-14276V-8.1.2.6"],"known_not_affected":["P-14121V-24.2.1","P-14277V-24.2.0-24.2.2","P-14121V-24.2.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14276V-8.1.2.7","P-14276V-8.1.3.0","P-14276V-8.1.2.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066624.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11125V-47.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066028.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-8.6.0.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066025.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-24.2.1","P-14121V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066001.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4436V-6.2.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065151.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10198V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13784V-6.0.0.1.0-6.0.0.3.0","P-13784V-7.0.0.0.0-7.0.0.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066725.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13940V-9.1.1.0-9.1.1.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066026.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-24.2.0-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066021.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14276V-8.1.2.7","P-10899V-8.6.0.4.0","P-11125V-47.0.0.0.0","P-10198V-12.2.1.4.0","P-13784V-6.0.0.1.0-6.0.0.3.0","P-14276V-8.1.3.0","P-13784V-7.0.0.0.0-7.0.0.1.0","P-4436V-6.2.1","P-13940V-9.1.1.0-9.1.1.8","P-14276V-8.1.2.6"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-14121V-24.2.1","P-14277V-24.2.0-24.2.2","P-14121V-24.2.0"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.","product_ids":["P-14121V-24.2.1","P-14277V-24.2.0-24.2.2","P-14121V-24.2.0"]}]},{"cve":"CVE-2024-35195","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-8478(Shell General / Core Client)V-8.0.40 and prior","P-8478(Shell General / Core Client)V-9.1.0 and prior","P-8478(Shell General / Core Client)V-8.4.3 and prior"]}],"ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"37182652"},{"system_name":"Oracle Bug ID of Oracle Communications Offline Mediation Controller","text":"37182059"},{"system_name":"Oracle Bug ID of Oracle Financial Services Compliance Studio","text":"37182356"},{"system_name":"Oracle Bug ID of Oracle Utilities Network Management System","text":"37182424"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core DBTier","text":"37182028"},{"system_name":"Oracle Bug ID of Oracle Communications Unified Assurance","text":"37182336"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy","text":"37182043"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository","text":"37182044"},{"system_name":"Oracle Bug ID of MySQL Shell","text":"37182001"},{"system_name":"Oracle Bug ID of Oracle Banking Liquidity Management","text":"37182013"},{"system_name":"Oracle Bug ID of Oracle Communications Operations Monitor","text":"37182061"},{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36981721"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy","text":"37182042"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (requests)).   The supported version that is affected is 7.0.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the MySQL Shell product of Oracle MySQL (component: Shell General / Core Client (requests)). For supported versions that are affected see note. This vulnerability cannot be exploited in the context of this product. Note: The component is included as part of the python distribution bundled with the package, and is updated for this CVE.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Porting (requests)).  Supported versions that are affected are 8.60 and  8.61. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Third Party (requests)).  Supported versions that are affected are 2.5.0.1.14, 2.5.0.2.9 and  2.6.0.1.5. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Utilities Network Management System executes to compromise Oracle Utilities Network Management System.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Network Management System accessible data as well as  unauthorized access to critical data or complete access to all Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common (requests)).   The supported version that is affected is 14.7.5.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Liquidity Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Banking Liquidity Management accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (requests)).   The supported version that is affected is 24.1.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core DBTier executes to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core DBTier accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core DBTier accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: ATS Framework (requests)).   The supported version that is affected is 24.2.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Security Edge Protection Proxy executes to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (requests)).  Supported versions that are affected are 24.2.0 and  24.3.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Service Communication Proxy executes to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Service Communication Proxy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Service Communication Proxy accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (requests)).  Supported versions that are affected are 24.3.0 and  24.2.2. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Unified Data Repository executes to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Unified Data Repository accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Unified Data Repository accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications Applications (component: Install (requests)).  Supported versions that are affected are 12.0.0.8, 15.0.0.0 and  15.0.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Offline Mediation Controller.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Offline Mediation Controller accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Offline Mediation Controller accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (requests)).  Supported versions that are affected are 5.1 and  5.2. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Operations Monitor executes to compromise Oracle Communications Operations Monitor.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Operations Monitor accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Operations Monitor accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (requests)).  Supported versions that are affected are 6.0.0-6.0.5. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (requests)).   The supported version that is affected is 8.1.2.6. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data as well as  unauthorized access to critical data or complete access to all Oracle Financial Services Compliance Studio accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2269V-15.0.0.0","P-2269V-15.0.1.0","P-14597V-6.0.0-6.0.5","P-14974V-24.1.0","P-13304V-14.7.5.0.0","P-2241V-2.6.0.1.5","P-14123V-24.2.0","P-2241V-2.5.0.2.9","P-2241V-2.5.0.1.14","P-14119V-24.2.2","P-10761V-5.1","P-14392V-8.1.2.6","P-14119V-24.3.0","P-14117V-24.2.0","P-14117V-24.3.0","P-10761V-5.2","P-2269V-12.0.0.8","P-2025V-7.0.0.0.0","P-5085V-8.61","P-5085V-8.60"],"known_not_affected":["P-8478(Shell General / Core Client)V-8.0.40 and prior","P-8478(Shell General / Core Client)V-9.1.0 and prior","P-8478(Shell General / Core Client)V-8.4.3 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Shell General / Core Client)V-8.0.40 and prior","P-8478(Shell General / Core Client)V-9.1.0 and prior","P-8478(Shell General / Core Client)V-8.4.3 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2241V-2.5.0.1.14","P-2241V-2.6.0.1.5","P-2241V-2.5.0.2.9"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066725.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13304V-14.7.5.0.0"],"url":"https://support.oracle.com"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14974V-24.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066027.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14117V-24.2.0","P-14117V-24.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066004.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14119V-24.2.2","P-14119V-24.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066908.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2269V-15.0.0.0","P-2269V-15.0.1.0","P-2269V-12.0.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064001.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10761V-5.1","P-10761V-5.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066003.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-6.0.0-6.0.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14392V-8.1.2.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065911.1"}],"scores":[{"cvss_v3":{"baseScore":5.6,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N","version":"3.1"},"products":["P-14974V-24.1.0","P-2241V-2.6.0.1.5","P-14123V-24.2.0","P-2241V-2.5.0.2.9","P-2241V-2.5.0.1.14","P-14119V-24.2.2","P-10761V-5.1","P-14119V-24.3.0","P-14117V-24.2.0","P-14117V-24.3.0","P-10761V-5.2","P-2025V-7.0.0.0.0","P-5085V-8.61","P-5085V-8.60"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-8478(Shell General / Core Client)V-8.0.40 and prior","P-8478(Shell General / Core Client)V-9.1.0 and prior","P-8478(Shell General / Core Client)V-8.4.3 and prior"]},{"cvss_v3":{"baseScore":5.7,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N","version":"3.1"},"products":["P-14392V-8.1.2.6","P-2269V-15.0.0.0","P-2269V-15.0.1.0","P-14597V-6.0.0-6.0.5","P-13304V-14.7.5.0.0","P-2269V-12.0.0.8"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-8478(Shell General / Core Client)V-8.0.40 and prior","P-8478(Shell General / Core Client)V-9.1.0 and prior","P-8478(Shell General / Core Client)V-8.4.3 and prior"]}]},{"cve":"CVE-2024-3596","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_cannot_be_controlled_by_adversary","product_ids":["P-14868V-24.2.1"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Communications Operations Monitor","text":"37240866"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management","text":"37381477"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Console","text":"37425577"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (pyrad)).  Supported versions that are affected are 5.1 and  5.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Radius to compromise Oracle Communications Operations Monitor.  While the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (Kerberos)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (Kerberos)).   The supported version that is affected is 24.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  While the vulnerability is in Oracle Communications Cloud Native Core Console, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14250V-24.2.1","P-10761V-5.1","P-10761V-5.2"],"known_not_affected":["P-14868V-24.2.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10761V-5.1","P-10761V-5.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066003.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14868V-24.2.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066002.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14250V-24.2.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066907.1"}],"scores":[{"cvss_v3":{"baseScore":9.0,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"products":["P-14250V-24.2.1","P-10761V-5.1","P-10761V-5.2"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-14868V-24.2.1"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.","product_ids":["P-14868V-24.2.1"]}]},{"cve":"CVE-2024-36114","ids":[{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"37148150"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Aircompressor)).  Supported versions that are affected are 7.0.0.0.0 and  7.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition as well as  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data and  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":8.6,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","version":"3.1"},"products":["P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0"]}]},{"cve":"CVE-2024-36137","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"36908308"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch (Node.js)).  Supported versions that are affected are 8.60 and  8.61. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 6.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H","version":"3.1"},"products":["P-5085V-8.61","P-5085V-8.60"]}]},{"cve":"CVE-2024-36138","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"36908308"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch (Node.js)).  Supported versions that are affected are 8.60 and  8.61. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 6.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H","version":"3.1"},"products":["P-5085V-8.61","P-5085V-8.60"]}]},{"cve":"CVE-2024-37370","ids":[{"system_name":"Oracle Bug ID of Oracle Security Service","text":"37288939"},{"system_name":"Oracle Bug ID of Oracle Communications Diameter Signaling Router","text":"37034622"},{"system_name":"Oracle Bug ID of MySQL Server","text":"37034600"},{"system_name":"Oracle Bug ID of Oracle SD-WAN Edge","text":"37034638"},{"system_name":"Oracle Bug ID of Oracle Communications Billing and Revenue Management","text":"37034606"},{"system_name":"Oracle Bug ID of Oracle Communications User Data Repository","text":"37034625"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Platform (Kerberos)).  Supported versions that are affected are 12.11 and  14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications User Data Repository.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications User Data Repository accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications User Data Repository. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (Kerberos)).  Supported versions that are affected are 9.0.0.0.0-9.0.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Platform (Kerberos)).  Supported versions that are affected are 12.0.0.4-12.0.0.8 and  15.0.0.0-15.0.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Billing and Revenue Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging (Kerberos)).  Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and  9.0.1 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Internal tools (Kerberos)).  Supported versions that are affected are 9.1.1.5-9.1.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SD-WAN Edge.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle SD-WAN Edge accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Edge. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Security Toolkit (Kerberos)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Security Service.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Security Service accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Security Service. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10899V-9.0.0.0.0-9.0.2.0.0","P-2136(Platform)V-15.0.0.0-15.0.0.1","P-13940V-9.1.1.5-9.1.1.8","P-11108V-12.11","P-8478(Server: Packaging)V-8.0.39 and prior","P-991V-12.2.1.4.0","P-8478(Server: Packaging)V-8.4.2 and prior","P-11108V-14.0","P-8478(Server: Packaging)V-9.0.1 and prior","P-2136(Platform)V-12.0.0.4-12.0.0.8"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11108V-12.11","P-11108V-14.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066024.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-9.0.0.0.0-9.0.2.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066025.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2136(Platform)V-15.0.0.0-15.0.0.1","P-2136(Platform)V-12.0.0.4-12.0.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064003.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Packaging)V-8.0.39 and prior","P-8478(Server: Packaging)V-8.4.2 and prior","P-8478(Server: Packaging)V-9.0.1 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13940V-9.1.1.5-9.1.1.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066026.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-991V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","version":"3.1"},"products":["P-10899V-9.0.0.0.0-9.0.2.0.0","P-2136(Platform)V-15.0.0.0-15.0.0.1","P-13940V-9.1.1.5-9.1.1.8","P-11108V-12.11","P-8478(Server: Packaging)V-8.0.39 and prior","P-991V-12.2.1.4.0","P-8478(Server: Packaging)V-8.4.2 and prior","P-11108V-14.0","P-8478(Server: Packaging)V-9.0.1 and prior","P-2136(Platform)V-12.0.0.4-12.0.0.8"]}]},{"cve":"CVE-2024-37371","ids":[{"system_name":"Oracle Bug ID of Oracle Security Service","text":"37288939"},{"system_name":"Oracle Bug ID of Oracle Communications Diameter Signaling Router","text":"37034622"},{"system_name":"Oracle Bug ID of MySQL Server","text":"37034600"},{"system_name":"Oracle Bug ID of Oracle SD-WAN Edge","text":"37034638"},{"system_name":"Oracle Bug ID of Oracle Communications Billing and Revenue Management","text":"37034606"},{"system_name":"Oracle Bug ID of Oracle Communications User Data Repository","text":"37034625"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Platform (Kerberos)).  Supported versions that are affected are 12.11 and  14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications User Data Repository.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications User Data Repository accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications User Data Repository. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (Kerberos)).  Supported versions that are affected are 9.0.0.0.0-9.0.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Platform (Kerberos)).  Supported versions that are affected are 12.0.0.4-12.0.0.8 and  15.0.0.0-15.0.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Billing and Revenue Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging (Kerberos)).  Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and  9.0.1 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Internal tools (Kerberos)).  Supported versions that are affected are 9.1.1.5-9.1.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SD-WAN Edge.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle SD-WAN Edge accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Edge. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Security Toolkit (Kerberos)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Security Service.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Security Service accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Security Service. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10899V-9.0.0.0.0-9.0.2.0.0","P-2136(Platform)V-15.0.0.0-15.0.0.1","P-13940V-9.1.1.5-9.1.1.8","P-11108V-12.11","P-8478(Server: Packaging)V-8.0.39 and prior","P-991V-12.2.1.4.0","P-8478(Server: Packaging)V-8.4.2 and prior","P-11108V-14.0","P-8478(Server: Packaging)V-9.0.1 and prior","P-2136(Platform)V-12.0.0.4-12.0.0.8"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11108V-12.11","P-11108V-14.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066024.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-9.0.0.0.0-9.0.2.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066025.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2136(Platform)V-15.0.0.0-15.0.0.1","P-2136(Platform)V-12.0.0.4-12.0.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064003.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Packaging)V-8.0.39 and prior","P-8478(Server: Packaging)V-8.4.2 and prior","P-8478(Server: Packaging)V-9.0.1 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13940V-9.1.1.5-9.1.1.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066026.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-991V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","version":"3.1"},"products":["P-10899V-9.0.0.0.0-9.0.2.0.0","P-2136(Platform)V-15.0.0.0-15.0.0.1","P-13940V-9.1.1.5-9.1.1.8","P-11108V-12.11","P-8478(Server: Packaging)V-8.0.39 and prior","P-991V-12.2.1.4.0","P-8478(Server: Packaging)V-8.4.2 and prior","P-11108V-14.0","P-8478(Server: Packaging)V-9.0.1 and prior","P-2136(Platform)V-12.0.0.4-12.0.0.8"]}]},{"cve":"CVE-2024-37372","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"36908308"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch (Node.js)).  Supported versions that are affected are 8.60 and  8.61. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 6.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H","version":"3.1"},"products":["P-5085V-8.61","P-5085V-8.60"]}]},{"cve":"CVE-2024-37891","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Billing and Revenue Management","text":"37362104"},{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"37086412"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Policy","text":"37362113"},{"system_name":"Oracle Bug ID of Oracle Utilities Network Management System","text":"37362328"},{"system_name":"Oracle Bug ID of Oracle Communications Unified Assurance","text":"37362163"},{"system_name":"Oracle Bug ID of Oracle Communications Policy Management","text":"37362160"},{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36981693"},{"system_name":"Oracle Bug ID of Oracle Communications User Data Repository","text":"37362164"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Porting (urllib3)).  Supported versions that are affected are 8.60 and  8.61. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care (urllib3)).  Supported versions that are affected are 12.0.0.4-12.0.0.8 and  15.0.0.0-15.0.0.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Third Party (urllib3)).  Supported versions that are affected are 2.5.0.1.15, 2.5.0.2.9 and  2.6.0.1.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (urllib3)).   The supported version that is affected is 15.0.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Policy Management accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (urllib3)).  Supported versions that are affected are 6.0.0-6.0.5. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Platform (urllib3)).  Supported versions that are affected are 12.11, 14.0 and  15.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications User Data Repository.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications User Data Repository accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (urllib3)).   The supported version that is affected is 7.0.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (urllib3)).  Supported versions that are affected are 24.2.0-24.2.2. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14277V-24.2.0-24.2.2","P-2136(Billing Care)V-15.0.0.0-15.0.0.1","P-14597V-6.0.0-6.0.5","P-2241V-2.6.0.1.7","P-2241V-2.5.0.2.9","P-2241V-2.5.0.1.15","P-11108V-12.11","P-2136(Billing Care)V-12.0.0.4-12.0.0.8","P-10900V-15.0.0.0.0","P-11108V-15.0","P-11108V-14.0","P-2025V-7.0.0.0.0","P-5085V-8.61","P-5085V-8.60"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2136(Billing Care)V-15.0.0.0-15.0.0.1","P-2136(Billing Care)V-12.0.0.4-12.0.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064003.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2241V-2.5.0.1.15","P-2241V-2.6.0.1.7","P-2241V-2.5.0.2.9"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066725.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10900V-15.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-6.0.0-6.0.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11108V-12.11","P-11108V-15.0","P-11108V-14.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066024.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-24.2.0-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066021.1"}],"scores":[{"cvss_v3":{"baseScore":4.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-14277V-24.2.0-24.2.2","P-2136(Billing Care)V-15.0.0.0-15.0.0.1","P-14597V-6.0.0-6.0.5","P-2241V-2.6.0.1.7","P-2241V-2.5.0.2.9","P-2241V-2.5.0.1.15","P-11108V-12.11","P-2136(Billing Care)V-12.0.0.4-12.0.0.8","P-10900V-15.0.0.0.0","P-11108V-15.0","P-11108V-14.0","P-2025V-7.0.0.0.0","P-5085V-8.61","P-5085V-8.60"]}]},{"cve":"CVE-2024-38473","ids":[{"system_name":"Oracle Bug ID of Oracle HTTP Server","text":"37042942"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Mod_rewrite, Core (Apache HTTP Server)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data as well as  unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1042(Mod_rewrite, Core)V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042(Mod_rewrite, Core)V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"products":["P-1042(Mod_rewrite, Core)V-12.2.1.4.0"]}]},{"cve":"CVE-2024-38475","ids":[{"system_name":"Oracle Bug ID of Oracle HTTP Server","text":"37042942"},{"system_name":"Oracle Bug ID of Oracle SD-WAN Edge","text":"36989989"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Platform (Apache HTTP Server)).  Supported versions that are affected are 9.1.1.5-9.1.1.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SD-WAN Edge.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle SD-WAN Edge accessible data as well as  unauthorized update, insert or delete access to some of Oracle SD-WAN Edge accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Mod_rewrite, Core (Apache HTTP Server)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data as well as  unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1042(Mod_rewrite, Core)V-12.2.1.4.0","P-13940V-9.1.1.5-9.1.1.9"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13940V-9.1.1.5-9.1.1.9"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066026.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042(Mod_rewrite, Core)V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":8.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","version":"3.1"},"products":["P-13940V-9.1.1.5-9.1.1.9"]},{"cvss_v3":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"products":["P-1042(Mod_rewrite, Core)V-12.2.1.4.0"]}]},{"cve":"CVE-2024-38526","ids":[{"system_name":"Oracle Bug ID of Siebel CRM End User","text":"36846738"}],"notes":[{"category":"description","text":"Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: EAI, UI (Oxygen XML WebHelp)).  Supported versions that are affected are 24.11 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User.  While the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Siebel CRM End User accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM End User. CVSS 3.1 Base Score 7.2 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9011V-24.11 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9011V-24.11 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065150.1"}],"scores":[{"cvss_v3":{"baseScore":7.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L","version":"3.1"},"products":["P-9011V-24.11 and prior"]}]},{"cve":"CVE-2024-38807","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Service Catalog and Design","text":"37332193"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Console","text":"37425645"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications Applications (component: Solution Designer (Spring Boot)).  Supported versions that are affected are 8.0.0.3 and  8.1.0.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Service Catalog and Design executes to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Service Catalog and Design accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Service Catalog and Design accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (Spring Boot)).   The supported version that is affected is 24.2.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Console executes to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Console accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Console accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14250V-24.2.1","P-2283V-8.0.0.3","P-2283V-8.1.0.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2283V-8.0.0.3","P-2283V-8.1.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14250V-24.2.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066907.1"}],"scores":[{"cvss_v3":{"baseScore":6.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"products":["P-14250V-24.2.1","P-2283V-8.0.0.3","P-2283V-8.1.0.1"]}]},{"cve":"CVE-2024-38809","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy","text":"37366309"},{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36966313"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server, Pipeline Test Failures, Installation (Spring Framework)).  Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Signaling (Spring Security)).   The supported version that is affected is 24.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0","P-2025V-12.2.1.4.0","P-14123V-24.2.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-12.2.1.4.0","P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066020.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["P-2025V-12.2.1.4.0","P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0"]},{"cvss_v3":{"baseScore":4.8,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-14123V-24.2.0"]}]},{"cve":"CVE-2024-38816","ids":[{"system_name":"Oracle Bug ID of Oracle Identity Manager","text":"37260085"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function","text":"37259993"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy","text":"37260000"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Policy","text":"37259999"},{"system_name":"Oracle Bug ID of Oracle Middleware Common Libraries and Tools","text":"37062680"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository","text":"37260003"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).  Supported versions that are affected are 24.2.0 and  24.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).  Supported versions that are affected are 24.2.0-24.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Signaling (Spring Framework)).  Supported versions that are affected are 24.2.0, 24.2.1 and  24.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).  Supported versions that are affected are 24.3.0 and 24.2.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Unified Data Repository accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Installer (Spring Framework)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Spring Framework)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14119V-24.2.3","P-14121V-24.2.1","P-14277V-24.2.0-24.2.2","P-14119V-24.3.0","P-1980V-12.2.1.4.0","P-14123V-24.2.1","P-4647V-12.2.1.4.0","P-14123V-24.2.2","P-14123V-24.2.0","P-14121V-24.2.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-24.2.1","P-14121V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066001.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-24.2.0-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066021.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-24.2.1","P-14123V-24.2.2","P-14123V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14119V-24.2.3","P-14119V-24.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066908.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1980V-12.2.1.4.0","P-4647V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-14119V-24.2.3","P-14121V-24.2.1","P-14277V-24.2.0-24.2.2","P-14119V-24.3.0","P-1980V-12.2.1.4.0","P-14123V-24.2.1","P-4647V-12.2.1.4.0","P-14123V-24.2.2","P-14123V-24.2.0","P-14121V-24.2.0"]}]},{"cve":"CVE-2024-38819","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-5760V-19.1.0.0.0-19.1.0.0.18","P-14117V-24.2.0","P-14117V-24.3.0"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Financial Services Behavior Detection Platform","text":"37260019"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function","text":"37259993"},{"system_name":"Oracle Bug ID of Oracle Middleware Common Libraries and Tools","text":"37062680"},{"system_name":"Oracle Bug ID of Oracle Financial Services Model Management and Governance","text":"37385567"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Policy","text":"37259999"},{"system_name":"Oracle Bug ID of Oracle Identity Manager","text":"37260085"},{"system_name":"Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters","text":"37260075"},{"system_name":"Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition","text":"37260071"},{"system_name":"Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure","text":"37260018"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy","text":"37260000"},{"system_name":"Oracle Bug ID of Oracle Financial Services Compliance Studio","text":"37260022"},{"system_name":"Oracle Bug ID of Oracle Retail Financial Integration","text":"37260100"},{"system_name":"Oracle Bug ID of Oracle Retail Integration Bus","text":"37260111"},{"system_name":"Oracle Bug ID of Oracle Utilities Testing Accelerator","text":"37260122"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy","text":"37260002"},{"system_name":"Oracle Bug ID of Enterprise Manager for MySQL Database","text":"37260013"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository","text":"37260003"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Spring Framework)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Spring Framework)).   The supported version that is affected is 8.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Model Management and Governance accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).  Supported versions that are affected are 24.2.0-24.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Signaling (Spring Framework)).  Supported versions that are affected are 24.2.0, 24.2.1 and  24.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Signaling (Spring Framework)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).  Supported versions that are affected are 24.3.0 and 24.2.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Unified Data Repository accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Enterprise Manager for MySQL Database product of Oracle Enterprise Manager (component: EM Plugin: General (Spring Framework)).   The supported version that is affected is 13.5.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager for MySQL Database.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Enterprise Manager for MySQL Database accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Spring Framework)).  Supported versions that are affected are 8.0.7.8, 8.0.8.6 and  8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (Spring Framework)).  Supported versions that are affected are 8.0.8.1, 8.1.2.7 and  8.1.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Behavior Detection Platform accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Spring Framework)).   The supported version that is affected is 8.1.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Compliance Studio accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (Spring Framework)).   The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Application Adapters (Spring Framework)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Installer (Spring Framework)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration Bugs (Spring Framework)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3.0 and  19.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Financial Integration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3.0 and  19.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Integration Bus accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 6.0.0.1.0-6.0.0.3.0 and  7.0.0.0.0-7.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Utilities Testing Accelerator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).  Supported versions that are affected are 24.2.0 and  24.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14277V-24.2.0-24.2.2","P-14121V-24.2.1","P-13789V-8.0.8","P-10722V-15.0.3.1","P-5680V-8.0.8.6","P-14123V-24.2.1","P-14123V-24.2.2","P-13784V-7.0.0.0.0-7.0.0.1.0","P-14123V-24.2.0","P-14119V-24.2.3","P-14392V-8.1.2.6","P-14119V-24.3.0","P-1980V-12.2.1.4.0","P-9190V-8.0.8.1","P-11166V-13.5.2.0.0","P-14276V-8.1.3.0","P-10722V-19.0.1.0","P-1807V-14.1.3.2","P-1807V-16.0.3.0","P-14121V-24.2.0","P-9190V-8.1.2.7","P-9190V-8.1.2.8","P-10722V-16.0.3.0","P-13784V-6.0.0.1.0-6.0.0.3.0","P-10722V-14.1.3.2","P-1807V-19.0.1.0","P-5680V-8.1.2.5","P-1807V-15.0.3.1","P-4647V-12.2.1.4.0","P-5680V-8.0.7.8"],"known_not_affected":["P-5760V-19.1.0.0.0-19.1.0.0.18","P-14117V-24.2.0","P-14117V-24.3.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1980V-12.2.1.4.0","P-4647V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14276V-8.1.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066624.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-24.2.0-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066021.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-24.2.1","P-14123V-24.2.2","P-14123V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14117V-24.2.0","P-14117V-24.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066004.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14119V-24.2.3","P-14119V-24.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066908.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11166V-13.5.2.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056561.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5680V-8.1.2.5","P-5680V-8.0.8.6","P-5680V-8.0.7.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065940.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9190V-8.1.2.7","P-9190V-8.0.8.1","P-9190V-8.1.2.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066717.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14392V-8.1.2.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065911.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13789V-8.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066716.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5760V-19.1.0.0.0-19.1.0.0.18"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10722V-15.0.3.1","P-1807V-15.0.3.1","P-10722V-16.0.3.0","P-10722V-19.0.1.0","P-10722V-14.1.3.2","P-1807V-14.1.3.2","P-1807V-16.0.3.0","P-1807V-19.0.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3062129.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13784V-6.0.0.1.0-6.0.0.3.0","P-13784V-7.0.0.0.0-7.0.0.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066725.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-24.2.1","P-14121V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066001.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-14277V-24.2.0-24.2.2","P-14121V-24.2.1","P-13789V-8.0.8","P-10722V-15.0.3.1","P-5680V-8.0.8.6","P-14123V-24.2.1","P-14123V-24.2.2","P-13784V-7.0.0.0.0-7.0.0.1.0","P-14123V-24.2.0","P-14119V-24.2.3","P-14392V-8.1.2.6","P-14119V-24.3.0","P-1980V-12.2.1.4.0","P-9190V-8.0.8.1","P-11166V-13.5.2.0.0","P-14276V-8.1.3.0","P-10722V-19.0.1.0","P-1807V-14.1.3.2","P-1807V-16.0.3.0","P-14121V-24.2.0","P-9190V-8.1.2.7","P-9190V-8.1.2.8","P-10722V-16.0.3.0","P-13784V-6.0.0.1.0-6.0.0.3.0","P-10722V-14.1.3.2","P-1807V-19.0.1.0","P-5680V-8.1.2.5","P-1807V-15.0.3.1","P-4647V-12.2.1.4.0","P-5680V-8.0.7.8"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-5760V-19.1.0.0.0-19.1.0.0.18","P-14117V-24.2.0","P-14117V-24.3.0"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-5760V-19.1.0.0.0-19.1.0.0.18","P-14117V-24.2.0","P-14117V-24.3.0"]}]},{"cve":"CVE-2024-38820","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-5760V-19.1.0.0.0-19.1.0.0.18","P-14117V-24.2.0","P-14117V-24.3.0"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Financial Services Behavior Detection Platform","text":"37260019"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function","text":"37259993"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Policy","text":"37259999"},{"system_name":"Oracle Bug ID of Oracle Financial Services Model Management and Governance","text":"37385567"},{"system_name":"Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters","text":"37260075"},{"system_name":"Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition","text":"37260071"},{"system_name":"Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure","text":"37260018"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy","text":"37260000"},{"system_name":"Oracle Bug ID of Oracle Financial Services Compliance Studio","text":"37260022"},{"system_name":"Oracle Bug ID of Oracle Utilities Testing Accelerator","text":"37260122"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy","text":"37260002"},{"system_name":"Oracle Bug ID of Enterprise Manager for MySQL Database","text":"37260013"},{"system_name":"Oracle Bug ID of Oracle BI Publisher","text":"37243652"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository","text":"37260003"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Development Operations (Spring Framework)).  Supported versions that are affected are 7.0.0.0.0 and  7.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Framework)).  Supported versions that are affected are 24.2.0 and  24.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Framework)).  Supported versions that are affected are 24.2.0-24.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Signaling (Spring Framework)).  Supported versions that are affected are 24.2.0, 24.2.1 and  24.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Signaling (Spring Framework)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Spring Framework)).  Supported versions that are affected are 24.3.0 and 24.2.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Unified Data Repository accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Enterprise Manager for MySQL Database product of Oracle Enterprise Manager (component: EM Plugin: General (Spring Framework)).   The supported version that is affected is 13.5.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager for MySQL Database.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Enterprise Manager for MySQL Database accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Spring Framework)).  Supported versions that are affected are 8.0.7.8, 8.0.8.6 and  8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (Spring Framework)).  Supported versions that are affected are 8.0.8.1, 8.1.2.7 and  8.1.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Behavior Detection Platform accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Spring Framework)).   The supported version that is affected is 8.1.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Compliance Studio accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (Spring Framework)).   The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Application Adapters (Spring Framework)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Spring Framework)).  Supported versions that are affected are 6.0.0.1.0-6.0.0.3.0 and  7.0.0.0.0-7.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Utilities Testing Accelerator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Spring Framework)).   The supported version that is affected is 8.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Model Management and Governance accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14121V-24.2.1","P-14277V-24.2.0-24.2.2","P-1479V-7.0.0.0.0","P-13789V-8.0.8","P-5680V-8.0.8.6","P-9190V-8.1.2.7","P-1479V-7.6.0.0.0","P-9190V-8.1.2.8","P-14123V-24.2.1","P-14123V-24.2.2","P-13784V-6.0.0.1.0-6.0.0.3.0","P-13784V-7.0.0.0.0-7.0.0.1.0","P-14123V-24.2.0","P-14119V-24.2.3","P-5680V-8.1.2.5","P-14392V-8.1.2.6","P-14119V-24.3.0","P-9190V-8.0.8.1","P-11166V-13.5.2.0.0","P-14276V-8.1.3.0","P-5680V-8.0.7.8","P-14121V-24.2.0"],"known_not_affected":["P-5760V-19.1.0.0.0-19.1.0.0.18","P-14117V-24.2.0","P-14117V-24.3.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1479V-7.0.0.0.0","P-1479V-7.6.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-24.2.1","P-14121V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066001.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-24.2.0-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066021.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-24.2.1","P-14123V-24.2.2","P-14123V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14117V-24.2.0","P-14117V-24.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066004.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14119V-24.2.3","P-14119V-24.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066908.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11166V-13.5.2.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056561.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5680V-8.1.2.5","P-5680V-8.0.8.6","P-5680V-8.0.7.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065940.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9190V-8.1.2.7","P-9190V-8.0.8.1","P-9190V-8.1.2.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066717.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14392V-8.1.2.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065911.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13789V-8.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066716.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5760V-19.1.0.0.0-19.1.0.0.18"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13784V-6.0.0.1.0-6.0.0.3.0","P-13784V-7.0.0.0.0-7.0.0.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066725.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14276V-8.1.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066624.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-1479V-7.0.0.0.0","P-1479V-7.6.0.0.0"]},{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-14121V-24.2.1","P-14277V-24.2.0-24.2.2","P-13789V-8.0.8","P-5680V-8.0.8.6","P-9190V-8.1.2.7","P-9190V-8.1.2.8","P-14123V-24.2.1","P-14123V-24.2.2","P-13784V-6.0.0.1.0-6.0.0.3.0","P-13784V-7.0.0.0.0-7.0.0.1.0","P-14123V-24.2.0","P-14119V-24.2.3","P-5680V-8.1.2.5","P-14392V-8.1.2.6","P-14119V-24.3.0","P-9190V-8.0.8.1","P-11166V-13.5.2.0.0","P-14276V-8.1.3.0","P-5680V-8.0.7.8","P-14121V-24.2.0"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-5760V-19.1.0.0.0-19.1.0.0.18","P-14117V-24.2.0","P-14117V-24.3.0"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-5760V-19.1.0.0.0-19.1.0.0.18","P-14117V-24.2.0","P-14117V-24.3.0"]}]},{"cve":"CVE-2024-38827","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy","text":"37366309"},{"system_name":"Oracle Bug ID of Oracle Communications Unified Inventory Management","text":"37366316"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Policy","text":"37366307"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function","text":"37366301"},{"system_name":"Oracle Bug ID of Oracle Financial Services Compliance Studio","text":"37366320"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (Spring Security)).  Supported versions that are affected are 7.4.1 and  7.4.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Inventory Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Signaling (Spring Security)).   The supported version that is affected is 24.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Spring Security)).  Supported versions that are affected are 24.2.0-24.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Spring Security)).  Supported versions that are affected are 24.2.0 and  24.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Spring Security)).   The supported version that is affected is 8.1.2.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Compliance Studio accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Compliance Studio accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14277V-24.2.0-24.2.2","P-14121V-24.2.1","P-14392V-8.1.2.6","P-4516V-7.4.1","P-4516V-7.4.2","P-14123V-24.2.0","P-14121V-24.2.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4516V-7.4.1","P-4516V-7.4.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064002.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-24.2.0-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066021.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-24.2.1","P-14121V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066001.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14392V-8.1.2.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065911.1"}],"scores":[{"cvss_v3":{"baseScore":4.8,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-14277V-24.2.0-24.2.2","P-14121V-24.2.1","P-14392V-8.1.2.6","P-4516V-7.4.1","P-4516V-7.4.2","P-14123V-24.2.0","P-14121V-24.2.0"]}]},{"cve":"CVE-2024-38998","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-14277V-24.2.0-24.2.2","P-13789V-8.0.8","P-5680V-8.0.8.6","P-2270V-7.4.0","P-2270V-7.4.1","P-13784V-7.0.0.0.0-7.0.0.1.0","P-2545V-14.1.1.0.0","P-4516V-7.5.1","P-2245V-4.4.0.3.0","P-2241V-2.5.0.2.9","P-619(Oracle Spatial and Graph Spatial Web Services)V-21.3-21.16","P-9190V-8.0.8.1","P-2245V-4.3.0.3.0-4.3.0.6.0","P-9456V-23.3.0.289.1830","P-14276V-8.1.2.6","P-14276V-8.1.2.7","P-4622V-13.3.0.1","P-2136(Billing Care)V-15.0.0.0-15.0.0.1","P-9190V-8.1.2.7","P-9456V-23.4.1.038.1857","P-10758V-4.1.0","P-9190V-8.1.2.8","P-1215V-12.2.1.4.0","P-9456V-24.1.2.163.1158","P-13784V-6.0.0.1.0-6.0.0.3.0","P-5624V-12.2.18-12.2.36","P-2245V-4.5.0.0.0","P-2241V-2.6.0.1.7","P-10757V-9.3.0","P-5757V-23.4-23.6","P-5757V-19.1.0.0.0-19.25.0.0.241015","P-5680V-8.1.2.5","P-9456V-24.1.0.108.0942","P-5477V-13.0.0","P-10605V-20.12.0-20.12.15","P-2245V-24.1.0.0.0-24.3.0.0.0","P-10354V-23.12.0-23.12.12","P-10354V-21.12.0-21.12.17","P-619(Oracle Spatial and Graph Spatial Web Services)V-19.3-19.25","P-5085V-8.61","P-5085V-8.60","P-13545V-8.1.2.8","P-14121V-24.2.1","P-13545V-8.1.2.7","P-5757V-21.3-21.16","P-11528V-3.07","P-10899V-8.6.0.4.0","P-9142V-8.1.2.8","P-9142V-8.1.2.7","P-9456V-24.2.1.180.1634","P-2283V-8.1.0.1","P-2270V-7.5.0","P-4516V-7.6.0","P-1696V-12.2.1.4.0","P-2245V-4.4.0.0.0","P-2245V-4.4.0.2.0","P-9456V-23.4.0.346.1619","P-9456V-24.1.1.120.1228","P-2283V-8.0.0.3","P-2136(Billing Care)V-12.0.0.4-12.0.0.8","P-13545V-8.0.8.2","P-11108V-14.0","P-14276V-8.1.3.0","P-9456V-24.2.2.187.1943","P-14121V-24.2.0","P-14069V-24.4.0","P-2545V-12.2.1.4.0","P-10758V-4.2.0","P-2245V-4.5.0.1.1","P-10757V-9.2.0","P-14069V-23.4.4","P-10354V-20.12.0-20.12.16","P-10354V-22.12.0-22.12.15","P-10761V-5.1","P-9456V-24.2.0.169.2208","P-10761V-5.2","P-9646V-Prior to 9.2.3","P-2245V-4.5.0.1.3","P-10605V-21.12.0-21.12.13","P-9456V-23.3.1.305.1055","P-10354V-24.12.0","P-5680V-8.0.7.8","P-5477V-12.7.2","P-5477V-12.7.1"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function","text":"37225120"},{"system_name":"Oracle Bug ID of Oracle Life Sciences Empirica Signal","text":"37229501"},{"system_name":"Oracle Bug ID of Oracle WebCenter Portal","text":"37229700"},{"system_name":"Oracle Bug ID of Oracle Documaker","text":"37225284"},{"system_name":"Oracle Bug ID of Oracle Communications User Data Repository","text":"37225281"},{"system_name":"Oracle Bug ID of Oracle Fusion Middleware MapViewer","text":"37229549"},{"system_name":"Oracle Bug ID of Oracle Application Testing Suite","text":"37225062"},{"system_name":"Oracle Bug ID of Oracle Communications Unified Inventory Management","text":"37225280"},{"system_name":"Oracle Bug ID of Oracle Enterprise Session Border Controller","text":"37225080"},{"system_name":"Oracle Bug ID of Oracle Communications Billing and Revenue Management","text":"37225119"},{"system_name":"Oracle Bug ID of Primavera Unifier","text":"37229690"},{"system_name":"Oracle Bug ID of Oracle GoldenGate","text":"37229493"},{"system_name":"Oracle Bug ID of Oracle REST Data Services","text":"37229691"},{"system_name":"Oracle Bug ID of Graph Server and Client","text":"37229494"},{"system_name":"Oracle Bug ID of Oracle Coherence","text":"37225116"},{"system_name":"Oracle Bug ID of Oracle Financial Services Behavior Detection Platform","text":"37225312"},{"system_name":"Oracle Bug ID of Oracle Policy Automation","text":"37229553"},{"system_name":"Oracle Bug ID of Oracle Big Data Spatial and Graph","text":"37225111"},{"system_name":"Oracle Bug ID of Oracle Enterprise Communications Broker","text":"37225078"},{"system_name":"Oracle Bug ID of Oracle Financial Services Enterprise Case Management","text":"37225332"},{"system_name":"Oracle Bug ID of Oracle Communications Service Catalog and Design","text":"37225131"},{"system_name":"Oracle Bug ID of Oracle Utilities Testing Accelerator","text":"37229655"},{"system_name":"Oracle Bug ID of Oracle Communications Order and Service Management","text":"37225130"},{"system_name":"Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition","text":"37225350"},{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"37229679"},{"system_name":"Oracle Bug ID of Oracle Utilities Application Framework","text":"37229636"},{"system_name":"Oracle Bug ID of Oracle Database Server","text":"37225072"},{"system_name":"Oracle Bug ID of Oracle Communications Operations Monitor","text":"37225129"},{"system_name":"Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure","text":"37225302"},{"system_name":"Oracle Bug ID of Oracle Financial Services Regulatory Reporting","text":"37225346"},{"system_name":"Oracle Bug ID of Primavera Gateway","text":"37229681"},{"system_name":"Oracle Bug ID of Oracle Communications Diameter Signaling Router","text":"37225127"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Policy","text":"37225122"},{"system_name":"Oracle Bug ID of Oracle Financial Services Model Management and Governance","text":"37225342"},{"system_name":"Oracle Bug ID of Oracle Utilities Network Management System","text":"37229641"}],"notes":[{"category":"description","text":"Security-in-Depth issue in the Oracle Coherence product of Oracle Fusion Middleware (component: Third Party (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Patches (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Service Catalog and Design product of Oracle Communications Applications (component: Solution Designer (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Documaker product of Oracle Insurance Applications (component: Enterprise Edition (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Platform (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Financial Services Regulatory Reporting product of Oracle Financial Services Applications (component: Platform (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle GoldenGate (component: Embedded Web UI for Services (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Graph Server and Client product of Oracle Graph Server and Client (component: Install (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Life Sciences Empirica Signal product of Oracle Health Sciences Applications (component: UI (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Fusion Middleware MapViewer product of Oracle Fusion Middleware (component: Install (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle Policy Automation (component: Determinations Engine (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Security (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Third Party (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Charting (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle REST Data Services (component: General (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle Big Data Spatial and Graph (component: Big Data Spatial (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: Web UI (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Enterprise Communications Broker product of Oracle Communications (component: Web UI (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Spatial and Graph Spatial Web Services (RequireJS) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Load Testing for Web Apps (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications User Data Repository product of Oracle Communications (component: Platform (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-14277V-24.2.0-24.2.2","P-13789V-8.0.8","P-5680V-8.0.8.6","P-2270V-7.4.0","P-2270V-7.4.1","P-13784V-7.0.0.0.0-7.0.0.1.0","P-2545V-14.1.1.0.0","P-4516V-7.5.1","P-2245V-4.4.0.3.0","P-2241V-2.5.0.2.9","P-619(Oracle Spatial and Graph Spatial Web Services)V-21.3-21.16","P-9190V-8.0.8.1","P-2245V-4.3.0.3.0-4.3.0.6.0","P-9456V-23.3.0.289.1830","P-14276V-8.1.2.6","P-14276V-8.1.2.7","P-4622V-13.3.0.1","P-2136(Billing Care)V-15.0.0.0-15.0.0.1","P-9190V-8.1.2.7","P-9456V-23.4.1.038.1857","P-10758V-4.1.0","P-9190V-8.1.2.8","P-1215V-12.2.1.4.0","P-9456V-24.1.2.163.1158","P-13784V-6.0.0.1.0-6.0.0.3.0","P-5624V-12.2.18-12.2.36","P-2245V-4.5.0.0.0","P-2241V-2.6.0.1.7","P-10757V-9.3.0","P-5757V-23.4-23.6","P-5757V-19.1.0.0.0-19.25.0.0.241015","P-5680V-8.1.2.5","P-9456V-24.1.0.108.0942","P-5477V-13.0.0","P-10605V-20.12.0-20.12.15","P-2245V-24.1.0.0.0-24.3.0.0.0","P-10354V-23.12.0-23.12.12","P-10354V-21.12.0-21.12.17","P-619(Oracle Spatial and Graph Spatial Web Services)V-19.3-19.25","P-5085V-8.61","P-5085V-8.60","P-13545V-8.1.2.8","P-14121V-24.2.1","P-13545V-8.1.2.7","P-5757V-21.3-21.16","P-11528V-3.07","P-10899V-8.6.0.4.0","P-9142V-8.1.2.8","P-9142V-8.1.2.7","P-9456V-24.2.1.180.1634","P-2283V-8.1.0.1","P-2270V-7.5.0","P-4516V-7.6.0","P-1696V-12.2.1.4.0","P-2245V-4.4.0.0.0","P-2245V-4.4.0.2.0","P-9456V-23.4.0.346.1619","P-9456V-24.1.1.120.1228","P-2283V-8.0.0.3","P-2136(Billing Care)V-12.0.0.4-12.0.0.8","P-13545V-8.0.8.2","P-11108V-14.0","P-14276V-8.1.3.0","P-9456V-24.2.2.187.1943","P-14121V-24.2.0","P-14069V-24.4.0","P-2545V-12.2.1.4.0","P-10758V-4.2.0","P-2245V-4.5.0.1.1","P-10757V-9.2.0","P-14069V-23.4.4","P-10354V-20.12.0-20.12.16","P-10354V-22.12.0-22.12.15","P-10761V-5.1","P-9456V-24.2.0.169.2208","P-10761V-5.2","P-9646V-Prior to 9.2.3","P-2245V-4.5.0.1.3","P-10605V-21.12.0-21.12.13","P-9456V-23.3.1.305.1055","P-10354V-24.12.0","P-5680V-8.0.7.8","P-5477V-12.7.2","P-5477V-12.7.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2545V-12.2.1.4.0","P-1215V-12.2.1.4.0","P-2545V-14.1.1.0.0","P-1696V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2136(Billing Care)V-15.0.0.0-15.0.0.1","P-2136(Billing Care)V-12.0.0.4-12.0.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064003.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-24.2.1","P-14121V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066001.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-24.2.0-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066021.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-8.6.0.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066025.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10761V-5.1","P-10761V-5.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066003.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2270V-7.4.0","P-2270V-7.4.1","P-2270V-7.5.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064005.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2283V-8.0.0.3","P-2283V-8.1.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4516V-7.5.1","P-4516V-7.6.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064002.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5477V-13.0.0","P-5477V-12.7.2","P-5477V-12.7.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065956.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5680V-8.1.2.5","P-5680V-8.0.8.6","P-5680V-8.0.7.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065940.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9190V-8.1.2.7","P-9190V-8.0.8.1","P-9190V-8.1.2.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066717.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13545V-8.1.2.8","P-13545V-8.1.2.7","P-13545V-8.0.8.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065910.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14276V-8.1.2.7","P-14276V-8.1.3.0","P-14276V-8.1.2.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066624.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9142V-8.1.2.8","P-9142V-8.1.2.7"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065882.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13789V-8.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066716.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5757V-21.3-21.16","P-14069V-24.4.0","P-11528V-3.07","P-9456V-23.4.1.038.1857","P-9456V-24.2.1.180.1634","P-9456V-24.1.2.163.1158","P-5757V-23.4-23.6","P-5757V-19.1.0.0.0-19.25.0.0.241015","P-619(Oracle Spatial and Graph Spatial Web Services)V-21.3-21.16","P-14069V-23.4.4","P-9456V-23.4.0.346.1619","P-9456V-24.1.0.108.0942","P-9456V-24.1.1.120.1228","P-9456V-24.2.0.169.2208","P-9456V-23.3.1.305.1055","P-619(Oracle Spatial and Graph Spatial Web Services)V-19.3-19.25","P-9456V-23.3.0.289.1830","P-9456V-24.2.2.187.1943"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9646V-Prior to 9.2.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065955.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5624V-12.2.18-12.2.36"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066257.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2245V-24.1.0.0.0-24.3.0.0.0","P-2245V-4.5.0.1.3","P-2245V-4.5.0.1.1","P-13784V-6.0.0.1.0-6.0.0.3.0","P-2245V-4.3.0.3.0-4.3.0.6.0","P-2245V-4.5.0.0.0","P-2241V-2.6.0.1.7","P-13784V-7.0.0.0.0-7.0.0.1.0","P-2245V-4.4.0.0.0","P-2245V-4.4.0.2.0","P-2245V-4.4.0.3.0","P-2241V-2.5.0.2.9"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066725.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10354V-20.12.0-20.12.16","P-10354V-22.12.0-22.12.15","P-10605V-20.12.0-20.12.15","P-10354V-23.12.0-23.12.12","P-10354V-21.12.0-21.12.17","P-10605V-21.12.0-21.12.13","P-10354V-24.12.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065975.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10757V-9.3.0","P-10757V-9.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065963.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10758V-4.2.0","P-10758V-4.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065964.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4622V-13.3.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056561.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11108V-14.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066024.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-14277V-24.2.0-24.2.2","P-13789V-8.0.8","P-5680V-8.0.8.6","P-2270V-7.4.0","P-2270V-7.4.1","P-13784V-7.0.0.0.0-7.0.0.1.0","P-2545V-14.1.1.0.0","P-4516V-7.5.1","P-2245V-4.4.0.3.0","P-2241V-2.5.0.2.9","P-619(Oracle Spatial and Graph Spatial Web Services)V-21.3-21.16","P-9190V-8.0.8.1","P-2245V-4.3.0.3.0-4.3.0.6.0","P-9456V-23.3.0.289.1830","P-14276V-8.1.2.6","P-14276V-8.1.2.7","P-4622V-13.3.0.1","P-2136(Billing Care)V-15.0.0.0-15.0.0.1","P-9190V-8.1.2.7","P-9456V-23.4.1.038.1857","P-10758V-4.1.0","P-9190V-8.1.2.8","P-1215V-12.2.1.4.0","P-9456V-24.1.2.163.1158","P-13784V-6.0.0.1.0-6.0.0.3.0","P-5624V-12.2.18-12.2.36","P-2245V-4.5.0.0.0","P-2241V-2.6.0.1.7","P-10757V-9.3.0","P-5757V-23.4-23.6","P-5757V-19.1.0.0.0-19.25.0.0.241015","P-5680V-8.1.2.5","P-9456V-24.1.0.108.0942","P-5477V-13.0.0","P-10605V-20.12.0-20.12.15","P-2245V-24.1.0.0.0-24.3.0.0.0","P-10354V-23.12.0-23.12.12","P-10354V-21.12.0-21.12.17","P-619(Oracle Spatial and Graph Spatial Web Services)V-19.3-19.25","P-5085V-8.61","P-5085V-8.60","P-13545V-8.1.2.8","P-14121V-24.2.1","P-13545V-8.1.2.7","P-5757V-21.3-21.16","P-11528V-3.07","P-10899V-8.6.0.4.0","P-9142V-8.1.2.8","P-9142V-8.1.2.7","P-9456V-24.2.1.180.1634","P-2283V-8.1.0.1","P-2270V-7.5.0","P-4516V-7.6.0","P-1696V-12.2.1.4.0","P-2245V-4.4.0.0.0","P-2245V-4.4.0.2.0","P-9456V-23.4.0.346.1619","P-9456V-24.1.1.120.1228","P-2283V-8.0.0.3","P-2136(Billing Care)V-12.0.0.4-12.0.0.8","P-13545V-8.0.8.2","P-11108V-14.0","P-14276V-8.1.3.0","P-9456V-24.2.2.187.1943","P-14121V-24.2.0","P-14069V-24.4.0","P-2545V-12.2.1.4.0","P-10758V-4.2.0","P-2245V-4.5.0.1.1","P-10757V-9.2.0","P-14069V-23.4.4","P-10354V-20.12.0-20.12.16","P-10354V-22.12.0-22.12.15","P-10761V-5.1","P-9456V-24.2.0.169.2208","P-10761V-5.2","P-9646V-Prior to 9.2.3","P-2245V-4.5.0.1.3","P-10605V-21.12.0-21.12.13","P-9456V-23.3.1.305.1055","P-10354V-24.12.0","P-5680V-8.0.7.8","P-5477V-12.7.2","P-5477V-12.7.1"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-14277V-24.2.0-24.2.2","P-13789V-8.0.8","P-5680V-8.0.8.6","P-2270V-7.4.0","P-2270V-7.4.1","P-13784V-7.0.0.0.0-7.0.0.1.0","P-2545V-14.1.1.0.0","P-4516V-7.5.1","P-2245V-4.4.0.3.0","P-2241V-2.5.0.2.9","P-619(Oracle Spatial and Graph Spatial Web Services)V-21.3-21.16","P-9190V-8.0.8.1","P-2245V-4.3.0.3.0-4.3.0.6.0","P-9456V-23.3.0.289.1830","P-14276V-8.1.2.6","P-14276V-8.1.2.7","P-4622V-13.3.0.1","P-2136(Billing Care)V-15.0.0.0-15.0.0.1","P-9190V-8.1.2.7","P-9456V-23.4.1.038.1857","P-10758V-4.1.0","P-9190V-8.1.2.8","P-1215V-12.2.1.4.0","P-9456V-24.1.2.163.1158","P-13784V-6.0.0.1.0-6.0.0.3.0","P-5624V-12.2.18-12.2.36","P-2245V-4.5.0.0.0","P-2241V-2.6.0.1.7","P-10757V-9.3.0","P-5757V-23.4-23.6","P-5757V-19.1.0.0.0-19.25.0.0.241015","P-5680V-8.1.2.5","P-9456V-24.1.0.108.0942","P-5477V-13.0.0","P-10605V-20.12.0-20.12.15","P-2245V-24.1.0.0.0-24.3.0.0.0","P-10354V-23.12.0-23.12.12","P-10354V-21.12.0-21.12.17","P-619(Oracle Spatial and Graph Spatial Web Services)V-19.3-19.25","P-5085V-8.61","P-5085V-8.60","P-13545V-8.1.2.8","P-14121V-24.2.1","P-13545V-8.1.2.7","P-5757V-21.3-21.16","P-11528V-3.07","P-10899V-8.6.0.4.0","P-9142V-8.1.2.8","P-9142V-8.1.2.7","P-9456V-24.2.1.180.1634","P-2283V-8.1.0.1","P-2270V-7.5.0","P-4516V-7.6.0","P-1696V-12.2.1.4.0","P-2245V-4.4.0.0.0","P-2245V-4.4.0.2.0","P-9456V-23.4.0.346.1619","P-9456V-24.1.1.120.1228","P-2283V-8.0.0.3","P-2136(Billing Care)V-12.0.0.4-12.0.0.8","P-13545V-8.0.8.2","P-11108V-14.0","P-14276V-8.1.3.0","P-9456V-24.2.2.187.1943","P-14121V-24.2.0","P-14069V-24.4.0","P-2545V-12.2.1.4.0","P-10758V-4.2.0","P-2245V-4.5.0.1.1","P-10757V-9.2.0","P-14069V-23.4.4","P-10354V-20.12.0-20.12.16","P-10354V-22.12.0-22.12.15","P-10761V-5.1","P-9456V-24.2.0.169.2208","P-10761V-5.2","P-9646V-Prior to 9.2.3","P-2245V-4.5.0.1.3","P-10605V-21.12.0-21.12.13","P-9456V-23.3.1.305.1055","P-10354V-24.12.0","P-5680V-8.0.7.8","P-5477V-12.7.2","P-5477V-12.7.1"]}]},{"cve":"CVE-2024-38999","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-14277V-24.2.0-24.2.2","P-13789V-8.0.8","P-5680V-8.0.8.6","P-2270V-7.4.0","P-2270V-7.4.1","P-13784V-7.0.0.0.0-7.0.0.1.0","P-4516V-7.5.1","P-2545V-14.1.1.0.0","P-2245V-4.4.0.3.0","P-2241V-2.5.0.2.9","P-619(Oracle Spatial and Graph Spatial Web Services)V-21.3-21.16","P-9190V-8.0.8.1","P-2245V-4.3.0.3.0-4.3.0.6.0","P-9456V-23.3.0.289.1830","P-14276V-8.1.2.6","P-14276V-8.1.2.7","P-4622V-13.3.0.1","P-9190V-8.1.2.7","P-9456V-23.4.1.038.1857","P-2136(Billing Care)V-15.0.0.0-15.0.0.1","P-10758V-4.1.0","P-9190V-8.1.2.8","P-1215V-12.2.1.4.0","P-9456V-24.1.2.163.1158","P-13784V-6.0.0.1.0-6.0.0.3.0","P-5624V-12.2.18-12.2.36","P-2245V-4.5.0.0.0","P-2241V-2.6.0.1.7","P-10757V-9.3.0","P-5757V-23.4-23.6","P-5757V-19.1.0.0.0-19.25.0.0.241015","P-5680V-8.1.2.5","P-9456V-24.1.0.108.0942","P-5477V-13.0.0","P-10605V-20.12.0-20.12.15","P-2245V-24.1.0.0.0-24.3.0.0.0","P-10354V-23.12.0-23.12.12","P-10354V-21.12.0-21.12.17","P-619(Oracle Spatial and Graph Spatial Web Services)V-19.3-19.25","P-5085V-8.61","P-5085V-8.60","P-13545V-8.1.2.8","P-13545V-8.1.2.7","P-5757V-21.3-21.16","P-11528V-3.07","P-14121V-24.2.1","P-9142V-8.1.2.8","P-10899V-8.6.0.4.0","P-9142V-8.1.2.7","P-9456V-24.2.1.180.1634","P-2283V-8.1.0.1","P-2270V-7.5.0","P-4516V-7.6.0","P-2245V-4.4.0.0.0","P-1696V-12.2.1.4.0","P-2245V-4.4.0.2.0","P-9456V-23.4.0.346.1619","P-9456V-24.1.1.120.1228","P-2283V-8.0.0.3","P-2136(Billing Care)V-12.0.0.4-12.0.0.8","P-13545V-8.0.8.2","P-11108V-14.0","P-14276V-8.1.3.0","P-9456V-24.2.2.187.1943","P-14121V-24.2.0","P-14069V-24.4.0","P-10758V-4.2.0","P-2545V-12.2.1.4.0","P-2245V-4.5.0.1.1","P-10757V-9.2.0","P-14069V-23.4.4","P-10354V-20.12.0-20.12.16","P-10354V-22.12.0-22.12.15","P-10761V-5.1","P-9456V-24.2.0.169.2208","P-9646V-Prior to 9.2.3","P-2245V-4.5.0.1.3","P-10761V-5.2","P-10605V-21.12.0-21.12.13","P-9456V-23.3.1.305.1055","P-10354V-24.12.0","P-5680V-8.0.7.8","P-5477V-12.7.2","P-5477V-12.7.1"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function","text":"37225120"},{"system_name":"Oracle Bug ID of Oracle Life Sciences Empirica Signal","text":"37229501"},{"system_name":"Oracle Bug ID of Oracle WebCenter Portal","text":"37229700"},{"system_name":"Oracle Bug ID of Oracle Documaker","text":"37225284"},{"system_name":"Oracle Bug ID of Oracle Communications User Data Repository","text":"37225281"},{"system_name":"Oracle Bug ID of Oracle Fusion Middleware MapViewer","text":"37229549"},{"system_name":"Oracle Bug ID of Oracle Application Testing Suite","text":"37225062"},{"system_name":"Oracle Bug ID of Oracle Communications Unified Inventory Management","text":"37225280"},{"system_name":"Oracle Bug ID of Oracle Enterprise Session Border Controller","text":"37225080"},{"system_name":"Oracle Bug ID of Oracle Communications Billing and Revenue Management","text":"37225119"},{"system_name":"Oracle Bug ID of Primavera Unifier","text":"37229690"},{"system_name":"Oracle Bug ID of Oracle GoldenGate","text":"37229493"},{"system_name":"Oracle Bug ID of Oracle REST Data Services","text":"37229691"},{"system_name":"Oracle Bug ID of Graph Server and Client","text":"37229494"},{"system_name":"Oracle Bug ID of Oracle Coherence","text":"37225116"},{"system_name":"Oracle Bug ID of Oracle Financial Services Behavior Detection Platform","text":"37225312"},{"system_name":"Oracle Bug ID of Oracle Policy Automation","text":"37229553"},{"system_name":"Oracle Bug ID of Oracle Enterprise Communications Broker","text":"37225078"},{"system_name":"Oracle Bug ID of Oracle Big Data Spatial and Graph","text":"37225111"},{"system_name":"Oracle Bug ID of Oracle Financial Services Enterprise Case Management","text":"37225332"},{"system_name":"Oracle Bug ID of Oracle Communications Service Catalog and Design","text":"37225131"},{"system_name":"Oracle Bug ID of Oracle Utilities Testing Accelerator","text":"37229655"},{"system_name":"Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition","text":"37225350"},{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"37229679"},{"system_name":"Oracle Bug ID of Oracle Communications Order and Service Management","text":"37225130"},{"system_name":"Oracle Bug ID of Oracle Utilities Application Framework","text":"37229636"},{"system_name":"Oracle Bug ID of Oracle Database Server","text":"37225072"},{"system_name":"Oracle Bug ID of Oracle Communications Operations Monitor","text":"37225129"},{"system_name":"Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure","text":"37225302"},{"system_name":"Oracle Bug ID of Oracle Financial Services Regulatory Reporting","text":"37225346"},{"system_name":"Oracle Bug ID of Primavera Gateway","text":"37229681"},{"system_name":"Oracle Bug ID of Oracle Communications Diameter Signaling Router","text":"37225127"},{"system_name":"Oracle Bug ID of Oracle Financial Services Model Management and Governance","text":"37225342"},{"system_name":"Oracle Bug ID of Oracle Utilities Network Management System","text":"37229641"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Policy","text":"37225122"}],"notes":[{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications User Data Repository product of Oracle Communications (component: Platform (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Documaker product of Oracle Insurance Applications (component: Enterprise Edition (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Platform (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Financial Services Regulatory Reporting product of Oracle Financial Services Applications (component: Platform (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle GoldenGate (component: Embedded Web UI for Services (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Graph Server and Client product of Oracle Graph Server and Client (component: Install (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Life Sciences Empirica Signal product of Oracle Health Sciences Applications (component: UI (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Fusion Middleware MapViewer product of Oracle Fusion Middleware (component: Install (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle Policy Automation (component: Determinations Engine (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Security (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Third Party (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Charting (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle REST Data Services (component: General (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Load Testing for Web Apps (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Spatial and Graph Spatial Web Services (RequireJS) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Enterprise Communications Broker product of Oracle Communications (component: Web UI (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: Web UI (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle Big Data Spatial and Graph (component: Big Data Spatial (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Coherence product of Oracle Fusion Middleware (component: Third Party (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Patches (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Communications Service Catalog and Design product of Oracle Communications Applications (component: Solution Designer (RequireJS)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-14277V-24.2.0-24.2.2","P-13789V-8.0.8","P-5680V-8.0.8.6","P-2270V-7.4.0","P-2270V-7.4.1","P-13784V-7.0.0.0.0-7.0.0.1.0","P-4516V-7.5.1","P-2545V-14.1.1.0.0","P-2245V-4.4.0.3.0","P-2241V-2.5.0.2.9","P-619(Oracle Spatial and Graph Spatial Web Services)V-21.3-21.16","P-9190V-8.0.8.1","P-2245V-4.3.0.3.0-4.3.0.6.0","P-9456V-23.3.0.289.1830","P-14276V-8.1.2.6","P-14276V-8.1.2.7","P-4622V-13.3.0.1","P-9190V-8.1.2.7","P-9456V-23.4.1.038.1857","P-2136(Billing Care)V-15.0.0.0-15.0.0.1","P-10758V-4.1.0","P-9190V-8.1.2.8","P-1215V-12.2.1.4.0","P-9456V-24.1.2.163.1158","P-13784V-6.0.0.1.0-6.0.0.3.0","P-5624V-12.2.18-12.2.36","P-2245V-4.5.0.0.0","P-2241V-2.6.0.1.7","P-10757V-9.3.0","P-5757V-23.4-23.6","P-5757V-19.1.0.0.0-19.25.0.0.241015","P-5680V-8.1.2.5","P-9456V-24.1.0.108.0942","P-5477V-13.0.0","P-10605V-20.12.0-20.12.15","P-2245V-24.1.0.0.0-24.3.0.0.0","P-10354V-23.12.0-23.12.12","P-10354V-21.12.0-21.12.17","P-619(Oracle Spatial and Graph Spatial Web Services)V-19.3-19.25","P-5085V-8.61","P-5085V-8.60","P-13545V-8.1.2.8","P-13545V-8.1.2.7","P-5757V-21.3-21.16","P-11528V-3.07","P-14121V-24.2.1","P-9142V-8.1.2.8","P-10899V-8.6.0.4.0","P-9142V-8.1.2.7","P-9456V-24.2.1.180.1634","P-2283V-8.1.0.1","P-2270V-7.5.0","P-4516V-7.6.0","P-2245V-4.4.0.0.0","P-1696V-12.2.1.4.0","P-2245V-4.4.0.2.0","P-9456V-23.4.0.346.1619","P-9456V-24.1.1.120.1228","P-2283V-8.0.0.3","P-2136(Billing Care)V-12.0.0.4-12.0.0.8","P-13545V-8.0.8.2","P-11108V-14.0","P-14276V-8.1.3.0","P-9456V-24.2.2.187.1943","P-14121V-24.2.0","P-14069V-24.4.0","P-10758V-4.2.0","P-2545V-12.2.1.4.0","P-2245V-4.5.0.1.1","P-10757V-9.2.0","P-14069V-23.4.4","P-10354V-20.12.0-20.12.16","P-10354V-22.12.0-22.12.15","P-10761V-5.1","P-9456V-24.2.0.169.2208","P-9646V-Prior to 9.2.3","P-2245V-4.5.0.1.3","P-10761V-5.2","P-10605V-21.12.0-21.12.13","P-9456V-23.3.1.305.1055","P-10354V-24.12.0","P-5680V-8.0.7.8","P-5477V-12.7.2","P-5477V-12.7.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4516V-7.5.1","P-4516V-7.6.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064002.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11108V-14.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066024.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5477V-13.0.0","P-5477V-12.7.2","P-5477V-12.7.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065956.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5680V-8.1.2.5","P-5680V-8.0.8.6","P-5680V-8.0.7.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065940.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9190V-8.1.2.7","P-9190V-8.0.8.1","P-9190V-8.1.2.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066717.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13545V-8.1.2.8","P-13545V-8.1.2.7","P-13545V-8.0.8.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065910.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14276V-8.1.2.7","P-14276V-8.1.3.0","P-14276V-8.1.2.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066624.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9142V-8.1.2.8","P-9142V-8.1.2.7"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065882.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13789V-8.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066716.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5757V-21.3-21.16","P-14069V-24.4.0","P-11528V-3.07","P-9456V-23.4.1.038.1857","P-9456V-24.2.1.180.1634","P-9456V-24.1.2.163.1158","P-5757V-23.4-23.6","P-5757V-19.1.0.0.0-19.25.0.0.241015","P-619(Oracle Spatial and Graph Spatial Web Services)V-21.3-21.16","P-14069V-23.4.4","P-9456V-23.4.0.346.1619","P-9456V-24.1.0.108.0942","P-9456V-24.1.1.120.1228","P-9456V-24.2.0.169.2208","P-9456V-23.3.1.305.1055","P-619(Oracle Spatial and Graph Spatial Web Services)V-19.3-19.25","P-9456V-23.3.0.289.1830","P-9456V-24.2.2.187.1943"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9646V-Prior to 9.2.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065955.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2545V-12.2.1.4.0","P-1215V-12.2.1.4.0","P-1696V-12.2.1.4.0","P-2545V-14.1.1.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5624V-12.2.18-12.2.36"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066257.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2245V-24.1.0.0.0-24.3.0.0.0","P-2245V-4.5.0.1.3","P-2245V-4.5.0.1.1","P-13784V-6.0.0.1.0-6.0.0.3.0","P-2245V-4.3.0.3.0-4.3.0.6.0","P-2245V-4.5.0.0.0","P-2241V-2.6.0.1.7","P-13784V-7.0.0.0.0-7.0.0.1.0","P-2245V-4.4.0.0.0","P-2245V-4.4.0.2.0","P-2245V-4.4.0.3.0","P-2241V-2.5.0.2.9"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066725.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10354V-20.12.0-20.12.16","P-10354V-22.12.0-22.12.15","P-10605V-20.12.0-20.12.15","P-10354V-23.12.0-23.12.12","P-10354V-21.12.0-21.12.17","P-10605V-21.12.0-21.12.13","P-10354V-24.12.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065975.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4622V-13.3.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056561.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10758V-4.2.0","P-10758V-4.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065964.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10757V-9.3.0","P-10757V-9.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065963.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2136(Billing Care)V-15.0.0.0-15.0.0.1","P-2136(Billing Care)V-12.0.0.4-12.0.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064003.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-24.2.1","P-14121V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066001.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-24.2.0-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066021.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10899V-8.6.0.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066025.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10761V-5.1","P-10761V-5.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066003.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2270V-7.4.0","P-2270V-7.4.1","P-2270V-7.5.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064005.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2283V-8.0.0.3","P-2283V-8.1.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064016.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-14277V-24.2.0-24.2.2","P-13789V-8.0.8","P-5680V-8.0.8.6","P-2270V-7.4.0","P-2270V-7.4.1","P-13784V-7.0.0.0.0-7.0.0.1.0","P-4516V-7.5.1","P-2545V-14.1.1.0.0","P-2245V-4.4.0.3.0","P-2241V-2.5.0.2.9","P-619(Oracle Spatial and Graph Spatial Web Services)V-21.3-21.16","P-9190V-8.0.8.1","P-2245V-4.3.0.3.0-4.3.0.6.0","P-9456V-23.3.0.289.1830","P-14276V-8.1.2.6","P-14276V-8.1.2.7","P-4622V-13.3.0.1","P-9190V-8.1.2.7","P-9456V-23.4.1.038.1857","P-2136(Billing Care)V-15.0.0.0-15.0.0.1","P-10758V-4.1.0","P-9190V-8.1.2.8","P-1215V-12.2.1.4.0","P-9456V-24.1.2.163.1158","P-13784V-6.0.0.1.0-6.0.0.3.0","P-5624V-12.2.18-12.2.36","P-2245V-4.5.0.0.0","P-2241V-2.6.0.1.7","P-10757V-9.3.0","P-5757V-23.4-23.6","P-5757V-19.1.0.0.0-19.25.0.0.241015","P-5680V-8.1.2.5","P-9456V-24.1.0.108.0942","P-5477V-13.0.0","P-10605V-20.12.0-20.12.15","P-2245V-24.1.0.0.0-24.3.0.0.0","P-10354V-23.12.0-23.12.12","P-10354V-21.12.0-21.12.17","P-619(Oracle Spatial and Graph Spatial Web Services)V-19.3-19.25","P-5085V-8.61","P-5085V-8.60","P-13545V-8.1.2.8","P-13545V-8.1.2.7","P-5757V-21.3-21.16","P-11528V-3.07","P-14121V-24.2.1","P-9142V-8.1.2.8","P-10899V-8.6.0.4.0","P-9142V-8.1.2.7","P-9456V-24.2.1.180.1634","P-2283V-8.1.0.1","P-2270V-7.5.0","P-4516V-7.6.0","P-2245V-4.4.0.0.0","P-1696V-12.2.1.4.0","P-2245V-4.4.0.2.0","P-9456V-23.4.0.346.1619","P-9456V-24.1.1.120.1228","P-2283V-8.0.0.3","P-2136(Billing Care)V-12.0.0.4-12.0.0.8","P-13545V-8.0.8.2","P-11108V-14.0","P-14276V-8.1.3.0","P-9456V-24.2.2.187.1943","P-14121V-24.2.0","P-14069V-24.4.0","P-10758V-4.2.0","P-2545V-12.2.1.4.0","P-2245V-4.5.0.1.1","P-10757V-9.2.0","P-14069V-23.4.4","P-10354V-20.12.0-20.12.16","P-10354V-22.12.0-22.12.15","P-10761V-5.1","P-9456V-24.2.0.169.2208","P-9646V-Prior to 9.2.3","P-2245V-4.5.0.1.3","P-10761V-5.2","P-10605V-21.12.0-21.12.13","P-9456V-23.3.1.305.1055","P-10354V-24.12.0","P-5680V-8.0.7.8","P-5477V-12.7.2","P-5477V-12.7.1"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-14277V-24.2.0-24.2.2","P-13789V-8.0.8","P-5680V-8.0.8.6","P-2270V-7.4.0","P-2270V-7.4.1","P-13784V-7.0.0.0.0-7.0.0.1.0","P-4516V-7.5.1","P-2545V-14.1.1.0.0","P-2245V-4.4.0.3.0","P-2241V-2.5.0.2.9","P-619(Oracle Spatial and Graph Spatial Web Services)V-21.3-21.16","P-9190V-8.0.8.1","P-2245V-4.3.0.3.0-4.3.0.6.0","P-9456V-23.3.0.289.1830","P-14276V-8.1.2.6","P-14276V-8.1.2.7","P-4622V-13.3.0.1","P-9190V-8.1.2.7","P-9456V-23.4.1.038.1857","P-2136(Billing Care)V-15.0.0.0-15.0.0.1","P-10758V-4.1.0","P-9190V-8.1.2.8","P-1215V-12.2.1.4.0","P-9456V-24.1.2.163.1158","P-13784V-6.0.0.1.0-6.0.0.3.0","P-5624V-12.2.18-12.2.36","P-2245V-4.5.0.0.0","P-2241V-2.6.0.1.7","P-10757V-9.3.0","P-5757V-23.4-23.6","P-5757V-19.1.0.0.0-19.25.0.0.241015","P-5680V-8.1.2.5","P-9456V-24.1.0.108.0942","P-5477V-13.0.0","P-10605V-20.12.0-20.12.15","P-2245V-24.1.0.0.0-24.3.0.0.0","P-10354V-23.12.0-23.12.12","P-10354V-21.12.0-21.12.17","P-619(Oracle Spatial and Graph Spatial Web Services)V-19.3-19.25","P-5085V-8.61","P-5085V-8.60","P-13545V-8.1.2.8","P-13545V-8.1.2.7","P-5757V-21.3-21.16","P-11528V-3.07","P-14121V-24.2.1","P-9142V-8.1.2.8","P-10899V-8.6.0.4.0","P-9142V-8.1.2.7","P-9456V-24.2.1.180.1634","P-2283V-8.1.0.1","P-2270V-7.5.0","P-4516V-7.6.0","P-2245V-4.4.0.0.0","P-1696V-12.2.1.4.0","P-2245V-4.4.0.2.0","P-9456V-23.4.0.346.1619","P-9456V-24.1.1.120.1228","P-2283V-8.0.0.3","P-2136(Billing Care)V-12.0.0.4-12.0.0.8","P-13545V-8.0.8.2","P-11108V-14.0","P-14276V-8.1.3.0","P-9456V-24.2.2.187.1943","P-14121V-24.2.0","P-14069V-24.4.0","P-10758V-4.2.0","P-2545V-12.2.1.4.0","P-2245V-4.5.0.1.1","P-10757V-9.2.0","P-14069V-23.4.4","P-10354V-20.12.0-20.12.16","P-10354V-22.12.0-22.12.15","P-10761V-5.1","P-9456V-24.2.0.169.2208","P-9646V-Prior to 9.2.3","P-2245V-4.5.0.1.3","P-10761V-5.2","P-10605V-21.12.0-21.12.13","P-9456V-23.3.1.305.1055","P-10354V-24.12.0","P-5680V-8.0.7.8","P-5477V-12.7.2","P-5477V-12.7.1"]}]},{"cve":"CVE-2024-4030","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}],"ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"37059368"},{"system_name":"Oracle Bug ID of Oracle Communications Unified Assurance","text":"37059349"},{"system_name":"Oracle Bug ID of Oracle Blockchain Platform","text":"37059329"}],"notes":[{"category":"description","text":"Security-in-Depth issue in Oracle Blockchain Platform (component: Blockchain Cloud Service Console (Python)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Python)).  Supported versions that are affected are 6.0.0-6.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Porting (Python)).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60","P-14597V-6.0.0-6.0.5"],"known_not_affected":["P-13444V-21.1.2","P-13444V-24.1.3"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-6.0.0-6.0.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13444V-21.1.2","P-13444V-24.1.3"]},{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14597V-6.0.0-6.0.5","P-5085V-8.61","P-5085V-8.60"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}]},{"cve":"CVE-2024-4032","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}],"ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"37059368"},{"system_name":"Oracle Bug ID of Oracle Communications Unified Assurance","text":"37059349"},{"system_name":"Oracle Bug ID of Oracle Blockchain Platform","text":"37059329"}],"notes":[{"category":"description","text":"Security-in-Depth issue in Oracle Blockchain Platform (component: Blockchain Cloud Service Console (Python)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Python)).  Supported versions that are affected are 6.0.0-6.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Porting (Python)).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60","P-14597V-6.0.0-6.0.5"],"known_not_affected":["P-13444V-21.1.2","P-13444V-24.1.3"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-6.0.0-6.0.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13444V-21.1.2","P-13444V-24.1.3"]},{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14597V-6.0.0-6.0.5","P-5085V-8.61","P-5085V-8.60"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}]},{"cve":"CVE-2024-40898","ids":[{"system_name":"Oracle Bug ID of Oracle HTTP Server","text":"37042942"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Mod_rewrite, Core (Apache HTTP Server)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data as well as  unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1042(Mod_rewrite, Core)V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042(Mod_rewrite, Core)V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"products":["P-1042(Mod_rewrite, Core)V-12.2.1.4.0"]}]},{"cve":"CVE-2024-41817","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Operations Monitor","text":"37071867"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (ImageMagick)).  Supported versions that are affected are 5.1 and  5.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Operations Monitor executes to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10761V-5.1","P-10761V-5.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10761V-5.1","P-10761V-5.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066003.1"}],"scores":[{"cvss_v3":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-10761V-5.1","P-10761V-5.2"]}]},{"cve":"CVE-2024-43382","ids":[{"system_name":"Oracle Bug ID of Oracle BI Publisher","text":"37147990"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services (Snowflake JDBC)).  Supported versions that are affected are 7.0.0.0.0 and  7.6.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1479V-7.0.0.0.0","P-1479V-7.6.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1479V-7.0.0.0.0","P-1479V-7.6.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":5.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"products":["P-1479V-7.0.0.0.0","P-1479V-7.6.0.0.0"]}]},{"cve":"CVE-2024-45490","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition","text":"37034487"},{"system_name":"Oracle Bug ID of Oracle Communications Network Analytics Data Director","text":"37034444"},{"system_name":"Oracle Bug ID of Oracle HTTP Server","text":"37034488"},{"system_name":"Oracle Bug ID of Oracle Financial Services Behavior Detection Platform","text":"37034486"},{"system_name":"Oracle Bug ID of Oracle Blockchain Platform","text":"37059329"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Install/Upgrade (LibExpat)).  Supported versions that are affected are 24.1.0 and  24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle Blockchain Platform (component: Blockchain Cloud Service Console (Python)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (LibExpat)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (LibExpat)).   The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (LibExpat)).  Supported versions that are affected are 8.0.8.1, 8.1.2.7 and  8.1.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-13789V-8.0.8","P-9190V-8.1.2.7","P-14547V-24.2.0","P-1042(Core)V-12.2.1.4.0","P-14547V-24.1.0","P-9190V-8.0.8.1","P-9190V-8.1.2.8"],"known_not_affected":["P-13444V-21.1.2","P-13444V-24.1.3"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14547V-24.2.0","P-14547V-24.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066023.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042(Core)V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13789V-8.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066716.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9190V-8.1.2.7","P-9190V-8.0.8.1","P-9190V-8.1.2.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066717.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-13789V-8.0.8","P-9190V-8.1.2.7","P-14547V-24.2.0","P-1042(Core)V-12.2.1.4.0","P-14547V-24.1.0","P-9190V-8.0.8.1","P-9190V-8.1.2.8"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13444V-21.1.2","P-13444V-24.1.3"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}]},{"cve":"CVE-2024-45491","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition","text":"37034487"},{"system_name":"Oracle Bug ID of Oracle HTTP Server","text":"37034488"},{"system_name":"Oracle Bug ID of Oracle Communications Network Analytics Data Director","text":"37034444"},{"system_name":"Oracle Bug ID of Oracle Financial Services Behavior Detection Platform","text":"37034486"},{"system_name":"Oracle Bug ID of Oracle Blockchain Platform","text":"37059329"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (LibExpat)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (LibExpat)).   The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (LibExpat)).  Supported versions that are affected are 8.0.8.1, 8.1.2.7 and  8.1.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Install/Upgrade (LibExpat)).  Supported versions that are affected are 24.1.0 and  24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle Blockchain Platform (component: Blockchain Cloud Service Console (Python)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-13789V-8.0.8","P-9190V-8.1.2.7","P-1042(Core)V-12.2.1.4.0","P-14547V-24.2.0","P-9190V-8.0.8.1","P-9190V-8.1.2.8","P-14547V-24.1.0"],"known_not_affected":["P-13444V-21.1.2","P-13444V-24.1.3"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042(Core)V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13789V-8.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066716.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9190V-8.1.2.7","P-9190V-8.0.8.1","P-9190V-8.1.2.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066717.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14547V-24.2.0","P-14547V-24.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066023.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-13789V-8.0.8","P-9190V-8.1.2.7","P-1042(Core)V-12.2.1.4.0","P-14547V-24.2.0","P-9190V-8.0.8.1","P-9190V-8.1.2.8","P-14547V-24.1.0"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13444V-21.1.2","P-13444V-24.1.3"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}]},{"cve":"CVE-2024-45492","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition","text":"37034487"},{"system_name":"Oracle Bug ID of Oracle Communications Network Analytics Data Director","text":"37034444"},{"system_name":"Oracle Bug ID of Oracle HTTP Server","text":"37034488"},{"system_name":"Oracle Bug ID of Oracle Financial Services Behavior Detection Platform","text":"37034486"},{"system_name":"Oracle Bug ID of Oracle Blockchain Platform","text":"37059329"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Install/Upgrade (LibExpat)).  Supported versions that are affected are 24.1.0 and  24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (LibExpat)).  Supported versions that are affected are 8.0.8.1, 8.1.2.7 and  8.1.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (LibExpat)).   The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (LibExpat)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in Oracle Blockchain Platform (component: Blockchain Cloud Service Console (Python)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-13789V-8.0.8","P-9190V-8.1.2.7","P-14547V-24.2.0","P-1042(Core)V-12.2.1.4.0","P-14547V-24.1.0","P-9190V-8.0.8.1","P-9190V-8.1.2.8"],"known_not_affected":["P-13444V-21.1.2","P-13444V-24.1.3"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14547V-24.2.0","P-14547V-24.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066023.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9190V-8.1.2.7","P-9190V-8.0.8.1","P-9190V-8.1.2.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066717.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13789V-8.0.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066716.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042(Core)V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-13789V-8.0.8","P-9190V-8.1.2.7","P-14547V-24.2.0","P-1042(Core)V-12.2.1.4.0","P-14547V-24.1.0","P-9190V-8.0.8.1","P-9190V-8.1.2.8"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13444V-21.1.2","P-13444V-24.1.3"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}]},{"cve":"CVE-2024-45772","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-619(Oracle Spatial and Graph)V-21.3-21.16"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Database Server","text":"37297275"}],"notes":[{"category":"description","text":"Security-in-Depth issue in the Oracle Spatial and Graph (Apache Lucene) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-619(Oracle Spatial and Graph)V-21.3-21.16"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-619(Oracle Spatial and Graph)V-21.3-21.16"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-619(Oracle Spatial and Graph)V-21.3-21.16"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-619(Oracle Spatial and Graph)V-21.3-21.16"]}]},{"cve":"CVE-2024-45801","ids":[{"system_name":"Oracle Bug ID of Oracle Utilities Application Framework","text":"37233724"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General (DOMPurify)).  Supported versions that are affected are 4.3.0.3.0-4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3 and  24.1.0.0.0-24.3.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Utilities Application Framework accessible data as well as  unauthorized read access to a subset of Oracle Utilities Application Framework accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Utilities Application Framework. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2245V-24.1.0.0.0-24.3.0.0.0","P-2245V-4.5.0.1.3","P-2245V-4.5.0.1.1","P-2245V-4.3.0.3.0-4.3.0.6.0","P-2245V-4.5.0.0.0","P-2245V-4.4.0.0.0","P-2245V-4.4.0.2.0","P-2245V-4.4.0.3.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2245V-24.1.0.0.0-24.3.0.0.0","P-2245V-4.5.0.1.3","P-2245V-4.5.0.1.1","P-2245V-4.3.0.3.0-4.3.0.6.0","P-2245V-4.5.0.0.0","P-2245V-4.4.0.0.0","P-2245V-4.4.0.2.0","P-2245V-4.4.0.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066725.1"}],"scores":[{"cvss_v3":{"baseScore":7.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"products":["P-2245V-24.1.0.0.0-24.3.0.0.0","P-2245V-4.5.0.1.3","P-2245V-4.5.0.1.1","P-2245V-4.3.0.3.0-4.3.0.6.0","P-2245V-4.5.0.0.0","P-2245V-4.4.0.0.0","P-2245V-4.4.0.2.0","P-2245V-4.4.0.3.0"]}]},{"cve":"CVE-2024-4603","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"37044734"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security, Porting, Cloud Deployment Architecture (OpenSSL)).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","version":"3.1"},"products":["P-5085V-8.61","P-5085V-8.60"]}]},{"cve":"CVE-2024-47072","ids":[{"system_name":"Oracle Bug ID of Oracle Business Activity Monitoring","text":"37335185"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Activity Monitoring product of Oracle Fusion Middleware (component: BAM (XStream)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Activity Monitoring.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Activity Monitoring. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1675V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1675V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-1675V-12.2.1.4.0"]}]},{"cve":"CVE-2024-4741","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"37044734"},{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36991444"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security, Porting, Cloud Deployment Architecture (OpenSSL)).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security (OpenSSL)).  Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0","P-2025V-12.2.1.4.0","P-5085V-8.61","P-5085V-8.60"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-12.2.1.4.0","P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","version":"3.1"},"products":["P-2025V-12.2.1.4.0","P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0","P-5085V-8.61","P-5085V-8.60"]}]},{"cve":"CVE-2024-47535","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Service Catalog and Design","text":"37332162"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications Applications (component: Solution Designer (Netty)).  Supported versions that are affected are 8.0.0.3 and  8.1.0.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Service Catalog and Design executes to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2283V-8.0.0.3","P-2283V-8.1.0.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2283V-8.0.0.3","P-2283V-8.1.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064016.1"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-2283V-8.0.0.3","P-2283V-8.1.0.1"]}]},{"cve":"CVE-2024-47554","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-5(Oracle Database Workload Manager)V-21.4-21.16"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Communications Unified Assurance","text":"37358381"},{"system_name":"Oracle Bug ID of Oracle Communications Service Catalog and Design","text":"37305997"},{"system_name":"Oracle Bug ID of Oracle Communications Convergence","text":"37477009"},{"system_name":"Oracle Bug ID of Oracle WebCenter Portal","text":"37158244"},{"system_name":"Oracle Bug ID of Oracle Database Server","text":"37161881"},{"system_name":"Oracle Bug ID of Primavera Unifier","text":"37215110"},{"system_name":"Oracle Bug ID of Oracle WebLogic Server","text":"37335043"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Commons IO)).  Supported versions that are affected are 6.0.4-6.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: Configuration (Apache Commons IO)).  Supported versions that are affected are 3.0.2.0.0, 3.0.3.0.0 and  3.0.3.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Convergence.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Convergence. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Commons IO)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications Applications (component: Solution Designer (Apache Commons IO)).  Supported versions that are affected are 8.0.0.3 and  8.1.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Document Management (Apache Commons IO)).  Supported versions that are affected are 20.12.0-20.12.16, 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.12 and  24.12.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Primavera Unifier.  While the vulnerability is in Primavera Unifier, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Primavera Unifier. CVSS 3.1 Base Score 6.8 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Database Workload Manager (Apache Commons-IO) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (Apache Commons IO)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8501V-3.0.2.0.0","P-2283V-8.1.0.1","P-5242V-14.1.2.0.0","P-1696V-12.2.1.4.0","P-10354V-20.12.0-20.12.16","P-10354V-22.12.0-22.12.15","P-8501V-3.0.3.0.0","P-5242V-14.1.1.0.0","P-2283V-8.0.0.3","P-10354V-23.12.0-23.12.12","P-10354V-21.12.0-21.12.17","P-8501V-3.0.3.3.0","P-5242V-12.2.1.4.0","P-10354V-24.12.0","P-14597V-6.0.4-6.0.5"],"known_not_affected":["P-5(Oracle Database Workload Manager)V-21.4-21.16"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-6.0.4-6.0.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8501V-3.0.2.0.0","P-8501V-3.0.3.0.0","P-8501V-3.0.3.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3068476.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.4.0","P-5242V-14.1.2.0.0","P-1696V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2283V-8.0.0.3","P-2283V-8.1.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10354V-20.12.0-20.12.16","P-10354V-22.12.0-22.12.15","P-10354V-23.12.0-23.12.12","P-10354V-21.12.0-21.12.17","P-10354V-24.12.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065975.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5(Oracle Database Workload Manager)V-21.4-21.16"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-5242V-14.1.1.0.0","P-2283V-8.0.0.3","P-2283V-8.1.0.1","P-5242V-12.2.1.4.0","P-5242V-14.1.2.0.0","P-14597V-6.0.4-6.0.5"]},{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","version":"3.1"},"products":["P-8501V-3.0.2.0.0","P-8501V-3.0.3.0.0","P-8501V-3.0.3.3.0","P-1696V-12.2.1.4.0"]},{"cvss_v3":{"baseScore":6.8,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H","version":"3.1"},"products":["P-10354V-20.12.0-20.12.16","P-10354V-22.12.0-22.12.15","P-10354V-23.12.0-23.12.12","P-10354V-21.12.0-21.12.17","P-10354V-24.12.0"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-5(Oracle Database Workload Manager)V-21.4-21.16"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-5(Oracle Database Workload Manager)V-21.4-21.16"]}]},{"cve":"CVE-2024-47561","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Unified Assurance","text":"37363688"},{"system_name":"Oracle Bug ID of Oracle Business Process Management Suite","text":"37149355"},{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"37276121"},{"system_name":"Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters","text":"37203419"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Composer (Apache Avro)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Process Management Suite accessible data as well as  unauthorized read access to a subset of Oracle Business Process Management Suite accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Process Management Suite. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security (Apache Avro)).  Supported versions that are affected are 7.0.0.0.0 and  7.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Avro)).  Supported versions that are affected are 6.0.4-6.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Apache Avro)).  Supported versions that are affected are 19.1.0.0.0-19.1.0.0.18, 21.3.0.0.0-21.16.0.0.0 and 23.4-23.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle GoldenGate Big Data and Application Adapters executes to compromise Oracle GoldenGate Big Data and Application Adapters.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle GoldenGate Big Data and Application Adapters accessible data as well as  unauthorized read access to a subset of Oracle GoldenGate Big Data and Application Adapters accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GoldenGate Big Data and Application Adapters. CVSS 3.1 Base Score 5.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5760V-19.1.0.0.0-19.1.0.0.18","P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0","P-5325V-12.2.1.4.0","P-14597V-6.0.4-6.0.5","P-5760V-21.3.0.0.0-21.16.0.0.0","P-5760V-23.4-23.6"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5325V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-6.0.4-6.0.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5760V-19.1.0.0.0-19.1.0.0.18","P-5760V-21.3.0.0.0-21.16.0.0.0","P-5760V-23.4-23.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":7.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"products":["P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0","P-5325V-12.2.1.4.0","P-14597V-6.0.4-6.0.5"]},{"cvss_v3":{"baseScore":5.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"products":["P-5760V-19.1.0.0.0-19.1.0.0.18","P-5760V-21.3.0.0.0-21.16.0.0.0","P-5760V-23.4-23.6"]}]},{"cve":"CVE-2024-47803","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Automated Test Suite","text":"37316428"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function","text":"37316430"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy","text":"37316441"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Policy","text":"37316440"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy","text":"37316443"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Jenkins)).  Supported versions that are affected are 24.2.0 and  24.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP/2 to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Jenkins)).  Supported versions that are affected are 24.2.0-24.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Jenkins)).  Supported versions that are affected are 24.2.0 and  24.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Service Communication Proxy accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: ATS Framework (Jenkins)).  Supported versions that are affected are 24.2.0, 24.2.1 and  24.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: ATS Framework (Jenkins)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Automated Test Suite accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14121V-24.2.1","P-14277V-24.2.0-24.2.2","P-14117V-24.2.0","P-14488V-24.2.0","P-14117V-24.3.0","P-14123V-24.2.1","P-14123V-24.2.2","P-14123V-24.2.0","P-14121V-24.2.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-24.2.1","P-14121V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066001.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-24.2.0-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066021.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14117V-24.2.0","P-14117V-24.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066004.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-24.2.1","P-14123V-24.2.2","P-14123V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14488V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066022.1"}],"scores":[{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"products":["P-14121V-24.2.1","P-14277V-24.2.0-24.2.2","P-14117V-24.2.0","P-14488V-24.2.0","P-14117V-24.3.0","P-14123V-24.2.1","P-14123V-24.2.2","P-14123V-24.2.0","P-14121V-24.2.0"]}]},{"cve":"CVE-2024-47804","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Automated Test Suite","text":"37316428"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy","text":"37316441"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function","text":"37316430"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Policy","text":"37316440"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy","text":"37316443"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Jenkins)).  Supported versions that are affected are 24.2.0 and  24.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Service Communication Proxy accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: ATS Framework (Jenkins)).  Supported versions that are affected are 24.2.0, 24.2.1 and  24.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Jenkins)).  Supported versions that are affected are 24.2.0-24.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Jenkins)).  Supported versions that are affected are 24.2.0 and  24.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP/2 to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: ATS Framework (Jenkins)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Automated Test Suite accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14277V-24.2.0-24.2.2","P-14121V-24.2.1","P-14117V-24.2.0","P-14488V-24.2.0","P-14117V-24.3.0","P-14123V-24.2.1","P-14123V-24.2.2","P-14123V-24.2.0","P-14121V-24.2.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14117V-24.2.0","P-14117V-24.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066004.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-24.2.1","P-14123V-24.2.2","P-14123V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-24.2.0-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066021.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-24.2.1","P-14121V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066001.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14488V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066022.1"}],"scores":[{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"products":["P-14277V-24.2.0-24.2.2","P-14121V-24.2.1","P-14117V-24.2.0","P-14488V-24.2.0","P-14117V-24.3.0","P-14123V-24.2.1","P-14123V-24.2.2","P-14123V-24.2.0","P-14121V-24.2.0"]}]},{"cve":"CVE-2024-49766","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment","text":"37243646"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core DBTier","text":"37253017"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (Werkzeug)).  Supported versions that are affected are 24.2.0 and  24.3.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Cloud Native Core Network Function Cloud Native Environment executes to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Werkzeug)).  Supported versions that are affected are 24.1.0 and  24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Cloud Native Core DBTier executes to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core DBTier. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14125V-24.2.0","P-14974V-24.2.0","P-14125V-24.3.0","P-14974V-24.1.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14125V-24.2.0","P-14125V-24.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066005.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14974V-24.2.0","P-14974V-24.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066027.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14125V-24.2.0","P-14125V-24.3.0"]},{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["P-14974V-24.2.0","P-14974V-24.1.0"]}]},{"cve":"CVE-2024-49767","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function","text":"37328093"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment","text":"37243646"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository","text":"37328107"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Automated Test Suite","text":"37328091"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Policy","text":"37328101"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy","text":"37328103"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core DBTier","text":"37253017"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function","text":"37328099"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (Werkzeug)).  Supported versions that are affected are 24.2.0 and  24.3.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Cloud Native Core Network Function Cloud Native Environment executes to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Automated Test Suite (Werkzeug)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Werkzeug)).  Supported versions that are affected are 24.3.0 and  24.2.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Werkzeug)).  Supported versions that are affected are 24.2.0 and  24.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Install (Werkzeug)).   The supported version that is affected is 24.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Werkzeug)).  Supported versions that are affected are 24.2.0-24.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Werkzeug)).  Supported versions that are affected are 24.1.0 and  24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Cloud Native Core DBTier executes to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core DBTier. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: ATS Framework (Werkzeug)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14125V-24.2.0","P-14119V-24.2.3","P-14121V-24.2.1","P-14277V-24.2.0-24.2.2","P-14119V-24.3.0","P-14488V-24.2.0","P-14974V-24.2.0","P-14125V-24.3.0","P-14974V-24.1.0","P-14123V-24.2.0","P-14121V-24.2.0","P-14118V-24.2.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14125V-24.2.0","P-14125V-24.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066005.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14119V-24.2.3","P-14119V-24.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066908.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-24.2.1","P-14121V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066001.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14118V-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3067478.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-24.2.0-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066021.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14974V-24.2.0","P-14974V-24.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066027.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14488V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066022.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14125V-24.2.0","P-14125V-24.3.0"]},{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14119V-24.2.3","P-14121V-24.2.1","P-14277V-24.2.0-24.2.2","P-14119V-24.3.0","P-14488V-24.2.0","P-14123V-24.2.0","P-14121V-24.2.0","P-14118V-24.2.2"]},{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["P-14974V-24.2.0","P-14974V-24.1.0"]}]},{"cve":"CVE-2024-50379","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_cannot_be_controlled_by_adversary","product_ids":["P-14069V-23.4.4","P-14069V-24.4.0"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Communications Policy Management","text":"37440948"},{"system_name":"Oracle Bug ID of Graph Server and Client","text":"37440964"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (Apache Tomcat)).   The supported version that is affected is 15.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Graph Server and Client product of Oracle Graph Server and Client (component: Install (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10900V-15.0.0.0.0"],"known_not_affected":["P-14069V-23.4.4","P-14069V-24.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10900V-15.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14069V-23.4.4","P-14069V-24.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-10900V-15.0.0.0.0"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-14069V-23.4.4","P-14069V-24.4.0"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.","product_ids":["P-14069V-23.4.4","P-14069V-24.4.0"]}]},{"cve":"CVE-2024-50602","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Policy","text":"37414519"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function","text":"37414523"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository","text":"37414522"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (LibExpat)).  Supported versions that are affected are 24.2.0-24.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (LibExpat)).   The supported version that is affected is 24.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Alarms, KPI, and Measurements (LibExpat)).  Supported versions that are affected are 24.2.0 and  24.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14277V-24.2.0-24.2.2","P-14121V-24.2.1","P-14119V-24.3.0","P-14121V-24.2.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-24.2.0-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066021.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14119V-24.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066908.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-24.2.1","P-14121V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066001.1"}],"scores":[{"cvss_v3":{"baseScore":5.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14277V-24.2.0-24.2.2","P-14121V-24.2.1","P-14119V-24.3.0","P-14121V-24.2.0"]}]},{"cve":"CVE-2024-52316","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-5(Oracle Database Workload Manager)V-21.4-21.16","P-5(Oracle Database Grid)V-19.3-19.25","P-5(Oracle Database Grid)V-21.3-21.16"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Database Server","text":"37161881"},{"system_name":"Oracle Bug ID of Oracle Database Server","text":"37302727"}],"notes":[{"category":"description","text":"Security-in-Depth issue in the Oracle Database Workload Manager (Apache Commons-IO) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Oracle Database Grid (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-5(Oracle Database Workload Manager)V-21.4-21.16","P-5(Oracle Database Grid)V-19.3-19.25","P-5(Oracle Database Grid)V-21.3-21.16"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5(Oracle Database Workload Manager)V-21.4-21.16","P-5(Oracle Database Grid)V-19.3-19.25","P-5(Oracle Database Grid)V-21.3-21.16"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-5(Oracle Database Workload Manager)V-21.4-21.16"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-5(Oracle Database Grid)V-19.3-19.25","P-5(Oracle Database Grid)V-21.3-21.16"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-5(Oracle Database Workload Manager)V-21.4-21.16","P-5(Oracle Database Grid)V-19.3-19.25","P-5(Oracle Database Grid)V-21.3-21.16"]}]},{"cve":"CVE-2024-52317","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-5(Oracle Database Grid)V-19.3-19.25","P-5(Oracle Database Grid)V-21.3-21.16"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Database Server","text":"37302727"}],"notes":[{"category":"description","text":"Security-in-Depth issue in the Oracle Database Grid (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-5(Oracle Database Grid)V-19.3-19.25","P-5(Oracle Database Grid)V-21.3-21.16"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5(Oracle Database Grid)V-19.3-19.25","P-5(Oracle Database Grid)V-21.3-21.16"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-5(Oracle Database Grid)V-19.3-19.25","P-5(Oracle Database Grid)V-21.3-21.16"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-5(Oracle Database Grid)V-19.3-19.25","P-5(Oracle Database Grid)V-21.3-21.16"]}]},{"cve":"CVE-2024-53677","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Policy Management","text":"37390135"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (Apache Struts 2)).   The supported version that is affected is 15.0.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  While the vulnerability is in Oracle Communications Policy Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10900V-15.0.0.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10900V-15.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066016.1"}],"scores":[{"cvss_v3":{"baseScore":9.0,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"products":["P-10900V-15.0.0.0.0"]}]},{"cve":"CVE-2024-54677","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_cannot_be_controlled_by_adversary","product_ids":["P-14069V-23.4.4","P-14069V-24.4.0"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Communications Policy Management","text":"37440948"},{"system_name":"Oracle Bug ID of Graph Server and Client","text":"37440964"}],"notes":[{"category":"description","text":"Security-in-Depth issue in the Graph Server and Client product of Oracle Graph Server and Client (component: Install (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (Apache Tomcat)).   The supported version that is affected is 15.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10900V-15.0.0.0.0"],"known_not_affected":["P-14069V-23.4.4","P-14069V-24.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14069V-23.4.4","P-14069V-24.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10900V-15.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066016.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-14069V-23.4.4","P-14069V-24.4.0"]},{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-10900V-15.0.0.0.0"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.","product_ids":["P-14069V-23.4.4","P-14069V-24.4.0"]}]},{"cve":"CVE-2024-5535","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Console","text":"37425618"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management","text":"37210531"},{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"36991444"},{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"37044734"},{"system_name":"Oracle Bug ID of Oracle HTTP Server","text":"37044724"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Mod_Security (OpenSSL)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security (OpenSSL)).  Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security, Porting, Cloud Deployment Architecture (OpenSSL)).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (OpenSSL)).   The supported version that is affected is 24.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (OpenSSL)).   The supported version that is affected is 24.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Certificate Management. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14250V-24.2.1","P-2025V-12.2.1.4.0","P-1042(Mod_Security)V-12.2.1.4.0","P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0","P-5085V-8.61","P-14868V-24.2.1","P-5085V-8.60"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042(Mod_Security)V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2025V-12.2.1.4.0","P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14250V-24.2.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066907.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14868V-24.2.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066002.1"}],"scores":[{"cvss_v3":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","version":"3.1"},"products":["P-2025V-12.2.1.4.0","P-1042(Mod_Security)V-12.2.1.4.0","P-2025V-7.6.0.0.0","P-2025V-7.0.0.0.0","P-5085V-8.61","P-5085V-8.60"]},{"cvss_v3":{"baseScore":5.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14250V-24.2.1"]},{"cvss_v3":{"baseScore":3.7,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["P-14868V-24.2.1"]}]},{"cve":"CVE-2024-56337","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_cannot_be_controlled_by_adversary","product_ids":["P-14069V-23.4.4","P-14069V-24.4.0"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Communications Policy Management","text":"37440948"},{"system_name":"Oracle Bug ID of Graph Server and Client","text":"37440964"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (Apache Tomcat)).   The supported version that is affected is 15.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Security-in-Depth issue in the Graph Server and Client product of Oracle Graph Server and Client (component: Install (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10900V-15.0.0.0.0"],"known_not_affected":["P-14069V-23.4.4","P-14069V-24.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10900V-15.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066016.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14069V-23.4.4","P-14069V-24.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-10900V-15.0.0.0.0"]},{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-14069V-23.4.4","P-14069V-24.4.0"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.","product_ids":["P-14069V-23.4.4","P-14069V-24.4.0"]}]},{"cve":"CVE-2024-6119","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment","text":"37034294"},{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"37044734"},{"system_name":"Oracle Bug ID of Oracle HTTP Server","text":"37044724"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (Cryptography)).   The supported version that is affected is 24.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Mod_Security (OpenSSL)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security, Porting, Cloud Deployment Architecture (OpenSSL)).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60","P-1042(Mod_Security)V-12.2.1.4.0","P-14125V-24.3.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14125V-24.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066005.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042(Mod_Security)V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":5.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14125V-24.3.0"]},{"cvss_v3":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","version":"3.1"},"products":["P-1042(Mod_Security)V-12.2.1.4.0","P-5085V-8.61","P-5085V-8.60"]}]},{"cve":"CVE-2024-6162","ids":[{"system_name":"Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine","text":"37051249"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Security (Netty)).  Supported versions that are affected are 12.0.0.4-12.0.0.8, 15.0.0.0 and  15.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications BRM - Elastic Charging Engine. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9742V-15.0.0.0","P-9742V-15.0.1.0","P-9742V-12.0.0.4-12.0.0.8"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9742V-12.0.0.4-12.0.0.8","P-9742V-15.0.0.0","P-9742V-15.0.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064019.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-9742V-12.0.0.4-12.0.0.8","P-9742V-15.0.0.0","P-9742V-15.0.1.0"]}]},{"cve":"CVE-2024-6232","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}],"ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"37059368"},{"system_name":"Oracle Bug ID of Oracle Communications Unified Assurance","text":"37059349"},{"system_name":"Oracle Bug ID of Oracle Blockchain Platform","text":"37059329"}],"notes":[{"category":"description","text":"Security-in-Depth issue in Oracle Blockchain Platform (component: Blockchain Cloud Service Console (Python)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Porting (Python)).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Python)).  Supported versions that are affected are 6.0.0-6.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60","P-14597V-6.0.0-6.0.5"],"known_not_affected":["P-13444V-21.1.2","P-13444V-24.1.3"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-6.0.0-6.0.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064020.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13444V-21.1.2","P-13444V-24.1.3"]},{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14597V-6.0.0-6.0.5","P-5085V-8.61","P-5085V-8.60"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}]},{"cve":"CVE-2024-6763","ids":[{"system_name":"Oracle Bug ID of Oracle REST Data Services","text":"37206827"}],"notes":[{"category":"description","text":"Vulnerability in Oracle REST Data Services (component: General (Eclipse Jetty)).  Supported versions that are affected are 24.2.0 and  24.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle REST Data Services.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle REST Data Services accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9456V-24.3.0","P-9456V-24.2.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9456V-24.3.0","P-9456V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"products":["P-9456V-24.3.0","P-9456V-24.2.0"]}]},{"cve":"CVE-2024-6923","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Blockchain Platform","text":"37059329"}],"notes":[{"category":"description","text":"Security-in-Depth issue in Oracle Blockchain Platform (component: Blockchain Cloud Service Console (Python)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-13444V-21.1.2","P-13444V-24.1.3"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13444V-21.1.2","P-13444V-24.1.3"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}]},{"cve":"CVE-2024-7254","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-619(Oracle Spatial and Graph Mapviewer)V-19.3-19.25","P-619(Oracle Spatial and Graph Mapviewer)V-21.3-21.16"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Database Server","text":"37093559"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Policy","text":"37113053"},{"system_name":"Oracle Bug ID of Oracle BI Publisher","text":"37147990"},{"system_name":"Oracle Bug ID of Oracle Business Intelligence Enterprise Edition","text":"37148178"},{"system_name":"Oracle Bug ID of Oracle Communications Unified Assurance","text":"37297550"},{"system_name":"Oracle Bug ID of Oracle Communications Service Catalog and Design","text":"37332117"}],"notes":[{"category":"description","text":"Security-in-Depth issue in the Oracle Spatial and Graph Mapviewer (Google Protobuf-Java) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy Control Function (Google Protobuf-Java)).  Supported versions that are affected are 24.2.0-24.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services (Snowflake JDBC)).  Supported versions that are affected are 7.0.0.0.0 and  7.6.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server, Map viewer (Google Protobuf-Java)).   The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Microservices (Google Protobuf-Java)).  Supported versions that are affected are 6.0.0-6.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications Applications (component: Solution Designer (Google Protobuf-Java)).  Supported versions that are affected are 8.0.0.3 and  8.1.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14277V-24.2.0-24.2.2","P-1479V-7.0.0.0.0","P-2283V-8.0.0.3","P-1479V-7.6.0.0.0","P-14597V-6.0.0-6.0.5","P-2283V-8.1.0.1","P-2025V-7.0.0.0.0"],"known_not_affected":["P-619(Oracle Spatial and Graph Mapviewer)V-19.3-19.25","P-619(Oracle Spatial and Graph Mapviewer)V-21.3-21.16"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-619(Oracle Spatial and Graph Mapviewer)V-19.3-19.25","P-619(Oracle Spatial and Graph Mapviewer)V-21.3-21.16"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-24.2.0-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066021.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1479V-7.0.0.0.0","P-1479V-7.6.0.0.0","P-2025V-7.0.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-6.0.0-6.0.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2283V-8.0.0.3","P-2283V-8.1.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064016.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-619(Oracle Spatial and Graph Mapviewer)V-19.3-19.25","P-619(Oracle Spatial and Graph Mapviewer)V-21.3-21.16"]},{"cvss_v3":{"baseScore":8.2,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","version":"3.1"},"products":["P-14277V-24.2.0-24.2.2"]},{"cvss_v3":{"baseScore":5.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"products":["P-1479V-7.0.0.0.0","P-1479V-7.6.0.0.0"]},{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-2283V-8.0.0.3","P-14597V-6.0.0-6.0.5","P-2283V-8.1.0.1","P-2025V-7.0.0.0.0"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-619(Oracle Spatial and Graph Mapviewer)V-19.3-19.25","P-619(Oracle Spatial and Graph Mapviewer)V-21.3-21.16"]}]},{"cve":"CVE-2024-7592","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}],"ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"37059368"},{"system_name":"Oracle Bug ID of Oracle Communications Unified Assurance","text":"37059349"},{"system_name":"Oracle Bug ID of Oracle Blockchain Platform","text":"37059329"}],"notes":[{"category":"description","text":"Security-in-Depth issue in Oracle Blockchain Platform (component: Blockchain Cloud Service Console (Python)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Python)).  Supported versions that are affected are 6.0.0-6.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Porting (Python)).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60","P-14597V-6.0.0-6.0.5"],"known_not_affected":["P-13444V-21.1.2","P-13444V-24.1.3"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14597V-6.0.0-6.0.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13444V-21.1.2","P-13444V-24.1.3"]},{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14597V-6.0.0-6.0.5","P-5085V-8.61","P-5085V-8.60"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}]},{"cve":"CVE-2024-7885","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Policy","text":"37289630"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy","text":"37289632"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy","text":"37289633"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Console","text":"37429111"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function","text":"37289627"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository","text":"37289634"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function","text":"37289625"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install (Undertow)).  Supported versions that are affected are 24.2.0 and  24.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Install (Undertow)).   The supported version that is affected is 24.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Undertow)).  Supported versions that are affected are 24.2.0-24.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Undertow)).  Supported versions that are affected are 24.2.0, 24.2.1 and  24.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Signaling (Undertow)).  Supported versions that are affected are 24.2.0 and  24.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Install (Undertow)).   The supported version that is affected is 24.2.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (Undertow)).   The supported version that is affected is 24.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14119V-24.2.3","P-14250V-24.2.1","P-14121V-24.2.1","P-14277V-24.2.0-24.2.2","P-14117V-24.2.0","P-14117V-24.3.0","P-14123V-24.2.1","P-14123V-24.2.2","P-14123V-24.2.0","P-14121V-24.2.0","P-14118V-24.2.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14121V-24.2.1","P-14121V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066001.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14118V-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3067478.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14277V-24.2.0-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066021.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-24.2.1","P-14123V-24.2.2","P-14123V-24.2.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14117V-24.2.0","P-14117V-24.3.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066004.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14119V-24.2.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066908.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14250V-24.2.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066907.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-14119V-24.2.3","P-14250V-24.2.1","P-14121V-24.2.1","P-14277V-24.2.0-24.2.2","P-14117V-24.2.0","P-14117V-24.3.0","P-14123V-24.2.1","P-14123V-24.2.2","P-14123V-24.2.0","P-14121V-24.2.0","P-14118V-24.2.2"]}]},{"cve":"CVE-2024-8006","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Operations Monitor","text":"37107949"},{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy","text":"37107934"},{"system_name":"Oracle Bug ID of Oracle SD-WAN Edge","text":"37107962"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: ATS Framework (libpcap)).   The supported version that is affected is 24.2.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Security Edge Protection Proxy executes to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (libpcap)).  Supported versions that are affected are 5.1 and  5.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Operations Monitor executes to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Internal Tools (libpcap)).  Supported versions that are affected are 9.1.1.5-9.1.1.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle SD-WAN Edge executes to compromise Oracle SD-WAN Edge.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Edge. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10761V-5.1","P-14123V-24.2.2","P-13940V-9.1.1.5-9.1.1.8","P-10761V-5.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14123V-24.2.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066020.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10761V-5.1","P-10761V-5.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066003.1"},{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13940V-9.1.1.5-9.1.1.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066026.1"}],"scores":[{"cvss_v3":{"baseScore":4.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-10761V-5.1","P-13940V-9.1.1.5-9.1.1.8","P-10761V-5.2","P-14123V-24.2.2"]}]},{"cve":"CVE-2024-8088","flags":[{"date":"2025-01-21T13:00:00-07:00","label":"vulnerable_code_not_in_execute_path","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}],"ids":[{"system_name":"Oracle Bug ID of Oracle Blockchain Platform","text":"37059329"}],"notes":[{"category":"description","text":"Security-in-Depth issue in Oracle Blockchain Platform (component: Blockchain Cloud Service Console (Python)). This vulnerability cannot be exploited in the context of this product.","title":"Vulnerability Description"}],"product_status":{"known_not_affected":["P-13444V-21.1.2","P-13444V-24.1.3"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":0.0,"baseSeverity":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","version":"3.1"},"products":["P-13444V-21.1.2","P-13444V-24.1.3"]}],"threats":[{"category":"impact","date":"2025-01-21T13:00:00-07:00","details":"The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.","product_ids":["P-13444V-21.1.2","P-13444V-24.1.3"]}]},{"cve":"CVE-2024-8096","ids":[{"system_name":"Oracle Bug ID of Oracle HTTP Server","text":"36955222"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Mod_Security (curl)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle HTTP Server accessible data as well as  unauthorized read access to a subset of Oracle HTTP Server accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1042(Mod_Security)V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042(Mod_Security)V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-1042(Mod_Security)V-12.2.1.4.0"]}]},{"cve":"CVE-2024-8927","ids":[{"system_name":"Oracle Bug ID of Oracle Secure Backup","text":"37264570"}],"notes":[{"category":"description","text":"Vulnerability in Oracle Secure Backup (component: General (PHP)).  Supported versions that are affected are 18.1.0.1.0, 18.1.0.2.0 and  19.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Secure Backup.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Secure Backup accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1522V-19.1.0.0.0","P-1522V-18.1.0.1.0","P-1522V-18.1.0.2.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1522V-18.1.0.1.0","P-1522V-18.1.0.2.0","P-1522V-19.1.0.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-1522V-18.1.0.1.0","P-1522V-18.1.0.2.0","P-1522V-19.1.0.0.0"]}]},{"cve":"CVE-2024-9143","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Cloud Native Core Certificate Management","text":"37210531"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Cloud Native Core Certificate Management product of Oracle Communications (component: Configuration (OpenSSL)).   The supported version that is affected is 24.2.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Certificate Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Certificate Management. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-14868V-24.2.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-14868V-24.2.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066002.1"}],"scores":[{"cvss_v3":{"baseScore":3.7,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"products":["P-14868V-24.2.1"]}]},{"cve":"CVE-2025-0509","ids":[{"system_name":"Oracle Bug ID of Oracle Java SE","text":"37164018"}],"notes":[{"category":"description","text":"Vulnerability in Oracle Java SE (component: Install (Sparkle)).   The supported version that is affected is Oracle Java SE: 8u431. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Java SE executes to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Java SE, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: Only applies to the macOS autoupdater. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-856V-Oracle Java SE:8u431"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-856V-Oracle Java SE:8u431"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066051.1"}],"scores":[{"cvss_v3":{"baseScore":7.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H","version":"3.1"},"products":["P-856V-Oracle Java SE:8u431"]}]},{"cve":"CVE-2025-21489","ids":[{"system_name":"Oracle Bug ID of Oracle Advanced Outbound Telephony","text":"33025216"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Region Mapping).  Supported versions that are affected are 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data as well as  unauthorized read access to a subset of Oracle Advanced Outbound Telephony accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-785V-12.2.3-12.2.10"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-785V-12.2.3-12.2.10"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2484000.1"}],"scores":[{"cvss_v3":{"baseScore":6.1,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-785V-12.2.3-12.2.10"]}]},{"cve":"CVE-2025-21490","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"33327093"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"]}]},{"cve":"CVE-2025-21491","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"33691659"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"]}]},{"cve":"CVE-2025-21492","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"35945239"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.36 and prior and  8.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: Optimizer)V-8.0.36 and prior","P-8478(Server: Optimizer)V-8.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Optimizer)V-8.4.0","P-8478(Server: Optimizer)V-8.0.36 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(Server: Optimizer)V-8.4.0","P-8478(Server: Optimizer)V-8.0.36 and prior"]}]},{"cve":"CVE-2025-21493","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"35981769"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges).  Supported versions that are affected are 8.4.3 and prior and  9.1.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: Security: Privileges)V-8.4.3 and prior","P-8478(Server: Security: Privileges)V-9.1.0 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Security: Privileges)V-8.4.3 and prior","P-8478(Server: Security: Privileges)V-9.1.0 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(Server: Security: Privileges)V-8.4.3 and prior","P-8478(Server: Security: Privileges)V-9.1.0 and prior"]}]},{"cve":"CVE-2025-21494","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36043213"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges).  Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and  9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.1 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: Security: Privileges)V-8.0.39 and prior","P-8478(Server: Security: Privileges)V-9.0.1 and prior","P-8478(Server: Security: Privileges)V-8.4.2 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Security: Privileges)V-8.0.39 and prior","P-8478(Server: Security: Privileges)V-9.0.1 and prior","P-8478(Server: Security: Privileges)V-8.4.2 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.1,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(Server: Security: Privileges)V-8.0.39 and prior","P-8478(Server: Security: Privileges)V-9.0.1 and prior","P-8478(Server: Security: Privileges)V-8.4.2 and prior"]}]},{"cve":"CVE-2025-21495","ids":[{"system_name":"Oracle Bug ID of MySQL Enterprise Firewall","text":"36084822"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Enterprise Firewall product of Oracle MySQL (component: Firewall).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Enterprise Firewall.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Enterprise Firewall. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Firewall)V-9.1.0 and prior","P-8478(Firewall)V-8.0.40 and prior","P-8478(Firewall)V-8.4.3 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Firewall)V-9.1.0 and prior","P-8478(Firewall)V-8.4.3 and prior","P-8478(Firewall)V-8.0.40 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(Firewall)V-9.1.0 and prior","P-8478(Firewall)V-8.4.3 and prior","P-8478(Firewall)V-8.0.40 and prior"]}]},{"cve":"CVE-2025-21497","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36234681"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"products":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"]}]},{"cve":"CVE-2025-21498","ids":[{"system_name":"Oracle Bug ID of Oracle HTTP Server","text":"36342357"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle HTTP Server accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1042(Core)V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1042(Core)V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"products":["P-1042(Core)V-12.2.1.4.0"]}]},{"cve":"CVE-2025-21499","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36347992"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL).  Supported versions that are affected are 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: DDL)V-9.1.0 and prior","P-8478(Server: DDL)V-8.4.3 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: DDL)V-9.1.0 and prior","P-8478(Server: DDL)V-8.4.3 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(Server: DDL)V-9.1.0 and prior","P-8478(Server: DDL)V-8.4.3 and prior"]}]},{"acknowledgments":[{"names":["Jie Liang"],"organization":"WingTecher Lab"},{"names":["Jingzhou Fu"],"organization":"WingTecher Lab"},{"names":["Zhiyong Wu"],"organization":"WingTecher Lab"}],"cve":"CVE-2025-21500","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36421704"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: Optimizer)V-8.4.3 and prior","P-8478(Server: Optimizer)V-8.0.40 and prior","P-8478(Server: Optimizer)V-9.1.0 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Optimizer)V-8.4.3 and prior","P-8478(Server: Optimizer)V-8.0.40 and prior","P-8478(Server: Optimizer)V-9.1.0 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(Server: Optimizer)V-8.4.3 and prior","P-8478(Server: Optimizer)V-8.0.40 and prior","P-8478(Server: Optimizer)V-9.1.0 and prior"]}]},{"acknowledgments":[{"names":["Jie Liang"],"organization":"WingTecher Lab"},{"names":["Jingzhou Fu"],"organization":"WingTecher Lab"},{"names":["Zhiyong Wu"],"organization":"WingTecher Lab"}],"cve":"CVE-2025-21501","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36421735"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: Optimizer)V-8.4.3 and prior","P-8478(Server: Optimizer)V-8.0.40 and prior","P-8478(Server: Optimizer)V-9.1.0 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Optimizer)V-8.4.3 and prior","P-8478(Server: Optimizer)V-8.0.40 and prior","P-8478(Server: Optimizer)V-9.1.0 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(Server: Optimizer)V-8.4.3 and prior","P-8478(Server: Optimizer)V-8.0.40 and prior","P-8478(Server: Optimizer)V-9.1.0 and prior"]}]},{"cve":"CVE-2025-21502","ids":[{"system_name":"Oracle Bug ID of Oracle Java SE","text":"36425674"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot).  Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM for JDK: 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM Enterprise Edition: 20.3.16 and  21.3.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-856V-Oracle Java SE:8u431-perf","P-856V-Oracle Java SE:11.0.25","P-856V-Oracle GraalVM for JDK:17.0.13","P-856V-Oracle GraalVM Enterprise Edition:20.3.16","P-856V-Oracle Java SE:23.0.1","P-856V-Oracle GraalVM for JDK:21.0.5","P-856V-Oracle GraalVM Enterprise Edition:21.3.12","P-856V-Oracle Java SE:17.0.13","P-856V-Oracle Java SE:21.0.5","P-856V-Oracle GraalVM for JDK:23.0.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-856V-Oracle Java SE:8u431-perf","P-856V-Oracle Java SE:11.0.25","P-856V-Oracle GraalVM for JDK:17.0.13","P-856V-Oracle GraalVM Enterprise Edition:20.3.16","P-856V-Oracle Java SE:23.0.1","P-856V-Oracle GraalVM for JDK:21.0.5","P-856V-Oracle GraalVM Enterprise Edition:21.3.12","P-856V-Oracle Java SE:17.0.13","P-856V-Oracle Java SE:21.0.5","P-856V-Oracle GraalVM for JDK:23.0.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066051.1"}],"scores":[{"cvss_v3":{"baseScore":4.8,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-856V-Oracle Java SE:8u431-perf","P-856V-Oracle Java SE:11.0.25","P-856V-Oracle GraalVM for JDK:17.0.13","P-856V-Oracle GraalVM Enterprise Edition:20.3.16","P-856V-Oracle Java SE:23.0.1","P-856V-Oracle GraalVM for JDK:21.0.5","P-856V-Oracle GraalVM Enterprise Edition:21.3.12","P-856V-Oracle Java SE:17.0.13","P-856V-Oracle Java SE:21.0.5","P-856V-Oracle GraalVM for JDK:23.0.1"]}]},{"cve":"CVE-2025-21503","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36452528"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"]}]},{"cve":"CVE-2025-21504","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36492114"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and  9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: Optimizer)V-9.0.1 and prior","P-8478(Server: Optimizer)V-8.4.2 and prior","P-8478(Server: Optimizer)V-8.0.39 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Optimizer)V-9.0.1 and prior","P-8478(Server: Optimizer)V-8.4.2 and prior","P-8478(Server: Optimizer)V-8.0.39 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(Server: Optimizer)V-9.0.1 and prior","P-8478(Server: Optimizer)V-8.4.2 and prior","P-8478(Server: Optimizer)V-8.0.39 and prior"]}]},{"cve":"CVE-2025-21505","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36559078"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: Components Services)V-8.4.3 and prior","P-8478(Server: Components Services)V-9.1.0 and prior","P-8478(Server: Components Services)V-8.0.40 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Components Services)V-8.4.3 and prior","P-8478(Server: Components Services)V-8.0.40 and prior","P-8478(Server: Components Services)V-9.1.0 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(Server: Components Services)V-8.4.3 and prior","P-8478(Server: Components Services)V-8.0.40 and prior","P-8478(Server: Components Services)V-9.1.0 and prior"]}]},{"cve":"CVE-2025-21506","ids":[{"system_name":"Oracle Bug ID of Oracle Project Foundation","text":"36561947"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Technology Foundation).  Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Foundation.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Project Foundation accessible data as well as  unauthorized access to critical data or complete access to all Oracle Project Foundation accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1293V-12.2.3-12.2.13"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1293V-12.2.3-12.2.13"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2484000.1"}],"scores":[{"cvss_v3":{"baseScore":8.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"products":["P-1293V-12.2.3-12.2.13"]}]},{"acknowledgments":[{"names":["Ahmed Shah"],"organization":"Malleum"},{"names":["Nadeem Douba"],"organization":"Malleum"}],"cve":"CVE-2025-21507","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36577406"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC).  Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.0"]}]},{"acknowledgments":[{"names":["Ahmed Shah"],"organization":"Malleum"},{"names":["Nadeem Douba"],"organization":"Malleum"}],"cve":"CVE-2025-21508","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36577411"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC).  Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.0"]}]},{"acknowledgments":[{"names":["Ahmed Shah"],"organization":"Malleum"},{"names":["Nadeem Douba"],"organization":"Malleum"}],"cve":"CVE-2025-21509","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36577412"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC).  Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.0"]}]},{"acknowledgments":[{"names":["Ahmed Shah"],"organization":"Malleum"},{"names":["Nadeem Douba"],"organization":"Malleum"}],"cve":"CVE-2025-21510","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36577413"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC).  Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.0"]}]},{"acknowledgments":[{"names":["Ahmed Shah"],"organization":"Malleum"},{"names":["Nadeem Douba"],"organization":"Malleum"}],"cve":"CVE-2025-21511","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36577414"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC).  Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.0"]}]},{"acknowledgments":[{"names":["Ahmed Shah"],"organization":"Malleum"},{"names":["Alex Warren"],"organization":"Softsource vBridge"},{"names":["Nadeem Douba"],"organization":"Malleum"}],"cve":"CVE-2025-21512","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36577422"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC).  Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":6.1,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.0"]}]},{"acknowledgments":[{"names":["Ahmed Shah"],"organization":"Malleum"},{"names":["Nadeem Douba"],"organization":"Malleum"}],"cve":"CVE-2025-21513","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36577428"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC).  Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":6.1,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.0"]}]},{"acknowledgments":[{"names":["Ahmed Shah"],"organization":"Malleum"},{"names":["Nadeem Douba"],"organization":"Malleum"}],"cve":"CVE-2025-21514","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36577432"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC).  Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.0"]}]},{"acknowledgments":[{"names":["Ahmed Shah"],"organization":"Malleum"},{"names":["Nadeem Douba"],"organization":"Malleum"}],"cve":"CVE-2025-21515","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36577436"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC).  Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.0"]}]},{"cve":"CVE-2025-21516","ids":[{"system_name":"Oracle Bug ID of Oracle Customer Care","text":"36580289"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Service Requests).  Supported versions that are affected are 12.2.5-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Care.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Customer Care accessible data as well as  unauthorized access to critical data or complete access to all Oracle Customer Care accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-105V-12.2.5-12.2.13"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-105V-12.2.5-12.2.13"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2484000.1"}],"scores":[{"cvss_v3":{"baseScore":8.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"products":["P-105V-12.2.5-12.2.13"]}]},{"cve":"CVE-2025-21517","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36586953"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC).  Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.0"]}]},{"acknowledgments":[{"names":["Jie Liang"],"organization":"WingTecher Lab"},{"names":["Jingzhou Fu"],"organization":"WingTecher Lab"},{"names":["Zhiyong Wu"],"organization":"WingTecher Lab"},{"names":["Zongrui Peng"],"organization":"WingTecher Lab"}],"cve":"CVE-2025-21518","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36593235"},{"system_name":"Oracle Bug ID of MySQL Cluster","text":"37387180"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.6.32 and prior, 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8479V-9.1.0 and prior","P-8478(Server: Optimizer)V-8.4.3 and prior","P-8479V-7.6.32 and prior","P-8479V-8.4.3 and prior","P-8478(Server: Optimizer)V-8.0.40 and prior","P-8478(Server: Optimizer)V-9.1.0 and prior","P-8479V-8.0.40 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8479V-9.1.0 and prior","P-8478(Server: Optimizer)V-8.4.3 and prior","P-8479V-7.6.32 and prior","P-8479V-8.4.3 and prior","P-8478(Server: Optimizer)V-8.0.40 and prior","P-8478(Server: Optimizer)V-9.1.0 and prior","P-8479V-8.0.40 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8479V-9.1.0 and prior","P-8478(Server: Optimizer)V-8.4.3 and prior","P-8479V-7.6.32 and prior","P-8479V-8.4.3 and prior","P-8478(Server: Optimizer)V-8.0.40 and prior","P-8478(Server: Optimizer)V-9.1.0 and prior","P-8479V-8.0.40 and prior"]}]},{"cve":"CVE-2025-21519","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36608160"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: Security: Privileges)V-8.4.3 and prior","P-8478(Server: Security: Privileges)V-9.1.0 and prior","P-8478(Server: Security: Privileges)V-8.0.40 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Security: Privileges)V-8.4.3 and prior","P-8478(Server: Security: Privileges)V-9.1.0 and prior","P-8478(Server: Security: Privileges)V-8.0.40 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(Server: Security: Privileges)V-8.4.3 and prior","P-8478(Server: Security: Privileges)V-9.1.0 and prior","P-8478(Server: Security: Privileges)V-8.0.40 and prior"]}]},{"cve":"CVE-2025-21520","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36615714"},{"system_name":"Oracle Bug ID of MySQL Cluster","text":"37387224"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 1.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.6.32 and prior, 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Cluster accessible data. CVSS 3.1 Base Score 1.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8479V-9.1.0 and prior","P-8478(Server: Options)V-8.4.3 and prior","P-8478(Server: Options)V-9.1.0 and prior","P-8479V-7.6.32 and prior","P-8479V-8.4.3 and prior","P-8479V-8.0.40 and prior","P-8478(Server: Options)V-8.0.40 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8479V-9.1.0 and prior","P-8478(Server: Options)V-8.4.3 and prior","P-8478(Server: Options)V-9.1.0 and prior","P-8479V-7.6.32 and prior","P-8479V-8.4.3 and prior","P-8479V-8.0.40 and prior","P-8478(Server: Options)V-8.0.40 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":1.8,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N","version":"3.1"},"products":["P-8479V-9.1.0 and prior","P-8478(Server: Options)V-8.4.3 and prior","P-8478(Server: Options)V-9.1.0 and prior","P-8479V-7.6.32 and prior","P-8479V-8.4.3 and prior","P-8479V-8.0.40 and prior","P-8478(Server: Options)V-8.0.40 and prior"]}]},{"cve":"CVE-2025-21521","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36625082"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling).  Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and  9.0.1 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: Thread Pooling)V-8.0.39 and prior","P-8478(Server: Thread Pooling)V-9.0.1 and prior","P-8478(Server: Thread Pooling)V-8.4.2 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Thread Pooling)V-9.0.1 and prior","P-8478(Server: Thread Pooling)V-8.4.2 and prior","P-8478(Server: Thread Pooling)V-8.0.39 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(Server: Thread Pooling)V-9.0.1 and prior","P-8478(Server: Thread Pooling)V-8.4.2 and prior","P-8478(Server: Thread Pooling)V-8.0.39 and prior"]}]},{"cve":"CVE-2025-21522","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36652610"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: Parser)V-8.0.40 and prior","P-8478(Server: Parser)V-9.1.0 and prior","P-8478(Server: Parser)V-8.4.3 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Parser)V-8.0.40 and prior","P-8478(Server: Parser)V-9.1.0 and prior","P-8478(Server: Parser)V-8.4.3 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(Server: Parser)V-8.0.40 and prior","P-8478(Server: Parser)V-9.1.0 and prior","P-8478(Server: Parser)V-8.4.3 and prior"]}]},{"cve":"CVE-2025-21523","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36658450"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"]}]},{"cve":"CVE-2025-21524","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36660738"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics SEC).  Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.0"]}]},{"cve":"CVE-2025-21525","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36677952"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL).  Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and  9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: DDL)V-8.0.39 and prior","P-8478(Server: DDL)V-9.0.1 and prior","P-8478(Server: DDL)V-8.4.2 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: DDL)V-9.0.1 and prior","P-8478(Server: DDL)V-8.0.39 and prior","P-8478(Server: DDL)V-8.4.2 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(Server: DDL)V-9.0.1 and prior","P-8478(Server: DDL)V-8.0.39 and prior","P-8478(Server: DDL)V-8.4.2 and prior"]}]},{"cve":"CVE-2025-21526","ids":[{"system_name":"Oracle Bug ID of Primavera P6 Enterprise Project Portfolio Management","text":"36725243"}],"notes":[{"category":"description","text":"Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access).  Supported versions that are affected are 20.12.1.0-20.12.21.5, 21.12.1.0-21.12.20.0, 22.12.1.0-22.12.16.0 and  23.12.1.0-23.12.10.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5579V-20.12.1.0-20.12.21.5","P-5579V-22.12.1.0-22.12.16.0","P-5579V-21.12.1.0-21.12.20.0","P-5579V-23.12.1.0-23.12.10.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5579V-21.12.1.0-21.12.20.0","P-5579V-23.12.1.0-23.12.10.0","P-5579V-20.12.1.0-20.12.21.5","P-5579V-22.12.1.0-22.12.16.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065975.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-5579V-21.12.1.0-21.12.20.0","P-5579V-23.12.1.0-23.12.10.0","P-5579V-20.12.1.0-20.12.21.5","P-5579V-22.12.1.0-22.12.16.0"]}]},{"acknowledgments":[{"names":["Ahmed Shah"],"organization":"Malleum"},{"names":["Nadeem Douba"],"organization":"Malleum"}],"cve":"CVE-2025-21527","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36747071"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Design Tools SEC).  Supported versions that are affected are Prior to 9.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781V-Prior to 9.2.9.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781V-Prior to 9.2.9.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":6.1,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-4781V-Prior to 9.2.9.0"]}]},{"cve":"CVE-2025-21528","ids":[{"system_name":"Oracle Bug ID of Primavera P6 Enterprise Project Portfolio Management","text":"36767774"}],"notes":[{"category":"description","text":"Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access).  Supported versions that are affected are 20.12.1.0-20.12.21.5, 21.12.1.0-21.12.20.0, 22.12.1.0-22.12.16.0 and  23.12.1.0-23.12.10.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5579V-20.12.1.0-20.12.21.5","P-5579V-22.12.1.0-22.12.16.0","P-5579V-21.12.1.0-21.12.20.0","P-5579V-23.12.1.0-23.12.10.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5579V-21.12.1.0-21.12.20.0","P-5579V-23.12.1.0-23.12.10.0","P-5579V-20.12.1.0-20.12.21.5","P-5579V-22.12.1.0-22.12.16.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065975.1"}],"scores":[{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","version":"3.1"},"products":["P-5579V-21.12.1.0-21.12.20.0","P-5579V-23.12.1.0-23.12.10.0","P-5579V-20.12.1.0-20.12.21.5","P-5579V-22.12.1.0-22.12.16.0"]}]},{"cve":"CVE-2025-21529","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36778475"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: Information Schema)V-8.4.3 and prior","P-8478(Server: Information Schema)V-8.0.40 and prior","P-8478(Server: Information Schema)V-9.1.0 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Information Schema)V-8.4.3 and prior","P-8478(Server: Information Schema)V-8.0.40 and prior","P-8478(Server: Information Schema)V-9.1.0 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(Server: Information Schema)V-8.4.3 and prior","P-8478(Server: Information Schema)V-8.0.40 and prior","P-8478(Server: Information Schema)V-9.1.0 and prior"]}]},{"cve":"CVE-2025-21530","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"36790586"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"products":["P-5085V-8.61","P-5085V-8.60"]}]},{"cve":"CVE-2025-21531","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36879147"},{"system_name":"Oracle Bug ID of MySQL Cluster","text":"37387232"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.6.32 and prior, 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8479V-9.1.0 and prior","P-8478(InnoDB)V-8.0.40 and prior","P-8479V-7.6.32 and prior","P-8479V-8.4.3 and prior","P-8479V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8479V-9.1.0 and prior","P-8478(InnoDB)V-8.0.40 and prior","P-8479V-7.6.32 and prior","P-8479V-8.4.3 and prior","P-8479V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8479V-9.1.0 and prior","P-8478(InnoDB)V-8.0.40 and prior","P-8479V-7.6.32 and prior","P-8479V-8.4.3 and prior","P-8479V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"]}]},{"acknowledgments":[{"names":["Arjun Giri"],"organization":"Green Tick Nepal Pvt. Ltd."}],"cve":"CVE-2025-21532","ids":[{"system_name":"Oracle Bug ID of Oracle Analytics Desktop","text":"36883339"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Analytics Desktop product of Oracle Analytics (component: Install).  Supported versions that are affected are Prior to 8.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Analytics Desktop executes to compromise Oracle Analytics Desktop.  Successful attacks of this vulnerability can result in takeover of Oracle Analytics Desktop. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-12791V-Prior to 8.1.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-12791V-Prior to 8.1.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064266.2"}],"scores":[{"cvss_v3":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-12791V-Prior to 8.1.0"]}]},{"acknowledgments":[{"names":["Kandi Abhishek Reddy"]}],"cve":"CVE-2025-21533","ids":[{"system_name":"Oracle Bug ID of Oracle VM VirtualBox","text":"36888499"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are Prior to 7.0.24 and  prior to 7.1.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8370V-Prior to 7.0.24","P-8370V-prior to 7.1.6"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8370V-Prior to 7.0.24","P-8370V-prior to 7.1.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066582.1"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-8370V-Prior to 7.0.24","P-8370V-prior to 7.1.6"]}]},{"cve":"CVE-2025-21534","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36891888"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Performance Schema).  Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and  9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: Performance Schema)V-8.0.39 and prior","P-8478(Server: Performance Schema)V-8.4.2 and prior","P-8478(Server: Performance Schema)V-9.0.1 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Performance Schema)V-8.4.2 and prior","P-8478(Server: Performance Schema)V-9.0.1 and prior","P-8478(Server: Performance Schema)V-8.0.39 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(Server: Performance Schema)V-8.4.2 and prior","P-8478(Server: Performance Schema)V-9.0.1 and prior","P-8478(Server: Performance Schema)V-8.0.39 and prior"]}]},{"cve":"CVE-2025-21535","ids":[{"system_name":"Oracle Bug ID of Oracle WebLogic Server","text":"36942372"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.4.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.4.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-5242V-14.1.1.0.0","P-5242V-12.2.1.4.0"]}]},{"cve":"CVE-2025-21536","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"36980896"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and  9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: Optimizer)V-9.0.1 and prior","P-8478(Server: Optimizer)V-8.4.2 and prior","P-8478(Server: Optimizer)V-8.0.39 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Optimizer)V-9.0.1 and prior","P-8478(Server: Optimizer)V-8.4.2 and prior","P-8478(Server: Optimizer)V-8.0.39 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(Server: Optimizer)V-9.0.1 and prior","P-8478(Server: Optimizer)V-8.4.2 and prior","P-8478(Server: Optimizer)V-8.0.39 and prior"]}]},{"cve":"CVE-2025-21537","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise FIN Cash Management","text":"37031970"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Oracle PeopleSoft (component: Cash Management).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Cash Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Cash Management accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise FIN Cash Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4979V-9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4979V-9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-4979V-9.2"]}]},{"cve":"CVE-2025-21538","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36817487"},{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Tools","text":"36817492"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC).  Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC).  Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4781(Web Runtime SEC)V-Prior to 9.2.9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4781(Web Runtime SEC)V-Prior to 9.2.9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":6.1,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-4781(Web Runtime SEC)V-Prior to 9.2.9.2"]}]},{"cve":"CVE-2025-21539","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise FIN eSettlements","text":"37035121"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN eSettlements.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN eSettlements accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise FIN eSettlements accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4987V-9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4987V-9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-4987V-9.2"]}]},{"cve":"CVE-2025-21540","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"37041439"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data as well as  unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: Security: Privileges)V-8.4.3 and prior","P-8478(Server: Security: Privileges)V-9.1.0 and prior","P-8478(Server: Security: Privileges)V-8.0.40 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Security: Privileges)V-8.4.3 and prior","P-8478(Server: Security: Privileges)V-9.1.0 and prior","P-8478(Server: Security: Privileges)V-8.0.40 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-8478(Server: Security: Privileges)V-8.4.3 and prior","P-8478(Server: Security: Privileges)V-9.1.0 and prior","P-8478(Server: Security: Privileges)V-8.0.40 and prior"]}]},{"cve":"CVE-2025-21541","ids":[{"system_name":"Oracle Bug ID of Oracle Workflow","text":"37044489"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI).  Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Workflow accessible data as well as  unauthorized read access to a subset of Oracle Workflow accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-174V-12.2.3-12.2.14"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-174V-12.2.3-12.2.14"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2484000.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-174V-12.2.3-12.2.14"]}]},{"cve":"CVE-2025-21542","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Order and Service Management","text":"37182637"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security).  Supported versions that are affected are 7.4.0, 7.4.1 and  7.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Order and Service Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Order and Service Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Order and Service Management. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2270V-7.4.0","P-2270V-7.4.1","P-2270V-7.5.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2270V-7.4.0","P-2270V-7.4.1","P-2270V-7.5.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064005.1"}],"scores":[{"cvss_v3":{"baseScore":6.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"products":["P-2270V-7.4.0","P-2270V-7.4.1","P-2270V-7.5.0"]}]},{"cve":"CVE-2025-21543","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"37063288"},{"system_name":"Oracle Bug ID of MySQL Cluster","text":"37387034"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"},{"category":"description","text":"Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: Packaging).  Supported versions that are affected are 7.6.32 and prior, 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8479V-9.1.0 and prior","P-8478(Server: Packaging)V-8.0.40 and prior","P-8479V-7.6.32 and prior","P-8479V-8.4.3 and prior","P-8478(Server: Packaging)V-9.1.0 and prior","P-8478(Server: Packaging)V-8.4.3 and prior","P-8479V-8.0.40 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8479V-9.1.0 and prior","P-8478(Server: Packaging)V-8.0.40 and prior","P-8479V-7.6.32 and prior","P-8479V-8.4.3 and prior","P-8478(Server: Packaging)V-9.1.0 and prior","P-8478(Server: Packaging)V-8.4.3 and prior","P-8479V-8.0.40 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8479V-9.1.0 and prior","P-8478(Server: Packaging)V-8.0.40 and prior","P-8479V-7.6.32 and prior","P-8479V-8.4.3 and prior","P-8478(Server: Packaging)V-9.1.0 and prior","P-8478(Server: Packaging)V-8.4.3 and prior","P-8479V-8.0.40 and prior"]}]},{"cve":"CVE-2025-21544","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Order and Service Management","text":"37076378"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security).  Supported versions that are affected are 7.4.0, 7.4.1 and  7.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Order and Service Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Order and Service Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Order and Service Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2270V-7.4.0","P-2270V-7.4.1","P-2270V-7.5.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2270V-7.4.0","P-2270V-7.4.1","P-2270V-7.5.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064005.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-2270V-7.4.0","P-2270V-7.4.1","P-2270V-7.5.0"]}]},{"cve":"CVE-2025-21545","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise PeopleTools","text":"37091208"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5085V-8.61","P-5085V-8.60"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5085V-8.61","P-5085V-8.60"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-5085V-8.61","P-5085V-8.60"]}]},{"acknowledgments":[{"names":["Niels te Grotenhuis"]}],"cve":"CVE-2025-21546","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"37132323"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data as well as  unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: Security: Privileges)V-8.4.3 and prior","P-8478(Server: Security: Privileges)V-9.1.0 and prior","P-8478(Server: Security: Privileges)V-8.0.40 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Security: Privileges)V-8.4.3 and prior","P-8478(Server: Security: Privileges)V-9.1.0 and prior","P-8478(Server: Security: Privileges)V-8.0.40 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":3.8,"baseSeverity":"LOW","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-8478(Server: Security: Privileges)V-8.4.3 and prior","P-8478(Server: Security: Privileges)V-9.1.0 and prior","P-8478(Server: Security: Privileges)V-8.0.40 and prior"]}]},{"acknowledgments":[{"names":["Sonny"],"organization":"watchTowr"}],"cve":"CVE-2025-21547","ids":[{"system_name":"Oracle Bug ID of Oracle Hospitality OPERA 5","text":"37144652"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet).  Supported versions that are affected are 5.6.19.20, 5.6.25.8, 5.6.26.6 and  5.6.27.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hospitality OPERA 5 accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality OPERA 5. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-11580V-5.6.27.1","P-11580V-5.6.26.6","P-11580V-5.6.25.8","P-11580V-5.6.19.20"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11580V-5.6.27.1","P-11580V-5.6.26.6","P-11580V-5.6.25.8","P-11580V-5.6.19.20"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065083.1"}],"scores":[{"cvss_v3":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","version":"3.1"},"products":["P-11580V-5.6.27.1","P-11580V-5.6.26.6","P-11580V-5.6.25.8","P-11580V-5.6.19.20"]}]},{"acknowledgments":[{"names":["Jakub Barton"]},{"names":["Weibin Shi"]}],"cve":"CVE-2025-21548","ids":[{"system_name":"Oracle Bug ID of MySQL Connectors","text":"37145655"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python).  Supported versions that are affected are 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as  unauthorized read access to a subset of MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8576(Connector/Python)V-9.1.0 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8576(Connector/Python)V-9.1.0 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":6.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:H/A:H","version":"3.1"},"products":["P-8576(Connector/Python)V-9.1.0 and prior"]}]},{"cve":"CVE-2025-21549","ids":[{"system_name":"Oracle Bug ID of Oracle WebLogic Server","text":"36369988"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).   The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5242V-14.1.1.0.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5242V-14.1.1.0.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064245.2"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-5242V-14.1.1.0.0"]}]},{"acknowledgments":[{"names":["Long Lagon"]}],"cve":"CVE-2025-21550","ids":[{"system_name":"Oracle Bug ID of Oracle Financial Services Behavior Detection Platform","text":"37170901"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Web UI).  Supported versions that are affected are 8.0.8.1, 8.1.2.7 and  8.1.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Behavior Detection Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Behavior Detection Platform accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Behavior Detection Platform accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-9190V-8.1.2.7","P-9190V-8.0.8.1","P-9190V-8.1.2.8"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-9190V-8.1.2.7","P-9190V-8.0.8.1","P-9190V-8.1.2.8"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066717.1"}],"scores":[{"cvss_v3":{"baseScore":6.1,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-9190V-8.1.2.7","P-9190V-8.0.8.1","P-9190V-8.1.2.8"]}]},{"cve":"CVE-2025-21551","ids":[{"system_name":"Oracle Bug ID of Oracle Solaris","text":"37172843"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Solaris product of Oracle Systems (component: File system).   The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Solaris accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 6.0 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-10006V-11"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-10006V-11"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066080.1"}],"scores":[{"cvss_v3":{"baseScore":6.0,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H","version":"3.1"},"products":["P-10006V-11"]}]},{"cve":"CVE-2025-21552","ids":[{"system_name":"Oracle Bug ID of JD Edwards EnterpriseOne Orchestrator","text":"37154900"}],"notes":[{"category":"description","text":"Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security).  Supported versions that are affected are Prior to 9.2.9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Orchestrator accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-11681V-Prior to 9.2.9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-11681V-Prior to 9.2.9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065160.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-11681V-Prior to 9.2.9.2"]}]},{"cve":"CVE-2025-21553","ids":[{"system_name":"Oracle Bug ID of Oracle Database Server","text":"37222265"}],"notes":[{"category":"description","text":"Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.25, 21.3-21.16 and  23.4-23.6. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Java VM accessible data as well as  unauthorized read access to a subset of Java VM accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5(Java VM)V-23.4-23.6","P-5(Java VM)V-21.3-21.16","P-5(Java VM)V-19.3-19.25"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5(Java VM)V-21.3-21.16","P-5(Java VM)V-19.3-19.25","P-5(Java VM)V-23.4-23.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":4.2,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-5(Java VM)V-21.3-21.16","P-5(Java VM)V-19.3-19.25","P-5(Java VM)V-23.4-23.6"]}]},{"cve":"CVE-2025-21554","ids":[{"system_name":"Oracle Bug ID of Oracle Communications Order and Service Management","text":"37182672"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security).  Supported versions that are affected are 7.4.0, 7.4.1 and  7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Order and Service Management accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-2270V-7.4.0","P-2270V-7.4.1","P-2270V-7.5.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-2270V-7.4.0","P-2270V-7.4.1","P-2270V-7.5.0"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3064005.1"}],"scores":[{"cvss_v3":{"baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"products":["P-2270V-7.4.0","P-2270V-7.4.1","P-2270V-7.5.0"]}]},{"cve":"CVE-2025-21555","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"37189985"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"products":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"]}]},{"acknowledgments":[{"names":["Joel Snape"],"organization":"CrowdStrike"},{"names":["Lutz Wolf"],"organization":"CrowdStrike"}],"cve":"CVE-2025-21556","ids":[{"system_name":"Oracle Bug ID of Oracle Agile PLM Framework","text":"37224110"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework.  While the vulnerability is in Oracle Agile PLM Framework, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM Framework. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4461V-9.3.6"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4461V-9.3.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065151.1"}],"scores":[{"cvss_v3":{"baseScore":9.9,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"products":["P-4461V-9.3.6"]}]},{"acknowledgments":[{"names":["Milad Seddigh"]}],"cve":"CVE-2025-21557","ids":[{"system_name":"Oracle Bug ID of Oracle Application Express","text":"37239579"}],"notes":[{"category":"description","text":"Vulnerability in Oracle Application Express (component: General).  Supported versions that are affected are 23.2 and  24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Express.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as  unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-1348V-23.2","P-1348V-24.1"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-1348V-23.2","P-1348V-24.1"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3056559.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-1348V-23.2","P-1348V-24.1"]}]},{"acknowledgments":[{"names":["Robert Ingruber"],"organization":"Siemens Energy"},{"names":["Thomas Riedmaier"],"organization":"Siemens Energy"}],"cve":"CVE-2025-21558","ids":[{"system_name":"Oracle Bug ID of Primavera P6 Enterprise Project Portfolio Management","text":"37260144"}],"notes":[{"category":"description","text":"Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access).  Supported versions that are affected are 20.12.1.0-20.12.21.5, 21.12.1.0-21.12.20.0 and  22.12.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5579V-22.12.1.0","P-5579V-20.12.1.0-20.12.21.5","P-5579V-21.12.1.0-21.12.20.0"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5579V-22.12.1.0","P-5579V-21.12.1.0-21.12.20.0","P-5579V-20.12.1.0-20.12.21.5"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065975.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-5579V-22.12.1.0","P-5579V-21.12.1.0-21.12.20.0","P-5579V-20.12.1.0-20.12.21.5"]}]},{"cve":"CVE-2025-21559","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"37271715"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and  9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":5.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H","version":"3.1"},"products":["P-8478(InnoDB)V-8.0.40 and prior","P-8478(InnoDB)V-9.1.0 and prior","P-8478(InnoDB)V-8.4.3 and prior"]}]},{"cve":"CVE-2025-21560","ids":[{"system_name":"Oracle Bug ID of Oracle Agile PLM Framework","text":"37274814"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: SDK-Software Development Kit).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4461V-9.3.6"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4461V-9.3.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065151.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-4461V-9.3.6"]}]},{"cve":"CVE-2025-21561","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise SCM Purchasing","text":"37278068"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise SCM Purchasing accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise SCM Purchasing accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5133V-9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5133V-9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":5.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"products":["P-5133V-9.2"]}]},{"cve":"CVE-2025-21562","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise CC Common Application Objects","text":"37287822"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Run Control Management).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise CC Common Application Objects accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8911V-9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8911V-9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"products":["P-8911V-9.2"]}]},{"cve":"CVE-2025-21563","ids":[{"system_name":"Oracle Bug ID of PeopleSoft Enterprise CC Common Application Objects","text":"37287848"}],"notes":[{"category":"description","text":"Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Run Control Management).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise CC Common Application Objects accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8911V-9.2"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8911V-9.2"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065149.1"}],"scores":[{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"products":["P-8911V-9.2"]}]},{"cve":"CVE-2025-21564","ids":[{"system_name":"Oracle Bug ID of Oracle Agile PLM Framework","text":"37289995"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM Framework. CVSS 3.1 Base Score 8.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4461V-9.3.6"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4461V-9.3.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065151.1"}],"scores":[{"cvss_v3":{"baseScore":8.1,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","version":"3.1"},"products":["P-4461V-9.3.6"]}]},{"cve":"CVE-2025-21565","ids":[{"system_name":"Oracle Bug ID of Oracle Agile PLM Framework","text":"37297319"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Install).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4461V-9.3.6"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4461V-9.3.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065151.1"}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-4461V-9.3.6"]}]},{"cve":"CVE-2025-21566","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"37341055"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: Optimizer)V-9.1.0 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Optimizer)V-9.1.0 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["P-8478(Server: Optimizer)V-9.1.0 and prior"]}]},{"cve":"CVE-2025-21567","ids":[{"system_name":"Oracle Bug ID of MySQL Server","text":"37355755"}],"notes":[{"category":"description","text":"Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges).  Supported versions that are affected are 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8478(Server: Security: Privileges)V-9.1.0 and prior"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8478(Server: Security: Privileges)V-9.1.0 and prior"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065094.1"}],"scores":[{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"products":["P-8478(Server: Security: Privileges)V-9.1.0 and prior"]}]},{"acknowledgments":[{"names":["Dawid Jonienc"]}],"cve":"CVE-2025-21568","ids":[{"system_name":"Oracle Bug ID of Oracle Hyperion Data Relationship Management","text":"37118885"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and Security).   The supported version that is affected is 11.2.19.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 4.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4375V-11.2.19.0.000"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4375V-11.2.19.0.000"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2775466.2"}],"scores":[{"cvss_v3":{"baseScore":4.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N","version":"3.1"},"products":["P-4375V-11.2.19.0.000"]}]},{"cve":"CVE-2025-21569","ids":[{"system_name":"Oracle Bug ID of Oracle Hyperion Data Relationship Management","text":"37185428"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Web Services).   The supported version that is affected is 11.2.19.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-4375V-11.2.19.0.000"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-4375V-11.2.19.0.000"],"url":"https://support.oracle.com/rs?type=doc&amp;id=2775466.2"}],"scores":[{"cvss_v3":{"baseScore":6.6,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["P-4375V-11.2.19.0.000"]}]},{"acknowledgments":[{"names":["Marco Nappi"]}],"cve":"CVE-2025-21570","ids":[{"system_name":"Oracle Bug ID of Oracle Life Sciences Argus Safety","text":"37265438"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle Life Sciences Argus Safety product of Oracle Health Sciences Applications (component: Login).   The supported version that is affected is 8.2.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences Argus Safety.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Life Sciences Argus Safety, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Life Sciences Argus Safety accessible data as well as  unauthorized read access to a subset of Oracle Life Sciences Argus Safety accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-5710V-8.2.3"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-5710V-8.2.3"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3065955.1"}],"scores":[{"cvss_v3":{"baseScore":6.1,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["P-5710V-8.2.3"]}]},{"acknowledgments":[{"names":["Yuhao Jiang"]}],"cve":"CVE-2025-21571","ids":[{"system_name":"Oracle Bug ID of Oracle VM VirtualBox","text":"37454234"}],"notes":[{"category":"description","text":"Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are Prior to 7.0.24 and  prior to 7.1.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data as well as  unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L).","title":"Vulnerability Description"}],"product_status":{"known_affected":["P-8370V-Prior to 7.0.24","P-8370V-prior to 7.1.6"]},"remediations":[{"category":"vendor_fix","details":"Oracle customers with valid support contracts","product_ids":["P-8370V-Prior to 7.0.24","P-8370V-prior to 7.1.6"],"url":"https://support.oracle.com/rs?type=doc&amp;id=3066582.1"}],"scores":[{"cvss_v3":{"baseScore":7.3,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:L","version":"3.1"},"products":["P-8370V-Prior to 7.0.24","P-8370V-prior to 7.1.6"]}]}]}