{
  "document": {
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Oracle. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp"
      }
    },
    "lang": "en",
    "publisher": {
      "category": "vendor",
      "name": "Oracle",
      "namespace": "https://www.oracle.com"
    },
    "references": [
      {
        "summary": "URL to html version of Advisory",
        "url": "https://www.oracle.com/security-alerts/cpujan2026.html"
      },
      {
        "category": "self",
        "summary": "URL to CSAF version of Advisory",
        "url": "https://www.oracle.com/docs/tech/security-alerts/cpujan2026csaf.json"
      }
    ],
    "title": "Oracle Critical Patch Update Advisory - January 2026 - Oracle CSAF",
    "tracking": {
      "current_release_date": "2026-01-20T13:00:00-07:00",
      "id": "CPUJan2026csaf",
      "initial_release_date": "2026-01-20T13:00:00-07:00",
      "revision_history": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "number": "1",
          "summary": "Initial Release"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle APEX Sample Applications Version 23.2.0",
                    "product": {
                      "name": "Oracle APEX Sample Applications Version 23.2.0",
                      "product_id": "P-1348V-23.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:apex_sample_applications:23.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle APEX Sample Applications Version 23.2.1",
                    "product": {
                      "name": "Oracle APEX Sample Applications Version 23.2.1",
                      "product_id": "P-1348V-23.2.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:apex_sample_applications:23.2.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle APEX Sample Applications Version 24.1.0",
                    "product": {
                      "name": "Oracle APEX Sample Applications Version 24.1.0",
                      "product_id": "P-1348V-24.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:apex_sample_applications:24.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle APEX Sample Applications Version 24.2.0",
                    "product": {
                      "name": "Oracle APEX Sample Applications Version 24.2.0",
                      "product_id": "P-1348V-24.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:apex_sample_applications:24.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle APEX Sample Applications Version 24.2.1",
                    "product": {
                      "name": "Oracle APEX Sample Applications Version 24.2.1",
                      "product_id": "P-1348V-24.2.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:apex_sample_applications:24.2.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle APEX Sample Applications"
              }
            ],
            "category": "product_family",
            "name": "Oracle APEX"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle BI Publisher Version 7.6.0.0.0",
                    "product": {
                      "name": "Oracle BI Publisher Version 7.6.0.0.0",
                      "product_id": "P-1479V-7.6.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:bi_publisher:7.6.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle BI Publisher Version 8.2.0.0.0",
                    "product": {
                      "name": "Oracle BI Publisher Version 8.2.0.0.0",
                      "product_id": "P-1479V-8.2.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle BI Publisher"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Business Intelligence Enterprise Edition Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Business Intelligence Enterprise Edition Version 12.2.1.4.0",
                      "product_id": "P-2025V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Business Intelligence Enterprise Edition Version 7.6.0.0.0",
                    "product": {
                      "name": "Oracle Business Intelligence Enterprise Edition Version 7.6.0.0.0",
                      "product_id": "P-2025V-7.6.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:business_intelligence:7.6.0.0.0:*:*:*:enterprise:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Business Intelligence Enterprise Edition Version 8.2.0.0.0",
                    "product": {
                      "name": "Oracle Business Intelligence Enterprise Edition Version 8.2.0.0.0",
                      "product_id": "P-2025V-8.2.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Business Intelligence Enterprise Edition"
              }
            ],
            "category": "product_family",
            "name": "Oracle Analytics"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Commerce Guided Search(Content Acquisition System, Workbench, Endeca Application Controller) Version 11.4.0",
                    "product": {
                      "name": "Oracle Commerce Guided Search(Content Acquisition System, Workbench, Endeca Application Controller) Version 11.4.0",
                      "product_id": "P-9633(Content Acquisition System, Workbench, Endeca Application Controller)V-11.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Commerce Guided Search(MDEX, Forge) Version 11.4.0",
                    "product": {
                      "name": "Oracle Commerce Guided Search(MDEX, Forge) Version 11.4.0",
                      "product_id": "P-9633(MDEX, Forge)V-11.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Commerce Guided Search(Workbench) Version 11.4.0",
                    "product": {
                      "name": "Oracle Commerce Guided Search(Workbench) Version 11.4.0",
                      "product_id": "P-9633(Workbench)V-11.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Commerce Guided Search"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Commerce Platform Version 11.4.0",
                    "product": {
                      "name": "Oracle Commerce Platform Version 11.4.0",
                      "product_id": "P-9348V-11.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:commerce_platform:11.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Commerce Platform"
              }
            ],
            "category": "product_family",
            "name": "Oracle Commerce"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Cloud Native Session Border Controller Version 25.1.0",
                    "product": {
                      "name": "Oracle Cloud Native Session Border Controller Version 25.1.0",
                      "product_id": "P-14762V-25.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:cloud_native_session_border_controller:25.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Cloud Native Session Border Controller"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications ASAP Version 7.4.0",
                    "product": {
                      "name": "Oracle Communications ASAP Version 7.4.0",
                      "product_id": "P-2260V-7.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_asap:7.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications ASAP Version 7.4.1",
                    "product": {
                      "name": "Oracle Communications ASAP Version 7.4.1",
                      "product_id": "P-2260V-7.4.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_asap:7.4.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications ASAP"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.0.0.0",
                    "product": {
                      "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.0.0.0",
                      "product_id": "P-9742V-15.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.0.1.0",
                    "product": {
                      "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.0.1.0",
                      "product_id": "P-9742V-15.0.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.0.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.1.0.0",
                    "product": {
                      "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.1.0.0",
                      "product_id": "P-9742V-15.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications BRM - Elastic Charging Engine"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Billing and Revenue Management(Platform) Version 15.0.0.0.0",
                    "product": {
                      "name": "Oracle Communications Billing and Revenue Management(Platform) Version 15.0.0.0.0",
                      "product_id": "P-2136(Platform)V-15.0.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.0.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Billing and Revenue Management(Platform) Version 15.0.1.0.0",
                    "product": {
                      "name": "Oracle Communications Billing and Revenue Management(Platform) Version 15.0.1.0.0",
                      "product_id": "P-2136(Platform)V-15.0.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.0.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Billing and Revenue Management(Platform) Version 15.1.0.0.0",
                    "product": {
                      "name": "Oracle Communications Billing and Revenue Management(Platform) Version 15.1.0.0.0",
                      "product_id": "P-2136(Platform)V-15.1.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.1.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Billing and Revenue Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Diameter Signaling Router Version 9.0.0",
                    "product": {
                      "name": "Oracle Communications Diameter Signaling Router Version 9.0.0",
                      "product_id": "P-10899V-9.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:9.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Diameter Signaling Router Version 9.0.1",
                    "product": {
                      "name": "Oracle Communications Diameter Signaling Router Version 9.0.1",
                      "product_id": "P-10899V-9.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:9.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Diameter Signaling Router Version 9.1.0",
                    "product": {
                      "name": "Oracle Communications Diameter Signaling Router Version 9.1.0",
                      "product_id": "P-10899V-9.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_diameter_signaling_router:9.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Diameter Signaling Router"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Element Manager Version 9.0.0-9.0.4",
                    "product": {
                      "name": "Oracle Communications Element Manager Version 9.0.0-9.0.4",
                      "product_id": "P-11052V-9.0.0-9.0.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_element_manager:9.0.0-9.0.4:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Element Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications IP Service Activator Version 7.5.0",
                    "product": {
                      "name": "Oracle Communications IP Service Activator Version 7.5.0",
                      "product_id": "P-2261V-7.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_ip_service_activator:7.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications IP Service Activator"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Network Analytics Data Director Version 24.2.0-24.2.1",
                    "product": {
                      "name": "Oracle Communications Network Analytics Data Director Version 24.2.0-24.2.1",
                      "product_id": "P-14547V-24.2.0-24.2.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:24.2.0-24.2.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Analytics Data Director Version 24.3.0",
                    "product": {
                      "name": "Oracle Communications Network Analytics Data Director Version 24.3.0",
                      "product_id": "P-14547V-24.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:24.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Analytics Data Director Version 25.1.100",
                    "product": {
                      "name": "Oracle Communications Network Analytics Data Director Version 25.1.100",
                      "product_id": "P-14547V-25.1.100",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:25.1.100:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Analytics Data Director Version 25.1.200",
                    "product": {
                      "name": "Oracle Communications Network Analytics Data Director Version 25.1.200",
                      "product_id": "P-14547V-25.1.200",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:25.1.200:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Analytics Data Director Version 25.2.100",
                    "product": {
                      "name": "Oracle Communications Network Analytics Data Director Version 25.2.100",
                      "product_id": "P-14547V-25.2.100",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:25.2.100:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Network Analytics Data Director"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Integrity Version 7.3.6",
                    "product": {
                      "name": "Oracle Communications Network Integrity Version 7.3.6",
                      "product_id": "P-4491V-7.3.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Integrity Version 7.4.0",
                    "product": {
                      "name": "Oracle Communications Network Integrity Version 7.4.0",
                      "product_id": "P-4491V-7.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_integrity:7.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Integrity Version 7.5.0",
                    "product": {
                      "name": "Oracle Communications Network Integrity Version 7.5.0",
                      "product_id": "P-4491V-7.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_integrity:7.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Integrity Version 8.0.0",
                    "product": {
                      "name": "Oracle Communications Network Integrity Version 8.0.0",
                      "product_id": "P-4491V-8.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_integrity:8.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Network Integrity"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Operations Monitor Version 5.2",
                    "product": {
                      "name": "Oracle Communications Operations Monitor Version 5.2",
                      "product_id": "P-10761V-5.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_operations_monitor:5.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Operations Monitor Version 6.0",
                    "product": {
                      "name": "Oracle Communications Operations Monitor Version 6.0",
                      "product_id": "P-10761V-6.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_operations_monitor:6.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Operations Monitor Version 6.1",
                    "product": {
                      "name": "Oracle Communications Operations Monitor Version 6.1",
                      "product_id": "P-10761V-6.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_operations_monitor:6.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Operations Monitor"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Order and Service Management Version 7.5.0",
                    "product": {
                      "name": "Oracle Communications Order and Service Management Version 7.5.0",
                      "product_id": "P-2270V-7.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_order_and_service_management:7.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Order and Service Management Version 8.0.0",
                    "product": {
                      "name": "Oracle Communications Order and Service Management Version 8.0.0",
                      "product_id": "P-2270V-8.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_order_and_service_management:8.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Order and Service Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Policy Management Version 15.0.0.0",
                    "product": {
                      "name": "Oracle Communications Policy Management Version 15.0.0.0",
                      "product_id": "P-10900V-15.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_policy_management:15.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Policy Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Pricing Design Center Version 15.0.0.0.0",
                    "product": {
                      "name": "Oracle Communications Pricing Design Center Version 15.0.0.0.0",
                      "product_id": "P-9437V-15.0.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_pricing_design_center:15.0.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Pricing Design Center Version 15.0.1.0.0",
                    "product": {
                      "name": "Oracle Communications Pricing Design Center Version 15.0.1.0.0",
                      "product_id": "P-9437V-15.0.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_pricing_design_center:15.0.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Pricing Design Center Version 15.1.0.0.0",
                    "product": {
                      "name": "Oracle Communications Pricing Design Center Version 15.1.0.0.0",
                      "product_id": "P-9437V-15.1.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_pricing_design_center:15.1.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Pricing Design Center"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Session Border Controller Version 10.0.0",
                    "product": {
                      "name": "Oracle Communications Session Border Controller Version 10.0.0",
                      "product_id": "P-10750V-10.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_session_border_controller:10.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Session Border Controller Version 9.3.0",
                    "product": {
                      "name": "Oracle Communications Session Border Controller Version 9.3.0",
                      "product_id": "P-10750V-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_session_border_controller:9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Session Border Controller"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Session Report Manager Version 9.0.0-9.0.4",
                    "product": {
                      "name": "Oracle Communications Session Report Manager Version 9.0.0-9.0.4",
                      "product_id": "P-10770V-9.0.0-9.0.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_session_report_manager:9.0.0-9.0.4:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Session Report Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Unified Assurance Version 6.1.0-6.1.1",
                    "product": {
                      "name": "Oracle Communications Unified Assurance Version 6.1.0-6.1.1",
                      "product_id": "P-14597V-6.1.0-6.1.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_unified_assurance:6.1.0-6.1.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Unified Assurance"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Unified Inventory Management Version 7.7.0",
                    "product": {
                      "name": "Oracle Communications Unified Inventory Management Version 7.7.0",
                      "product_id": "P-4516V-7.7.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.7.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Unified Inventory Management Version 7.8.0",
                    "product": {
                      "name": "Oracle Communications Unified Inventory Management Version 7.8.0",
                      "product_id": "P-4516V-7.8.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.8.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Unified Inventory Management Version 8.0.0",
                    "product": {
                      "name": "Oracle Communications Unified Inventory Management Version 8.0.0",
                      "product_id": "P-4516V-8.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:8.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Unified Inventory Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Communications Broker Version 4.1.0",
                    "product": {
                      "name": "Oracle Enterprise Communications Broker Version 4.1.0",
                      "product_id": "P-10758V-4.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_communications_broker:4.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Communications Broker Version 4.2.0",
                    "product": {
                      "name": "Oracle Enterprise Communications Broker Version 4.2.0",
                      "product_id": "P-10758V-4.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_communications_broker:4.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Communications Broker Version 5.0.0",
                    "product": {
                      "name": "Oracle Enterprise Communications Broker Version 5.0.0",
                      "product_id": "P-10758V-5.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_communications_broker:5.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Enterprise Communications Broker"
              }
            ],
            "category": "product_family",
            "name": "Oracle Communications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Primavera Gateway Version 21.12.0-21.12.16",
                    "product": {
                      "name": "Primavera Gateway Version 21.12.0-21.12.16",
                      "product_id": "P-10605V-21.12.0-21.12.16",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_gateway:21.12.0-21.12.16:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Primavera Gateway"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Primavera P6 Enterprise Project Portfolio Management Version 21.12.0.0-21.12.21.5",
                    "product": {
                      "name": "Primavera P6 Enterprise Project Portfolio Management Version 21.12.0.0-21.12.21.5",
                      "product_id": "P-5579V-21.12.0.0-21.12.21.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:21.12.0.0-21.12.21.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera P6 Enterprise Project Portfolio Management Version 22.12.0.0-22.12.20.0",
                    "product": {
                      "name": "Primavera P6 Enterprise Project Portfolio Management Version 22.12.0.0-22.12.20.0",
                      "product_id": "P-5579V-22.12.0.0-22.12.20.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:22.12.0.0-22.12.20.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera P6 Enterprise Project Portfolio Management Version 23.12.0.0-23.12.17.0",
                    "product": {
                      "name": "Primavera P6 Enterprise Project Portfolio Management Version 23.12.0.0-23.12.17.0",
                      "product_id": "P-5579V-23.12.0.0-23.12.17.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:23.12.0.0-23.12.17.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera P6 Enterprise Project Portfolio Management Version 24.12.0.0-24.12.11.0",
                    "product": {
                      "name": "Primavera P6 Enterprise Project Portfolio Management Version 24.12.0.0-24.12.11.0",
                      "product_id": "P-5579V-24.12.0.0-24.12.11.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:24.12.0.0-24.12.11.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera P6 Enterprise Project Portfolio Management Version 24.12.0.0-24.12.6.0",
                    "product": {
                      "name": "Primavera P6 Enterprise Project Portfolio Management Version 24.12.0.0-24.12.6.0",
                      "product_id": "P-5579V-24.12.0.0-24.12.6.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:24.12.0.0-24.12.6.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Primavera P6 Enterprise Project Portfolio Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Primavera Unifier Version 21.12.0-21.12.17",
                    "product": {
                      "name": "Primavera Unifier Version 21.12.0-21.12.17",
                      "product_id": "P-10354V-21.12.0-21.12.17",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_unifier:21.12.0-21.12.17:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera Unifier Version 22.12.0-22.12.15",
                    "product": {
                      "name": "Primavera Unifier Version 22.12.0-22.12.15",
                      "product_id": "P-10354V-22.12.0-22.12.15",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_unifier:22.12.0-22.12.15:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera Unifier Version 23.12.0-23.12.16",
                    "product": {
                      "name": "Primavera Unifier Version 23.12.0-23.12.16",
                      "product_id": "P-10354V-23.12.0-23.12.16",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_unifier:23.12.0-23.12.16:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera Unifier Version 24.12.0-24.12.12",
                    "product": {
                      "name": "Primavera Unifier Version 24.12.0-24.12.12",
                      "product_id": "P-10354V-24.12.0-24.12.12",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_unifier:24.12.0-24.12.12:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Primavera Unifier Version 25.12.0",
                    "product": {
                      "name": "Primavera Unifier Version 25.12.0",
                      "product_id": "P-10354V-25.12.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_unifier:25.12.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Primavera Unifier"
              }
            ],
            "category": "product_family",
            "name": "Oracle Construction and Engineering"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Java VM) Version 19.3-19.29",
                    "product": {
                      "name": "Oracle Database Server(Java VM) Version 19.3-19.29",
                      "product_id": "P-5(Java VM)V-19.3-19.29",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_java_vm:19.3-19.29:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Oracle Database) Version 19.3-19.29",
                    "product": {
                      "name": "Oracle Database Server(Oracle Database) Version 19.3-19.29",
                      "product_id": "P-5(Oracle Database)V-19.3-19.29",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_:19.3-19.29:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(GraalVM Multilingual Engine) Version 21.3-21.20",
                    "product": {
                      "name": "Oracle Database Server(GraalVM Multilingual Engine) Version 21.3-21.20",
                      "product_id": "P-5(GraalVM Multilingual Engine)V-21.3-21.20",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_graalvm_multilingual_engine:21.3-21.20:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Java VM) Version 21.3-21.20",
                    "product": {
                      "name": "Oracle Database Server(Java VM) Version 21.3-21.20",
                      "product_id": "P-5(Java VM)V-21.3-21.20",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_java_vm:21.3-21.20:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Oracle Database) Version 21.3-21.20",
                    "product": {
                      "name": "Oracle Database Server(Oracle Database) Version 21.3-21.20",
                      "product_id": "P-5(Oracle Database)V-21.3-21.20",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_:21.3-21.20:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(RDBMS) Version 21.3-21.20",
                    "product": {
                      "name": "Oracle Database Server(RDBMS) Version 21.3-21.20",
                      "product_id": "P-5(RDBMS)V-21.3-21.20",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_rdbms:21.3-21.20:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Fleet Patching and Provisioning) Version 23.4.0-23.26.0",
                    "product": {
                      "name": "Oracle Database Server(Fleet Patching and Provisioning) Version 23.4.0-23.26.0",
                      "product_id": "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_fleet_patching_and_provisioning:23.4.0-23.26.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(GraalVM Multilingual Engine) Version 23.4.0-23.26.0",
                    "product": {
                      "name": "Oracle Database Server(GraalVM Multilingual Engine) Version 23.4.0-23.26.0",
                      "product_id": "P-5(GraalVM Multilingual Engine)V-23.4.0-23.26.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_graalvm_multilingual_engine:23.4.0-23.26.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Oracle Database Security) Version 23.4.0-23.26.0",
                    "product": {
                      "name": "Oracle Database Server(Oracle Database Security) Version 23.4.0-23.26.0",
                      "product_id": "P-5(Oracle Database Security)V-23.4.0-23.26.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_security:23.4.0-23.26.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(RDBMS) Version 23.4.0-23.26.0",
                    "product": {
                      "name": "Oracle Database Server(RDBMS) Version 23.4.0-23.26.0",
                      "product_id": "P-5(RDBMS)V-23.4.0-23.26.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_rdbms:23.4.0-23.26.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(SQLcl) Version 23.4.0-23.26.0",
                    "product": {
                      "name": "Oracle Database Server(SQLcl) Version 23.4.0-23.26.0",
                      "product_id": "P-5(SQLcl)V-23.4.0-23.26.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_sqlcl:23.4.0-23.26.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Oracle Spatial and Graph) Version 23.4.0-23.26.0",
                    "product": {
                      "name": "Oracle Database Server(Oracle Spatial and Graph) Version 23.4.0-23.26.0",
                      "product_id": "P-619(Oracle Spatial and Graph)V-23.4.0-23.26.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_e_spatial_and_graph:23.4.0-23.26.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Database Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Graal Development Kit for Micronaut Version 19.3-19.29",
                    "product": {
                      "name": "Oracle Graal Development Kit for Micronaut Version 19.3-19.29",
                      "product_id": "P-14599V-19.3-19.29",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graal_development_kit_for_micronaut:19.3-19.29:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Graal Development Kit for Micronaut Version 23.4.0-23.26.0",
                    "product": {
                      "name": "Oracle Graal Development Kit for Micronaut Version 23.4.0-23.26.0",
                      "product_id": "P-14599V-23.4.0-23.26.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graal_development_kit_for_micronaut:23.4.0-23.26.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Graal Development Kit for Micronaut"
              }
            ],
            "category": "product_family",
            "name": "Oracle Database Server"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Applications DBA Version 12.2.3-12.2.15",
                    "product": {
                      "name": "Oracle Applications DBA Version 12.2.3-12.2.15",
                      "product_id": "P-166V-12.2.3-12.2.15",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:applications_dba:12.2.3-12.2.15:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Applications DBA"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Configurator Version 12.2.3-12.2.15",
                    "product": {
                      "name": "Oracle Configurator Version 12.2.3-12.2.15",
                      "product_id": "P-31V-12.2.3-12.2.15",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:configurator:12.2.3-12.2.15:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Configurator"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Field Service Version 12.2.3-12.2.15",
                    "product": {
                      "name": "Oracle Field Service Version 12.2.3-12.2.15",
                      "product_id": "P-747V-12.2.3-12.2.15",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:field_service:12.2.3-12.2.15:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Field Service"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Human Resources Version 12.2.3-12.2.15",
                    "product": {
                      "name": "Oracle Human Resources Version 12.2.3-12.2.15",
                      "product_id": "P-507V-12.2.3-12.2.15",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:human_resources:12.2.3-12.2.15:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Human Resources"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Scripting Version 12.2.3-12.2.15",
                    "product": {
                      "name": "Oracle Scripting Version 12.2.3-12.2.15",
                      "product_id": "P-433V-12.2.3-12.2.15",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:scripting:12.2.3-12.2.15:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Scripting"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Succession planning Version 12.2.3-12.2.15",
                    "product": {
                      "name": "Oracle Succession planning Version 12.2.3-12.2.15",
                      "product_id": "P-5709V-12.2.3-12.2.15",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:succession_planning:12.2.3-12.2.15:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Succession planning"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Time and Labor Version 12.2.3-12.2.15",
                    "product": {
                      "name": "Oracle Time and Labor Version 12.2.3-12.2.15",
                      "product_id": "P-311V-12.2.3-12.2.15",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:time_and_labor:12.2.3-12.2.15:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Time and Labor"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Workflow Version 12.2.3-12.2.15",
                    "product": {
                      "name": "Oracle Workflow Version 12.2.3-12.2.15",
                      "product_id": "P-174V-12.2.3-12.2.15",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:workflow:12.2.3-12.2.15:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Workflow"
              }
            ],
            "category": "product_family",
            "name": "Oracle E-Business Suite"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Application Testing Suite Version 13.3.0.1",
                    "product": {
                      "name": "Oracle Application Testing Suite Version 13.3.0.1",
                      "product_id": "P-4622V-13.3.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Application Testing Suite"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Manager Base Platform(Oracle Enterprise Manager Base Platform - Agent Next Gen) Version 13.5",
                    "product": {
                      "name": "Oracle Enterprise Manager Base Platform(Oracle Enterprise Manager Base Platform - Agent Next Gen) Version 13.5",
                      "product_id": "P-1370(Oracle Enterprise Manager Base Platform - Agent Next Gen)V-13.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Manager Base Platform Version 13.5",
                    "product": {
                      "name": "Oracle Enterprise Manager Base Platform Version 13.5",
                      "product_id": "P-1370V-13.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Manager Base Platform(Gateway) Version 24.1",
                    "product": {
                      "name": "Oracle Enterprise Manager Base Platform(Gateway) Version 24.1",
                      "product_id": "P-1370(Gateway)V-24.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Manager Base Platform(Oracle Enterprise Manager Base Platform - Agent Next Gen) Version 24.1",
                    "product": {
                      "name": "Oracle Enterprise Manager Base Platform(Oracle Enterprise Manager Base Platform - Agent Next Gen) Version 24.1",
                      "product_id": "P-1370(Oracle Enterprise Manager Base Platform - Agent Next Gen)V-24.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Manager Base Platform Version 24.1",
                    "product": {
                      "name": "Oracle Enterprise Manager Base Platform Version 24.1",
                      "product_id": "P-1370V-24.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Enterprise Manager Base Platform"
              }
            ],
            "category": "product_family",
            "name": "Oracle Enterprise Manager"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Essbase Version 21.8.0.0.0",
                    "product": {
                      "name": "Oracle Essbase Version 21.8.0.0.0",
                      "product_id": "P-4379V-21.8.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:essbase:21.8.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Essbase"
              }
            ],
            "category": "product_family",
            "name": "Oracle Essbase"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Branch Version 14.5.0.0.0",
                    "product": {
                      "name": "Oracle Banking Branch Version 14.5.0.0.0",
                      "product_id": "P-14324V-14.5.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_branch:14.5.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Branch Version 14.6.0.0.0",
                    "product": {
                      "name": "Oracle Banking Branch Version 14.6.0.0.0",
                      "product_id": "P-14324V-14.6.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_branch:14.6.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Branch Version 14.7.0.0.0",
                    "product": {
                      "name": "Oracle Banking Branch Version 14.7.0.0.0",
                      "product_id": "P-14324V-14.7.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_branch:14.7.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Branch Version 14.8.0.0.0",
                    "product": {
                      "name": "Oracle Banking Branch Version 14.8.0.0.0",
                      "product_id": "P-14324V-14.8.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_branch:14.8.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Banking Branch"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Cash Management Version 14.5.0.15.0",
                    "product": {
                      "name": "Oracle Banking Cash Management Version 14.5.0.15.0",
                      "product_id": "P-14195V-14.5.0.15.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_cash_management:14.5.0.15.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Cash Management Version 14.6.0.11.0",
                    "product": {
                      "name": "Oracle Banking Cash Management Version 14.6.0.11.0",
                      "product_id": "P-14195V-14.6.0.11.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_cash_management:14.6.0.11.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Cash Management Version 14.7.0.9.0",
                    "product": {
                      "name": "Oracle Banking Cash Management Version 14.7.0.9.0",
                      "product_id": "P-14195V-14.7.0.9.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_cash_management:14.7.0.9.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Cash Management Version 14.8.0.1.0",
                    "product": {
                      "name": "Oracle Banking Cash Management Version 14.8.0.1.0",
                      "product_id": "P-14195V-14.8.0.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_cash_management:14.8.0.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Cash Management Version 14.8.1.0.0",
                    "product": {
                      "name": "Oracle Banking Cash Management Version 14.8.1.0.0",
                      "product_id": "P-14195V-14.8.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_cash_management:14.8.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Banking Cash Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Corporate Lending Process Management Version 14.5.0.0.0",
                    "product": {
                      "name": "Oracle Banking Corporate Lending Process Management Version 14.5.0.0.0",
                      "product_id": "P-13701V-14.5.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.5.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Corporate Lending Process Management Version 14.6.0.0.0",
                    "product": {
                      "name": "Oracle Banking Corporate Lending Process Management Version 14.6.0.0.0",
                      "product_id": "P-13701V-14.6.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.6.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Corporate Lending Process Management Version 14.7.0.0.0",
                    "product": {
                      "name": "Oracle Banking Corporate Lending Process Management Version 14.7.0.0.0",
                      "product_id": "P-13701V-14.7.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.7.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Banking Corporate Lending Process Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Liquidity Management Version 14.5.0.14.0",
                    "product": {
                      "name": "Oracle Banking Liquidity Management Version 14.5.0.14.0",
                      "product_id": "P-13304V-14.5.0.14.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_liquidity_management:14.5.0.14.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Liquidity Management Version 14.5.0.15.0",
                    "product": {
                      "name": "Oracle Banking Liquidity Management Version 14.5.0.15.0",
                      "product_id": "P-13304V-14.5.0.15.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_liquidity_management:14.5.0.15.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Liquidity Management Version 14.6.0.11.0",
                    "product": {
                      "name": "Oracle Banking Liquidity Management Version 14.6.0.11.0",
                      "product_id": "P-13304V-14.6.0.11.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_liquidity_management:14.6.0.11.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Liquidity Management Version 14.7.0.9.0",
                    "product": {
                      "name": "Oracle Banking Liquidity Management Version 14.7.0.9.0",
                      "product_id": "P-13304V-14.7.0.9.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_liquidity_management:14.7.0.9.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Liquidity Management Version 14.8.0.1.0",
                    "product": {
                      "name": "Oracle Banking Liquidity Management Version 14.8.0.1.0",
                      "product_id": "P-13304V-14.8.0.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_liquidity_management:14.8.0.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Liquidity Management Version 14.8.1.0.0",
                    "product": {
                      "name": "Oracle Banking Liquidity Management Version 14.8.1.0.0",
                      "product_id": "P-13304V-14.8.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_liquidity_management:14.8.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Banking Liquidity Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Supply Chain Finance Version 14.5.0.15.0",
                    "product": {
                      "name": "Oracle Banking Supply Chain Finance Version 14.5.0.15.0",
                      "product_id": "P-13872V-14.5.0.15.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_supply_chain_finance:14.5.0.15.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Supply Chain Finance Version 14.6.0.11.0",
                    "product": {
                      "name": "Oracle Banking Supply Chain Finance Version 14.6.0.11.0",
                      "product_id": "P-13872V-14.6.0.11.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_supply_chain_finance:14.6.0.11.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Supply Chain Finance Version 14.7.0.9.0",
                    "product": {
                      "name": "Oracle Banking Supply Chain Finance Version 14.7.0.9.0",
                      "product_id": "P-13872V-14.7.0.9.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_supply_chain_finance:14.7.0.9.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Supply Chain Finance Version 14.8.0.1.0",
                    "product": {
                      "name": "Oracle Banking Supply Chain Finance Version 14.8.0.1.0",
                      "product_id": "P-13872V-14.8.0.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_supply_chain_finance:14.8.0.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Supply Chain Finance Version 14.8.1.0.0",
                    "product": {
                      "name": "Oracle Banking Supply Chain Finance Version 14.8.1.0.0",
                      "product_id": "P-13872V-14.8.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_supply_chain_finance:14.8.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Banking Supply Chain Finance"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle FLEXCUBE Investor Servicing Version 14.5.0.15.0",
                    "product": {
                      "name": "Oracle FLEXCUBE Investor Servicing Version 14.5.0.15.0",
                      "product_id": "P-9099V-14.5.0.15.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:flexcube_investor_servicing:14.5.0.15.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle FLEXCUBE Investor Servicing Version 14.7.0.8.0",
                    "product": {
                      "name": "Oracle FLEXCUBE Investor Servicing Version 14.7.0.8.0",
                      "product_id": "P-9099V-14.7.0.8.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:flexcube_investor_servicing:14.7.0.8.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle FLEXCUBE Investor Servicing Version 14.8.0.1.0",
                    "product": {
                      "name": "Oracle FLEXCUBE Investor Servicing Version 14.8.0.1.0",
                      "product_id": "P-9099V-14.8.0.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:flexcube_investor_servicing:14.8.0.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle FLEXCUBE Investor Servicing"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle FLEXCUBE Universal Banking Version 14.0.0.0.0-14.8.0.0.0",
                    "product": {
                      "name": "Oracle FLEXCUBE Universal Banking Version 14.0.0.0.0-14.8.0.0.0",
                      "product_id": "P-9052V-14.0.0.0.0-14.8.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:flexcube_universal_banking:14.0.0.0.0-14.8.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle FLEXCUBE Universal Banking"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Compliance Studio Version 2.6.0",
                    "product": {
                      "name": "Oracle Financial Services Compliance Studio Version 2.6.0",
                      "product_id": "P-14392V-2.6.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_compliance_studio:2.6.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Financial Services Compliance Studio"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Model Management and Governance Version 8.1.3.2",
                    "product": {
                      "name": "Oracle Financial Services Model Management and Governance Version 8.1.3.2",
                      "product_id": "P-14276V-8.1.3.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_model_management_and_governance:8.1.3.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Financial Services Model Management and Governance"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Insurance Policy Administration J2EE Version 11.3.1-12.0.6",
                    "product": {
                      "name": "Oracle Insurance Policy Administration J2EE Version 11.3.1-12.0.6",
                      "product_id": "P-5279V-11.3.1-12.0.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.3.1-12.0.6:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Insurance Policy Administration J2EE"
              }
            ],
            "category": "product_family",
            "name": "Oracle Financial Services Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Access Manager Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Access Manager Version 12.2.1.4.0",
                      "product_id": "P-5565V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Access Manager Version 14.1.2.1.0",
                    "product": {
                      "name": "Oracle Access Manager Version 14.1.2.1.0",
                      "product_id": "P-5565V-14.1.2.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Access Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Business Process Management Suite Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Business Process Management Suite Version 12.2.1.4.0",
                      "product_id": "P-5325V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Business Process Management Suite Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle Business Process Management Suite Version 14.1.2.0.0",
                      "product_id": "P-5325V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:business_process_management_suite:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Business Process Management Suite"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Coherence Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Coherence Version 12.2.1.4.0",
                      "product_id": "P-2545V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Coherence Version 14.1.1.0.0",
                    "product": {
                      "name": "Oracle Coherence Version 14.1.1.0.0",
                      "product_id": "P-2545V-14.1.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Coherence"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Data Integrator Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Data Integrator Version 12.2.1.4.0",
                      "product_id": "P-2196V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Data Integrator Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle Data Integrator Version 14.1.2.0.0",
                      "product_id": "P-2196V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:data_integrator:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Data Integrator"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Fusion Middleware Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Fusion Middleware Version 12.2.1.4.0",
                      "product_id": "P-1032V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:fusion_middleware:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Fusion Middleware Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle Fusion Middleware Version 14.1.2.0.0",
                      "product_id": "P-1032V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:fusion_middleware:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Fusion Middleware"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 15.1.1.0.0",
                    "product": {
                      "name": "Oracle Global Lifecycle Management NextGen OUI Framework Version 15.1.1.0.0",
                      "product_id": "P-12738V-15.1.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:global_lifecycle_management_nextgen_oui_framework:15.1.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Global Lifecycle Management NextGen OUI Framework"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle HTTP Server(Core) Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle HTTP Server(Core) Version 12.2.1.4.0",
                      "product_id": "P-1042(Core)V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle HTTP Server(SSL module) Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle HTTP Server(SSL module) Version 12.2.1.4.0",
                      "product_id": "P-1042(SSL module)V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle HTTP Server(mod_proxy) Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle HTTP Server(mod_proxy) Version 12.2.1.4.0",
                      "product_id": "P-1042(mod_proxy)V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle HTTP Server(mod_security) Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle HTTP Server(mod_security) Version 12.2.1.4.0",
                      "product_id": "P-1042(mod_security)V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle HTTP Server(Core) Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle HTTP Server(Core) Version 14.1.2.0.0",
                      "product_id": "P-1042(Core)V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle HTTP Server(SSL Module) Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle HTTP Server(SSL Module) Version 14.1.2.0.0",
                      "product_id": "P-1042(SSL Module)V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle HTTP Server(SSL module) Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle HTTP Server(SSL module) Version 14.1.2.0.0",
                      "product_id": "P-1042(SSL module)V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle HTTP Server(mod_proxy) Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle HTTP Server(mod_proxy) Version 14.1.2.0.0",
                      "product_id": "P-1042(mod_proxy)V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle HTTP Server(mod_security) Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle HTTP Server(mod_security) Version 14.1.2.0.0",
                      "product_id": "P-1042(mod_security)V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle HTTP Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in(Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS) Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in(Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS) Version 12.2.1.4.0",
                      "product_id": "P-1042(Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS)V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:http_server__oracle_weblogic_server_proxy_plug-in:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in(Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS) Version 14.1.1.0.0",
                    "product": {
                      "name": "Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in(Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS) Version 14.1.1.0.0",
                      "product_id": "P-1042(Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS)V-14.1.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:http_server__oracle_weblogic_server_proxy_plug-in:14.1.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in(Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS) Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in(Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS) Version 14.1.2.0.0",
                      "product_id": "P-1042(Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS)V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:http_server__oracle_weblogic_server_proxy_plug-in:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Identity Manager Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Identity Manager Version 12.2.1.4.0",
                      "product_id": "P-1980V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Identity Manager Version 14.1.2.1.0",
                    "product": {
                      "name": "Oracle Identity Manager Version 14.1.2.1.0",
                      "product_id": "P-1980V-14.1.2.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Identity Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Identity Manager Connector Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Identity Manager Connector Version 12.2.1.4.0",
                      "product_id": "P-1999V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Identity Manager Connector Version 14.1.2.1.0",
                    "product": {
                      "name": "Oracle Identity Manager Connector Version 14.1.2.1.0",
                      "product_id": "P-1999V-14.1.2.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Identity Manager Connector"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Managed File Transfer Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Managed File Transfer Version 12.2.1.4.0",
                      "product_id": "P-10198V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:managed_file_transfer:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Managed File Transfer Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle Managed File Transfer Version 14.1.2.0.0",
                      "product_id": "P-10198V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:managed_file_transfer:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Managed File Transfer"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Middleware Common Libraries and Tools Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Middleware Common Libraries and Tools Version 12.2.1.4.0",
                      "product_id": "P-4647V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Middleware Common Libraries and Tools Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle Middleware Common Libraries and Tools Version 14.1.2.0.0",
                      "product_id": "P-4647V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:middleware_common_libraries_and_tools:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Middleware Common Libraries and Tools"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Outside In Technology Version 8.5.7",
                    "product": {
                      "name": "Oracle Outside In Technology Version 8.5.7",
                      "product_id": "P-2276V-8.5.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:outside_in_technology:8.5.7:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Outside In Technology Version 8.5.8",
                    "product": {
                      "name": "Oracle Outside In Technology Version 8.5.8",
                      "product_id": "P-2276V-8.5.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:outside_in_technology:8.5.8:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Outside In Technology"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle SOA Suite Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle SOA Suite Version 12.2.1.4.0",
                      "product_id": "P-1162V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:soa_suite:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle SOA Suite Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle SOA Suite Version 14.1.2.0.0",
                      "product_id": "P-1162V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:soa_suite:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle SOA Suite"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Security Service Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Security Service Version 12.2.1.4.0",
                      "product_id": "P-991V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:security_service:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Security Service"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Service Bus Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Service Bus Version 12.2.1.4.0",
                      "product_id": "P-5308V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:service_bus:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Service Bus Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle Service Bus Version 14.1.2.0.0",
                      "product_id": "P-5308V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:service_bus:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Service Bus"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Unified Directory Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Unified Directory Version 12.2.1.4.0",
                      "product_id": "P-9118V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:unified_directory:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Unified Directory Version 14.1.2.1.0",
                    "product": {
                      "name": "Oracle Unified Directory Version 14.1.2.1.0",
                      "product_id": "P-9118V-14.1.2.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:unified_directory:14.1.2.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Unified Directory"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle WebCenter Enterprise Capture Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle WebCenter Enterprise Capture Version 12.2.1.4.0",
                      "product_id": "P-10212V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle WebCenter Enterprise Capture Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle WebCenter Enterprise Capture Version 14.1.2.0.0",
                      "product_id": "P-10212V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle WebCenter Enterprise Capture"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle WebCenter Sites Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle WebCenter Sites Version 12.2.1.4.0",
                      "product_id": "P-9617V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle WebCenter Sites Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle WebCenter Sites Version 14.1.2.0.0",
                      "product_id": "P-9617V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle WebCenter Sites"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle WebLogic Server Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle WebLogic Server Version 12.2.1.4.0",
                      "product_id": "P-5242V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle WebLogic Server Version 14.1.1.0.0",
                    "product": {
                      "name": "Oracle WebLogic Server Version 14.1.1.0.0",
                      "product_id": "P-5242V-14.1.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle WebLogic Server Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle WebLogic Server Version 14.1.2.0.0",
                      "product_id": "P-5242V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle WebLogic Server Version 15.1.1.0.0",
                    "product": {
                      "name": "Oracle WebLogic Server Version 15.1.1.0.0",
                      "product_id": "P-5242V-15.1.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle WebLogic Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Weblogic Server Proxy Plug-in(Oracle Weblogic Server Proxy Plug-in for Apache HTTP Server) Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Weblogic Server Proxy Plug-in(Oracle Weblogic Server Proxy Plug-in for Apache HTTP Server) Version 12.2.1.4.0",
                      "product_id": "P-1042(Oracle Weblogic Server Proxy Plug-in for Apache HTTP Server)V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:weblogic_server_proxy_plug-in:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Weblogic Server Proxy Plug-in(Oracle Weblogic Server Proxy Plug-in for Apache HTTP Server) Version 14.1.1.0.0",
                    "product": {
                      "name": "Oracle Weblogic Server Proxy Plug-in(Oracle Weblogic Server Proxy Plug-in for Apache HTTP Server) Version 14.1.1.0.0",
                      "product_id": "P-1042(Oracle Weblogic Server Proxy Plug-in for Apache HTTP Server)V-14.1.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:weblogic_server_proxy_plug-in:14.1.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Weblogic Server Proxy Plug-in"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Service Delivery Platform Version 14.1.2.0.0",
                    "product": {
                      "name": "Service Delivery Platform Version 14.1.2.0.0",
                      "product_id": "P-2063V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Service Delivery Platform"
              }
            ],
            "category": "product_family",
            "name": "Oracle Fusion Middleware"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Version 19.1.0.0.0-19.29.0.0.251021",
                    "product": {
                      "name": "Oracle GoldenGate Version 19.1.0.0.0-19.29.0.0.251021",
                      "product_id": "P-5757V-19.1.0.0.0-19.29.0.0.251021",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate:19.1.0.0.0-19.29.0.0.251021:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Version 21.3-21.20",
                    "product": {
                      "name": "Oracle GoldenGate Version 21.3-21.20",
                      "product_id": "P-5757V-21.3-21.20",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate:21.3-21.20:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Version 23.4-23.10",
                    "product": {
                      "name": "Oracle GoldenGate Version 23.4-23.10",
                      "product_id": "P-5757V-23.4-23.10",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate:23.4-23.10:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GoldenGate"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Big Data and Application Adapters Version 19.1.0.0.0-19.1.0.0.20",
                    "product": {
                      "name": "Oracle GoldenGate Big Data and Application Adapters Version 19.1.0.0.0-19.1.0.0.20",
                      "product_id": "P-5760V-19.1.0.0.0-19.1.0.0.20",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_big_data_and_application_adapters:19.1.0.0.0-19.1.0.0.20:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Big Data and Application Adapters Version 21.3-21.14",
                    "product": {
                      "name": "Oracle GoldenGate Big Data and Application Adapters Version 21.3-21.14",
                      "product_id": "P-5760V-21.3-21.14",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_big_data_and_application_adapters:21.3-21.14:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Big Data and Application Adapters Version 21.3-21.20",
                    "product": {
                      "name": "Oracle GoldenGate Big Data and Application Adapters Version 21.3-21.20",
                      "product_id": "P-5760V-21.3-21.20",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_big_data_and_application_adapters:21.3-21.20:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Big Data and Application Adapters Version 23.4-23.10",
                    "product": {
                      "name": "Oracle GoldenGate Big Data and Application Adapters Version 23.4-23.10",
                      "product_id": "P-5760V-23.4-23.10",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_big_data_and_application_adapters:23.4-23.10:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GoldenGate Big Data and Application Adapters"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Stream Analytics Version 19.1.0.0.0-19.1.0.0.11",
                    "product": {
                      "name": "Oracle GoldenGate Stream Analytics Version 19.1.0.0.0-19.1.0.0.11",
                      "product_id": "P-14015V-19.1.0.0.0-19.1.0.0.11",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_stream_analytics:19.1.0.0.0-19.1.0.0.11:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Stream Analytics Version 19.1.0.0.0-19.1.0.0.13",
                    "product": {
                      "name": "Oracle GoldenGate Stream Analytics Version 19.1.0.0.0-19.1.0.0.13",
                      "product_id": "P-14015V-19.1.0.0.0-19.1.0.0.13",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_stream_analytics:19.1.0.0.0-19.1.0.0.13:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GoldenGate Stream Analytics"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Studio Version 23.8.0-23.9.0",
                    "product": {
                      "name": "Oracle GoldenGate Studio Version 23.8.0-23.9.0",
                      "product_id": "P-10945V-23.8.0-23.9.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_studio:23.8.0-23.9.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GoldenGate Studio"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Veridata Version 12.2.1.4.0-12.2.1.4.250531",
                    "product": {
                      "name": "Oracle GoldenGate Veridata Version 12.2.1.4.0-12.2.1.4.250531",
                      "product_id": "P-5758V-12.2.1.4.0-12.2.1.4.250531",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_veridata:12.2.1.4.0-12.2.1.4.250531:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GoldenGate Veridata"
              }
            ],
            "category": "product_family",
            "name": "Oracle GoldenGate"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Graph Server and Client Version 24.4.4",
                    "product": {
                      "name": "Oracle Graph Server and Client Version 24.4.4",
                      "product_id": "P-14069V-24.4.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graph_server_and_client:24.4.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Graph Server and Client Version 25.4.0",
                    "product": {
                      "name": "Oracle Graph Server and Client Version 25.4.0",
                      "product_id": "P-14069V-25.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graph_server_and_client:25.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Graph Server and Client"
              }
            ],
            "category": "product_family",
            "name": "Oracle Graph Server and Client"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Life Sciences Central Coding Version 7.0.1.0",
                    "product": {
                      "name": "Oracle Life Sciences Central Coding Version 7.0.1.0",
                      "product_id": "P-9644V-7.0.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:life_sciences_central_coding:7.0.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Life Sciences Central Coding"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Life Sciences Central Designer(Platform) Version 7.0.1.0",
                    "product": {
                      "name": "Oracle Life Sciences Central Designer(Platform) Version 7.0.1.0",
                      "product_id": "P-9645(Platform)V-7.0.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:life_sciences_central_designer:7.0.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Life Sciences Central Designer Version 7.0.1.0",
                    "product": {
                      "name": "Oracle Life Sciences Central Designer Version 7.0.1.0",
                      "product_id": "P-9645V-7.0.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:life_sciences_central_designer:7.0.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Life Sciences Central Designer"
              }
            ],
            "category": "product_family",
            "name": "Oracle Health Sciences Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Health Sciences Information Manager Version 4.0.0",
                    "product": {
                      "name": "Oracle Health Sciences Information Manager Version 4.0.0",
                      "product_id": "P-9177V-4.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:health_sciences_information_manager:4.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Health Sciences Information Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Healthcare Data Repository Version 8.2.0.5",
                    "product": {
                      "name": "Oracle Healthcare Data Repository Version 8.2.0.5",
                      "product_id": "P-9161V-8.2.0.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:healthcare_data_repository:8.2.0.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Healthcare Data Repository Version 8.2.0.6",
                    "product": {
                      "name": "Oracle Healthcare Data Repository Version 8.2.0.6",
                      "product_id": "P-9161V-8.2.0.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:healthcare_data_repository:8.2.0.6:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Healthcare Data Repository"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Healthcare Master Person Index Version 5.0.0.0-5.0.9.5",
                    "product": {
                      "name": "Oracle Healthcare Master Person Index Version 5.0.0.0-5.0.9.5",
                      "product_id": "P-8575V-5.0.0.0-5.0.9.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:healthcare_master_person_index:5.0.0.0-5.0.9.5:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Healthcare Master Person Index"
              }
            ],
            "category": "product_family",
            "name": "Oracle HealthCare Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hospitality OPERA 5 Property Services Version 5.6.19",
                    "product": {
                      "name": "Oracle Hospitality OPERA 5 Property Services Version 5.6.19",
                      "product_id": "P-11580V-5.6.19",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hospitality_opera_5_property_services:5.6.19:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Hospitality OPERA 5 Property Services Version 5.6.25",
                    "product": {
                      "name": "Oracle Hospitality OPERA 5 Property Services Version 5.6.25",
                      "product_id": "P-11580V-5.6.25",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hospitality_opera_5_property_services:5.6.25:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Hospitality OPERA 5 Property Services Version 5.6.26",
                    "product": {
                      "name": "Oracle Hospitality OPERA 5 Property Services Version 5.6.26",
                      "product_id": "P-11580V-5.6.26",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hospitality_opera_5_property_services:5.6.26:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Hospitality OPERA 5 Property Services Version 5.6.27",
                    "product": {
                      "name": "Oracle Hospitality OPERA 5 Property Services Version 5.6.27",
                      "product_id": "P-11580V-5.6.27",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hospitality_opera_5_property_services:5.6.27:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hospitality OPERA 5 Property Services"
              }
            ],
            "category": "product_family",
            "name": "Oracle Hospitality Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hyperion Calculation Manager Version 11.2.23",
                    "product": {
                      "name": "Oracle Hyperion Calculation Manager Version 11.2.23",
                      "product_id": "P-5685V-11.2.23",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hyperion_calculation_manager:11.2.23:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Calculation Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hyperion Financial Close Management Version 11.2.23",
                    "product": {
                      "name": "Oracle Hyperion Financial Close Management Version 11.2.23",
                      "product_id": "P-5616V-11.2.23",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hyperion_financial_close_management:11.2.23:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Financial Close Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hyperion Financial Management Version 11.2.23",
                    "product": {
                      "name": "Oracle Hyperion Financial Management Version 11.2.23",
                      "product_id": "P-4390V-11.2.23",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hyperion_financial_management:11.2.23:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Financial Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hyperion Financial Reporting Version 11.2.23",
                    "product": {
                      "name": "Oracle Hyperion Financial Reporting Version 11.2.23",
                      "product_id": "P-8776V-11.2.23",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.23:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Financial Reporting"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hyperion Infrastructure Technology Version 11.2.23",
                    "product": {
                      "name": "Oracle Hyperion Infrastructure Technology Version 11.2.23",
                      "product_id": "P-4392V-11.2.23",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.23:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Infrastructure Technology"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hyperion Planning Version 11.2.23",
                    "product": {
                      "name": "Oracle Hyperion Planning Version 11.2.23",
                      "product_id": "P-4402V-11.2.23",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hyperion_planning:11.2.23:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Planning"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hyperion Profitability and Cost Management Version 11.2.23",
                    "product": {
                      "name": "Oracle Hyperion Profitability and Cost Management Version 11.2.23",
                      "product_id": "P-4403V-11.2.23",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hyperion_profitability_and_cost_management:11.2.23:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Profitability and Cost Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Planning and Budgeting Cloud Service Version 25.04.07",
                    "product": {
                      "name": "Oracle Planning and Budgeting Cloud Service Version 25.04.07",
                      "product_id": "P-10707V-25.04.07",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:planning_and_budgeting_cloud_service:25.04.07:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Planning and Budgeting Cloud Service"
              }
            ],
            "category": "product_family",
            "name": "Oracle Hyperion"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "JD Edwards EnterpriseOne Tools Version 9.2.0.0-9.2.26.0",
                    "product": {
                      "name": "JD Edwards EnterpriseOne Tools Version 9.2.0.0-9.2.26.0",
                      "product_id": "P-4781V-9.2.0.0-9.2.26.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2.0.0-9.2.26.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "JD Edwards EnterpriseOne Tools Version 9.2.0.0-9.2.9.4",
                    "product": {
                      "name": "JD Edwards EnterpriseOne Tools Version 9.2.0.0-9.2.9.4",
                      "product_id": "P-4781V-9.2.0.0-9.2.9.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2.0.0-9.2.9.4:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "JD Edwards EnterpriseOne Tools"
              }
            ],
            "category": "product_family",
            "name": "Oracle JD Edwards"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle GraalVM Enterprise Edition Version 21.3.16",
                    "product": {
                      "name": "Oracle GraalVM Enterprise Edition Version 21.3.16",
                      "product_id": "P-13497V-21.3.16",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graalvm:21.3.16:*:*:*:enterprise:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GraalVM Enterprise Edition"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle GraalVM for JDK Version 17.0.17",
                    "product": {
                      "name": "Oracle GraalVM for JDK Version 17.0.17",
                      "product_id": "P-13497V-17.0.17",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graalvm_for_jdk:17.0.17:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle GraalVM for JDK Version 21.0.9",
                    "product": {
                      "name": "Oracle GraalVM for JDK Version 21.0.9",
                      "product_id": "P-13497V-21.0.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graalvm_for_jdk:21.0.9:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GraalVM for JDK"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle JDK Mission Control Version  9.1.1",
                    "product": {
                      "name": "Oracle JDK Mission Control Version  9.1.1",
                      "product_id": "P-856V- 9.1.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:jdk_mission_control:9.1.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle JDK Mission Control"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version 11.0.29",
                    "product": {
                      "name": "Oracle Java SE Version 11.0.29",
                      "product_id": "P-856V-11.0.29",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:11.0.29:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version 17.0.17",
                    "product": {
                      "name": "Oracle Java SE Version 17.0.17",
                      "product_id": "P-856V-17.0.17",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:17.0.17:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version 21.0.9",
                    "product": {
                      "name": "Oracle Java SE Version 21.0.9",
                      "product_id": "P-856V-21.0.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:21.0.9:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version 25.0.1",
                    "product": {
                      "name": "Oracle Java SE Version 25.0.1",
                      "product_id": "P-856V-25.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:25.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version 8u471",
                    "product": {
                      "name": "Oracle Java SE Version 8u471",
                      "product_id": "P-856V-8u471",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:8u471:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Java SE Version 8u471-b50",
                    "product": {
                      "name": "Oracle Java SE Version 8u471-b50",
                      "product_id": "P-856V-8u471-b50",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:8u471-b50:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version 8u471-perf",
                    "product": {
                      "name": "Oracle Java SE Version 8u471-perf",
                      "product_id": "P-856V-8u471-perf",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:8u471:*:*:*:enterprise_performance:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Java SE"
              }
            ],
            "category": "product_family",
            "name": "Oracle Java SE"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Key Vault Version 21.1.0.0.0-21.11.0.0.0",
                    "product": {
                      "name": "Oracle Key Vault Version 21.1.0.0.0-21.11.0.0.0",
                      "product_id": "P-10221V-21.1.0.0.0-21.11.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:key_vault:21.1.0.0.0-21.11.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Key Vault"
              }
            ],
            "category": "product_family",
            "name": "Oracle Key Vault"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 7.6.0-7.6.36",
                    "product": {
                      "name": "MySQL Cluster Version 7.6.0-7.6.36",
                      "product_id": "P-8479V-7.6.0-7.6.36",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_cluster:7.6.0-7.6.36:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 8.0.0-8.0.44",
                    "product": {
                      "name": "MySQL Cluster Version 8.0.0-8.0.44",
                      "product_id": "P-8479V-8.0.0-8.0.44",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.0-8.0.44:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 8.4.0-8.4.7",
                    "product": {
                      "name": "MySQL Cluster Version 8.4.0-8.4.7",
                      "product_id": "P-8479V-8.4.0-8.4.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.4.0-8.4.7:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 9.0.0-9.5.0",
                    "product": {
                      "name": "MySQL Cluster Version 9.0.0-9.5.0",
                      "product_id": "P-8479V-9.0.0-9.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.0.0-9.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Cluster"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Connectors(Connector/C++) Version 9.0.0-9.5.0",
                    "product": {
                      "name": "MySQL Connectors(Connector/C++) Version 9.0.0-9.5.0",
                      "product_id": "P-8576(Connector/C++)V-9.0.0-9.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_connector\\/c\\+\\+:9.0.0-9.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Connectors(Connector/ODBC) Version 9.0.0-9.5.0",
                    "product": {
                      "name": "MySQL Connectors(Connector/ODBC) Version 9.0.0-9.5.0",
                      "product_id": "P-8576(Connector/ODBC)V-9.0.0-9.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_connector\\/odbc:9.0.0-9.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Connectors"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Enterprise Backup Version 8.0.0-8.0.43",
                    "product": {
                      "name": "MySQL Enterprise Backup Version 8.0.0-8.0.43",
                      "product_id": "P-4629V-8.0.0-8.0.43",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_enterprise_backup:8.0.0-8.0.43:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Enterprise Backup Version 8.0.0-8.0.44",
                    "product": {
                      "name": "MySQL Enterprise Backup Version 8.0.0-8.0.44",
                      "product_id": "P-4629V-8.0.0-8.0.44",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_enterprise_backup:8.0.0-8.0.44:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Enterprise Backup Version 8.4.0-8.4.6",
                    "product": {
                      "name": "MySQL Enterprise Backup Version 8.4.0-8.4.6",
                      "product_id": "P-4629V-8.4.0-8.4.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_enterprise_backup:8.4.0-8.4.6:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Enterprise Backup Version 8.4.0-8.4.7",
                    "product": {
                      "name": "MySQL Enterprise Backup Version 8.4.0-8.4.7",
                      "product_id": "P-4629V-8.4.0-8.4.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_enterprise_backup:8.4.0-8.4.7:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Enterprise Backup Version 9.0.0-9.4.0",
                    "product": {
                      "name": "MySQL Enterprise Backup Version 9.0.0-9.4.0",
                      "product_id": "P-4629V-9.0.0-9.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_enterprise_backup:9.0.0-9.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Enterprise Backup Version 9.0.0-9.5.0",
                    "product": {
                      "name": "MySQL Enterprise Backup Version 9.0.0-9.5.0",
                      "product_id": "P-4629V-9.0.0-9.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_enterprise_backup:9.0.0-9.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Enterprise Backup"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(InnoDB) Version 8.0.0-8.0.44",
                    "product": {
                      "name": "MySQL Server(InnoDB) Version 8.0.0-8.0.44",
                      "product_id": "P-8478(InnoDB)V-8.0.0-8.0.44",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.44:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: DDL) Version 8.0.0-8.0.44",
                    "product": {
                      "name": "MySQL Server(Server: DDL) Version 8.0.0-8.0.44",
                      "product_id": "P-8478(Server: DDL)V-8.0.0-8.0.44",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.44:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Optimizer) Version 8.0.0-8.0.44",
                    "product": {
                      "name": "MySQL Server(Server: Optimizer) Version 8.0.0-8.0.44",
                      "product_id": "P-8478(Server: Optimizer)V-8.0.0-8.0.44",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.44:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Packaging) Version 8.0.0-8.0.44",
                    "product": {
                      "name": "MySQL Server(Server: Packaging) Version 8.0.0-8.0.44",
                      "product_id": "P-8478(Server: Packaging)V-8.0.0-8.0.44",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.44:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Thread Pooling) Version 8.0.0-8.0.44",
                    "product": {
                      "name": "MySQL Server(Server: Thread Pooling) Version 8.0.0-8.0.44",
                      "product_id": "P-8478(Server: Thread Pooling)V-8.0.0-8.0.44",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.44:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(InnoDB) Version 8.4.0-8.4.7",
                    "product": {
                      "name": "MySQL Server(InnoDB) Version 8.4.0-8.4.7",
                      "product_id": "P-8478(InnoDB)V-8.4.0-8.4.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.7:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: DDL) Version 8.4.0-8.4.7",
                    "product": {
                      "name": "MySQL Server(Server: DDL) Version 8.4.0-8.4.7",
                      "product_id": "P-8478(Server: DDL)V-8.4.0-8.4.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.7:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Docker Images) Version 8.4.0-8.4.7",
                    "product": {
                      "name": "MySQL Server(Server: Docker Images) Version 8.4.0-8.4.7",
                      "product_id": "P-8478(Server: Docker Images)V-8.4.0-8.4.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.7:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Optimizer) Version 8.4.0-8.4.7",
                    "product": {
                      "name": "MySQL Server(Server: Optimizer) Version 8.4.0-8.4.7",
                      "product_id": "P-8478(Server: Optimizer)V-8.4.0-8.4.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.7:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Packaging) Version 8.4.0-8.4.7",
                    "product": {
                      "name": "MySQL Server(Server: Packaging) Version 8.4.0-8.4.7",
                      "product_id": "P-8478(Server: Packaging)V-8.4.0-8.4.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.7:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Thread Pooling) Version 8.4.0-8.4.7",
                    "product": {
                      "name": "MySQL Server(Server: Thread Pooling) Version 8.4.0-8.4.7",
                      "product_id": "P-8478(Server: Thread Pooling)V-8.4.0-8.4.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.7:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(InnoDB) Version 9.0.0-9.5.0",
                    "product": {
                      "name": "MySQL Server(InnoDB) Version 9.0.0-9.5.0",
                      "product_id": "P-8478(InnoDB)V-9.0.0-9.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: DDL) Version 9.0.0-9.5.0",
                    "product": {
                      "name": "MySQL Server(Server: DDL) Version 9.0.0-9.5.0",
                      "product_id": "P-8478(Server: DDL)V-9.0.0-9.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Optimizer) Version 9.0.0-9.5.0",
                    "product": {
                      "name": "MySQL Server(Server: Optimizer) Version 9.0.0-9.5.0",
                      "product_id": "P-8478(Server: Optimizer)V-9.0.0-9.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Packaging) Version 9.0.0-9.5.0",
                    "product": {
                      "name": "MySQL Server(Server: Packaging) Version 9.0.0-9.5.0",
                      "product_id": "P-8478(Server: Packaging)V-9.0.0-9.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Parser) Version 9.0.0-9.5.0",
                    "product": {
                      "name": "MySQL Server(Server: Parser) Version 9.0.0-9.5.0",
                      "product_id": "P-8478(Server: Parser)V-9.0.0-9.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Pluggable Auth) Version 9.0.0-9.5.0",
                    "product": {
                      "name": "MySQL Server(Server: Pluggable Auth) Version 9.0.0-9.5.0",
                      "product_id": "P-8478(Server: Pluggable Auth)V-9.0.0-9.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Thread Pooling) Version 9.0.0-9.5.0",
                    "product": {
                      "name": "MySQL Server(Server: Thread Pooling) Version 9.0.0-9.5.0",
                      "product_id": "P-8478(Server: Thread Pooling)V-9.0.0-9.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Workbench Version 8.0.0-8.0.45",
                    "product": {
                      "name": "MySQL Workbench Version 8.0.0-8.0.45",
                      "product_id": "P-4627V-8.0.0-8.0.45",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_workbench:8.0.0-8.0.45:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Workbench"
              }
            ],
            "category": "product_family",
            "name": "Oracle MySQL"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle NoSQL Database Version 1.5",
                    "product": {
                      "name": "Oracle NoSQL Database Version 1.5",
                      "product_id": "P-13373V-1.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:nosql_database:1.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle NoSQL Database Version 1.6",
                    "product": {
                      "name": "Oracle NoSQL Database Version 1.6",
                      "product_id": "P-13373V-1.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:nosql_database:1.6:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle NoSQL Database"
              }
            ],
            "category": "product_family",
            "name": "Oracle NoSQL Database"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise HCM Human Resources Version 9.2",
                    "product": {
                      "name": "PeopleSoft Enterprise HCM Human Resources Version 9.2",
                      "product_id": "P-5071V-9.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_human_resources:9.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "PeopleSoft Enterprise HCM Human Resources"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise PeopleTools Version 8.60",
                    "product": {
                      "name": "PeopleSoft Enterprise PeopleTools Version 8.60",
                      "product_id": "P-5085V-8.60",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.60:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise PeopleTools Version 8.61",
                    "product": {
                      "name": "PeopleSoft Enterprise PeopleTools Version 8.61",
                      "product_id": "P-5085V-8.61",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.61:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise PeopleTools Version 8.62",
                    "product": {
                      "name": "PeopleSoft Enterprise PeopleTools Version 8.62",
                      "product_id": "P-5085V-8.62",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.62:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "PeopleSoft Enterprise PeopleTools"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise SCM Purchasing Version 9.2",
                    "product": {
                      "name": "PeopleSoft Enterprise SCM Purchasing Version 9.2",
                      "product_id": "P-5133V-9.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_scm_purchasing:9.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "PeopleSoft Enterprise SCM Purchasing"
              }
            ],
            "category": "product_family",
            "name": "Oracle PeopleSoft"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Advanced Inventory Planning Version 15.0.3",
                    "product": {
                      "name": "Oracle Retail Advanced Inventory Planning Version 15.0.3",
                      "product_id": "P-1785V-15.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_advanced_inventory_planning:15.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Advanced Inventory Planning Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Advanced Inventory Planning Version 16.0.3",
                      "product_id": "P-1785V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_advanced_inventory_planning:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Advanced Inventory Planning"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Allocation Version 15.0.3",
                    "product": {
                      "name": "Oracle Retail Allocation Version 15.0.3",
                      "product_id": "P-1786V-15.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_allocation:15.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Allocation Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Allocation Version 16.0.3",
                      "product_id": "P-1786V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_allocation:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Allocation"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Bulk Data Integration Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Bulk Data Integration Version 16.0.3",
                      "product_id": "P-12968V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_bulk_data_integration:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Bulk Data Integration Version 19.0.1",
                    "product": {
                      "name": "Oracle Retail Bulk Data Integration Version 19.0.1",
                      "product_id": "P-12968V-19.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_bulk_data_integration:19.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Bulk Data Integration"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Financial Integration Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Financial Integration Version 16.0.3",
                      "product_id": "P-10722V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_financial_integration:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Financial Integration Version 19.0.1",
                    "product": {
                      "name": "Oracle Retail Financial Integration Version 19.0.1",
                      "product_id": "P-10722V-19.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_financial_integration:19.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Financial Integration"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Fiscal Management Version 14.2",
                    "product": {
                      "name": "Oracle Retail Fiscal Management Version 14.2",
                      "product_id": "P-9038V-14.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_fiscal_management:14.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Fiscal Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Integration Bus Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Integration Bus Version 16.0.3",
                      "product_id": "P-1807V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_integration_bus:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Integration Bus Version 19.0.1",
                    "product": {
                      "name": "Oracle Retail Integration Bus Version 19.0.1",
                      "product_id": "P-1807V-19.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_integration_bus:19.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Integration Bus"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Predictive Application Server Version 15.0.3",
                    "product": {
                      "name": "Oracle Retail Predictive Application Server Version 15.0.3",
                      "product_id": "P-1823V-15.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_predictive_application_server:15.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Predictive Application Server Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Predictive Application Server Version 16.0.3",
                      "product_id": "P-1823V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_predictive_application_server:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Predictive Application Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Service Backbone Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Service Backbone Version 16.0.3",
                      "product_id": "P-10867V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_service_backbone:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Service Backbone Version 19.0.1",
                    "product": {
                      "name": "Oracle Retail Service Backbone Version 19.0.1",
                      "product_id": "P-10867V-19.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_service_backbone:19.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Service Backbone"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Office Version 25.0.1",
                    "product": {
                      "name": "Oracle Retail Xstore Office Version 25.0.1",
                      "product_id": "P-11560V-25.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_office:25.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Xstore Office"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 20.0.5",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 20.0.5",
                      "product_id": "P-11513V-20.0.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:20.0.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 21.0.4",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 21.0.4",
                      "product_id": "P-11513V-21.0.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:21.0.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 22.0.2",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 22.0.2",
                      "product_id": "P-11513V-22.0.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:22.0.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 23.0.2",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 23.0.2",
                      "product_id": "P-11513V-23.0.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:23.0.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 24.0.1",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 24.0.1",
                      "product_id": "P-11513V-24.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:24.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 25.0.0",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 25.0.0",
                      "product_id": "P-11513V-25.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:25.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Xstore Point of Service"
              }
            ],
            "category": "product_family",
            "name": "Oracle Retail Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Secure Backup Version 19.1.0.0.0-19.1.0.1.0",
                    "product": {
                      "name": "Oracle Secure Backup Version 19.1.0.0.0-19.1.0.1.0",
                      "product_id": "P-1522V-19.1.0.0.0-19.1.0.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:secure_backup:19.1.0.0.0-19.1.0.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Secure Backup"
              }
            ],
            "category": "product_family",
            "name": "Oracle Secure Backup"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Siebel Apps - Marketing Version 17.0-25.9",
                    "product": {
                      "name": "Siebel Apps - Marketing Version 17.0-25.9",
                      "product_id": "P-8974V-17.0-25.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:siebel_apps_-_marketing:17.0-25.9:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Siebel Apps - Marketing"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Siebel CRM Cloud Applications Version 17.0-25.11",
                    "product": {
                      "name": "Siebel CRM Cloud Applications Version 17.0-25.11",
                      "product_id": "P-14107V-17.0-25.11",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:siebel_crm_cloud_applications:17.0-25.11:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Siebel CRM Cloud Applications Version 17.0-25.9",
                    "product": {
                      "name": "Siebel CRM Cloud Applications Version 17.0-25.9",
                      "product_id": "P-14107V-17.0-25.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:siebel_crm_cloud_applications:17.0-25.9:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Siebel CRM Cloud Applications"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Siebel CRM Deployment Version 17.0-25.10",
                    "product": {
                      "name": "Siebel CRM Deployment Version 17.0-25.10",
                      "product_id": "P-9019V-17.0-25.10",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:siebel_crm_deployment:17.0-25.10:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Siebel CRM Deployment Version 17.0-25.11",
                    "product": {
                      "name": "Siebel CRM Deployment Version 17.0-25.11",
                      "product_id": "P-9019V-17.0-25.11",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:siebel_crm_deployment:17.0-25.11:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Siebel CRM Deployment Version 17.0-25.2",
                    "product": {
                      "name": "Siebel CRM Deployment Version 17.0-25.2",
                      "product_id": "P-9019V-17.0-25.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:siebel_crm_deployment:17.0-25.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Siebel CRM Deployment Version 17.0-25.9",
                    "product": {
                      "name": "Siebel CRM Deployment Version 17.0-25.9",
                      "product_id": "P-9019V-17.0-25.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:siebel_crm_deployment:17.0-25.9:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Siebel CRM Deployment"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Siebel CRM Integration Version 17.0-25.9",
                    "product": {
                      "name": "Siebel CRM Integration Version 17.0-25.9",
                      "product_id": "P-9008V-17.0-25.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:siebel_crm_integration:17.0-25.9:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Siebel CRM Integration"
              }
            ],
            "category": "product_family",
            "name": "Oracle Siebel CRM"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Agile PLM Version 9.3.6",
                    "product": {
                      "name": "Oracle Agile PLM Version 9.3.6",
                      "product_id": "P-4461V-9.3.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Agile PLM"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Agile Product Lifecycle Management for Process Version 6.2.4",
                    "product": {
                      "name": "Oracle Agile Product Lifecycle Management for Process Version 6.2.4",
                      "product_id": "P-4445V-6.2.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Agile Product Lifecycle Management for Process Version 6.2.4",
                    "product": {
                      "name": "Oracle Agile Product Lifecycle Management for Process Version 6.2.4",
                      "product_id": "P-4447V-6.2.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.4:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Agile Product Lifecycle Management for Process"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle AutoVue Office Version 21.1.0",
                    "product": {
                      "name": "Oracle AutoVue Office Version 21.1.0",
                      "product_id": "P-4449V-21.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:autovue_office:21.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle AutoVue Office"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Autovue for Agile Product Lifecycle Management Version 21.1.0",
                    "product": {
                      "name": "Oracle Autovue for Agile Product Lifecycle Management Version 21.1.0",
                      "product_id": "P-4434V-21.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:autovue_for_agile_product_lifecycle_management:21.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Autovue for Agile Product Lifecycle Management"
              }
            ],
            "category": "product_family",
            "name": "Oracle Supply Chain"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Solaris Version 10",
                    "product": {
                      "name": "Oracle Solaris Version 10",
                      "product_id": "P-10006V-10",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:solaris:10:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Solaris Version 11",
                    "product": {
                      "name": "Oracle Solaris Version 11",
                      "product_id": "P-10006V-11",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:solaris:11:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Solaris"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle ZFS Storage Appliance Kit Version 8.8",
                    "product": {
                      "name": "Oracle ZFS Storage Appliance Kit Version 8.8",
                      "product_id": "P-10026V-8.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle ZFS Storage Appliance Kit"
              }
            ],
            "category": "product_family",
            "name": "Oracle Systems"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle TimesTen In-Memory Database Version 22.1.1.1.0-22.1.1.35.0",
                    "product": {
                      "name": "Oracle TimesTen In-Memory Database Version 22.1.1.1.0-22.1.1.35.0",
                      "product_id": "P-1870V-22.1.1.1.0-22.1.1.35.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:timesten_in-memory_database:22.1.1.1.0-22.1.1.35.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle TimesTen In-Memory Database"
              }
            ],
            "category": "product_family",
            "name": "Oracle TimesTen In-Memory Database"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 25.10",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 25.10",
                      "product_id": "P-2245V-25.10",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:25.10:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 25.4",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 25.4",
                      "product_id": "P-2245V-25.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:25.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.3.0.5.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.3.0.5.0",
                      "product_id": "P-2245V-4.3.0.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.3.0.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.3.0.6.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.3.0.6.0",
                      "product_id": "P-2245V-4.3.0.6.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.3.0.6.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.4.0.0.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.4.0.0.0",
                      "product_id": "P-2245V-4.4.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.4.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.4.0.2.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.4.0.2.0",
                      "product_id": "P-2245V-4.4.0.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.4.0.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.4.0.3.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.4.0.3.0",
                      "product_id": "P-2245V-4.4.0.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.4.0.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.4.0.4.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.4.0.4.0",
                      "product_id": "P-2245V-4.4.0.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.4.0.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.5.0.0.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.5.0.0.0",
                      "product_id": "P-2245V-4.5.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.5.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.5.0.1.1",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.5.0.1.1",
                      "product_id": "P-2245V-4.5.0.1.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.5.0.1.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.5.0.1.3",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.5.0.1.3",
                      "product_id": "P-2245V-4.5.0.1.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.5.0.1.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.5.0.2.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.5.0.2.0",
                      "product_id": "P-2245V-4.5.0.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.5.0.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Utilities Application Framework"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Network Management System Version 2.5.0.1.16",
                    "product": {
                      "name": "Oracle Utilities Network Management System Version 2.5.0.1.16",
                      "product_id": "P-2241V-2.5.0.1.16",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.5.0.1.16:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Network Management System Version 2.5.0.2.10",
                    "product": {
                      "name": "Oracle Utilities Network Management System Version 2.5.0.2.10",
                      "product_id": "P-2241V-2.5.0.2.10",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.5.0.2.10:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Network Management System Version 2.6.0.1.9",
                    "product": {
                      "name": "Oracle Utilities Network Management System Version 2.6.0.1.9",
                      "product_id": "P-2241V-2.6.0.1.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.6.0.1.9:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Network Management System Version 2.6.0.2.5",
                    "product": {
                      "name": "Oracle Utilities Network Management System Version 2.6.0.2.5",
                      "product_id": "P-2241V-2.6.0.2.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.6.0.2.5:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Utilities Network Management System"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Testing Accelerator Version 25.4.0.0.1",
                    "product": {
                      "name": "Oracle Utilities Testing Accelerator Version 25.4.0.0.1",
                      "product_id": "P-13784V-25.4.0.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_testing_accelerator:25.4.0.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Testing Accelerator Version 7.0.0.0.6",
                    "product": {
                      "name": "Oracle Utilities Testing Accelerator Version 7.0.0.0.6",
                      "product_id": "P-13784V-7.0.0.0.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_testing_accelerator:7.0.0.0.6:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Testing Accelerator Version 7.0.0.1.4",
                    "product": {
                      "name": "Oracle Utilities Testing Accelerator Version 7.0.0.1.4",
                      "product_id": "P-13784V-7.0.0.1.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_testing_accelerator:7.0.0.1.4:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Utilities Testing Accelerator"
              }
            ],
            "category": "product_family",
            "name": "Oracle Utilities Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle VM VirtualBox Version 7.1.14",
                    "product": {
                      "name": "Oracle VM VirtualBox Version 7.1.14",
                      "product_id": "P-8370V-7.1.14",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:vm_virtualbox:7.1.14:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle VM VirtualBox Version 7.2.4",
                    "product": {
                      "name": "Oracle VM VirtualBox Version 7.2.4",
                      "product_id": "P-8370V-7.2.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:vm_virtualbox:7.2.4:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle VM VirtualBox"
              }
            ],
            "category": "product_family",
            "name": "Oracle Virtualization"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Zero Data Loss Recovery Appliance Software Version 23.1.0-23.1.202509",
                    "product": {
                      "name": "Oracle Zero Data Loss Recovery Appliance Software Version 23.1.0-23.1.202509",
                      "product_id": "P-11342V-23.1.0-23.1.202509",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:zero_data_loss_recovery_appliance_software:23.1.0-23.1.202509:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Zero Data Loss Recovery Appliance Software"
              }
            ],
            "category": "product_family",
            "name": "Oracle Zero Data Loss Recovery Appliance"
          }
        ],
        "category": "vendor",
        "name": "Oracle"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2018-1000632",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "38438609"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface (JDOM)).  Supported versions that are affected are 17.0-25.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9019V-17.0-25.11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-17.0-25.11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU44"
        }
      ]
    },
    {
      "cve": "CVE-2020-10683",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "38438609"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface (JDOM)).  Supported versions that are affected are 17.0-25.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9019V-17.0-25.11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-17.0-25.11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU44"
        }
      ]
    },
    {
      "cve": "CVE-2021-23926",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "38597844"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Core (Apache XMLBeans)).   The supported version that is affected is 8.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2025V-8.2.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1314"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2025V-8.2.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-33813",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "38438609"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface (JDOM)).  Supported versions that are affected are 17.0-25.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9019V-17.0-25.11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-17.0-25.11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU44"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9019V-17.0-25.11"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-43113",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Primavera Unifier",
          "text": "38646847"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Reports (iTextPDF)).  Supported versions that are affected are 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.12 and  25.12.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in takeover of Primavera Unifier. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10354V-22.12.0-22.12.15",
          "P-10354V-23.12.0-23.12.16",
          "P-10354V-24.12.0-24.12.12",
          "P-10354V-25.12.0",
          "P-10354V-21.12.0-21.12.17"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10354V-22.12.0-22.12.15",
            "P-10354V-23.12.0-23.12.16",
            "P-10354V-24.12.0-24.12.12",
            "P-10354V-21.12.0-21.12.17",
            "P-10354V-25.12.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU30"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10354V-22.12.0-22.12.15",
            "P-10354V-23.12.0-23.12.16",
            "P-10354V-24.12.0-24.12.12",
            "P-10354V-21.12.0-21.12.17",
            "P-10354V-25.12.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-45105",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
          "text": "38711159"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Core (Apache Log4j)).   The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9617V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9617V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9617V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-23395",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "38545166"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface (jquery-cookie)).  Supported versions that are affected are 17.0-25.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM Deployment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data as well as  unauthorized read access to a subset of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9019V-17.0-25.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-17.0-25.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU44"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9019V-17.0-25.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-40196",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Weblogic Server Proxy Plug-in",
          "text": "37616953"
        },
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "36273564"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Access Manager",
          "text": "37427092"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (Intel C++ Compiler Classic)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server.  Note: Applies to LINUX only.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Oracle Weblogic Server Proxy Plug-in for Apache HTTP Server (Intel C++ Compiler Classic)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Weblogic Server Proxy Plug-in executes to compromise Oracle Weblogic Server Proxy Plug-in.  Successful attacks of this vulnerability can result in takeover of Oracle Weblogic Server Proxy Plug-in.  Note: Applies to LINUX only.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Webserver Plugin (Intel C++ Compiler Classic)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Access Manager executes to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1042(Oracle Weblogic Server Proxy Plug-in for Apache HTTP Server)V-14.1.1.0.0",
          "P-1042(Oracle Weblogic Server Proxy Plug-in for Apache HTTP Server)V-12.2.1.4.0",
          "P-1042(Core)V-12.2.1.4.0",
          "P-5565V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Oracle Weblogic Server Proxy Plug-in for Apache HTTP Server)V-14.1.1.0.0",
            "P-1042(Oracle Weblogic Server Proxy Plug-in for Apache HTTP Server)V-12.2.1.4.0",
            "P-1042(Core)V-12.2.1.4.0",
            "P-5565V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ]
    },
    {
      "cve": "CVE-2022-41342",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Fusion Middleware",
          "text": "37564963"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Weblogic Server Proxy Plug-in",
          "text": "37616953"
        },
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "36273564"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Access Manager",
          "text": "37427092"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (Intel C++ Compiler Classic)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server.  Note: Applies to LINUX only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Webserver Plugin (Intel C++ Compiler Classic)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Access Manager executes to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Oracle Weblogic Server Proxy Plug-in for Apache HTTP Server (Intel C++ Compiler Classic)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Weblogic Server Proxy Plug-in executes to compromise Oracle Weblogic Server Proxy Plug-in.  Successful attacks of this vulnerability can result in takeover of Oracle Weblogic Server Proxy Plug-in.  Note: Applies to LINUX only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle Fusion Middleware (component: Dynamic Monitoring Service, Oracle Notification Service, libiau (Intel C++ Compiler Classic)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Fusion Middleware executes to compromise Oracle Fusion Middleware.  Successful attacks of this vulnerability can result in takeover of Oracle Fusion Middleware.  Note: Applies to LINUX only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1032V-12.2.1.4.0",
          "P-1042(Oracle Weblogic Server Proxy Plug-in for Apache HTTP Server)V-14.1.1.0.0",
          "P-1042(Oracle Weblogic Server Proxy Plug-in for Apache HTTP Server)V-12.2.1.4.0",
          "P-1042(Core)V-12.2.1.4.0",
          "P-5565V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Oracle Weblogic Server Proxy Plug-in for Apache HTTP Server)V-14.1.1.0.0",
            "P-1042(Oracle Weblogic Server Proxy Plug-in for Apache HTTP Server)V-12.2.1.4.0",
            "P-1042(Core)V-12.2.1.4.0",
            "P-1032V-12.2.1.4.0",
            "P-5565V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-1042(Oracle Weblogic Server Proxy Plug-in for Apache HTTP Server)V-14.1.1.0.0",
            "P-1042(Oracle Weblogic Server Proxy Plug-in for Apache HTTP Server)V-12.2.1.4.0",
            "P-1042(Core)V-12.2.1.4.0",
            "P-1032V-12.2.1.4.0",
            "P-5565V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-45047",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "38597913"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Core (Apache Mina SSHD)).   The supported version that is affected is 8.2.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via SSH to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2025V-8.2.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1314"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2025V-8.2.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-1393",
      "ids": [
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "38173895"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (X.Org Server)).  Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4781V-9.2.0.0-9.2.9.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU45"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-29081",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Life Sciences Central Coding",
          "text": "36303636"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Life Sciences Central Coding product of Oracle Health Sciences Applications (component: Installation and Configuration (InstallShield)).   The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Life Sciences Central Coding executes to compromise Oracle Life Sciences Central Coding.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Life Sciences Central Coding. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9644V-7.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9644V-7.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU33"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9644V-7.0.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-4091",
      "ids": [
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "38173841"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Samba)).  Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4781V-9.2.0.0-9.2.9.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU45"
        }
      ]
    },
    {
      "cve": "CVE-2023-4154",
      "ids": [
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "38173841"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Samba)).  Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4781V-9.2.0.0-9.2.9.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU45"
        }
      ]
    },
    {
      "cve": "CVE-2023-42669",
      "ids": [
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "38173841"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Samba)).  Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4781V-9.2.0.0-9.2.9.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU45"
        }
      ]
    },
    {
      "cve": "CVE-2023-42670",
      "ids": [
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "38173841"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Samba)).  Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4781V-9.2.0.0-9.2.9.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU45"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-6378",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-10945V-23.8.0-23.9.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Studio",
          "text": "38549323"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Studio product of Oracle GoldenGate (component: OGG Orchestration Service (logback)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-10945V-23.8.0-23.9.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10945V-23.8.0-23.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10945V-23.8.0-23.9.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-10945V-23.8.0-23.9.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-12133",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37847520"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Libtasn1)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-13009",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
          "text": "37664955"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
          "text": "38250468"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
          "text": "38287480"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Unified Directory",
          "text": "38073622"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Eclipse Jetty)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  While the vulnerability is in Oracle Middleware Common Libraries and Tools, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Middleware Common Libraries and Tools accessible data as well as  unauthorized read access to a subset of Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Oracle Enterprise Manager Base Platform - Agent Next Gen (Eclipse Jetty)).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform.  While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Gateway (Eclipse Jetty)).   The supported version that is affected is 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform.  While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: Core (Eclipse Jetty)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Unified Directory.  While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Unified Directory accessible data as well as  unauthorized read access to a subset of Oracle Unified Directory accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1370(Gateway)V-24.1",
          "P-4647V-14.1.2.0.0",
          "P-1370(Oracle Enterprise Manager Base Platform - Agent Next Gen)V-24.1",
          "P-9118V-12.2.1.4.0",
          "P-1370(Oracle Enterprise Manager Base Platform - Agent Next Gen)V-13.5",
          "P-9118V-14.1.2.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4647V-14.1.2.0.0",
            "P-9118V-12.2.1.4.0",
            "P-9118V-14.1.2.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1370(Gateway)V-24.1",
            "P-1370(Oracle Enterprise Manager Base Platform - Agent Next Gen)V-24.1",
            "P-1370(Oracle Enterprise Manager Base Platform - Agent Next Gen)V-13.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU6"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1370(Gateway)V-24.1",
            "P-4647V-14.1.2.0.0",
            "P-1370(Oracle Enterprise Manager Base Platform - Agent Next Gen)V-24.1",
            "P-9118V-12.2.1.4.0",
            "P-1370(Oracle Enterprise Manager Base Platform - Agent Next Gen)V-13.5",
            "P-9118V-14.1.2.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-23337",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Cloud Native Session Border Controller",
          "text": "38352625"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Cloud Native Session Border Controller product of Oracle Communications (component: Third Party (jq)).   The supported version that is affected is 25.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Cloud Native Session Border Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Cloud Native Session Border Controller.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14762V-25.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14762V-25.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU43"
        }
      ]
    },
    {
      "cve": "CVE-2024-23807",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Integration",
          "text": "30149144"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI (Apache Xerces-C++)).  Supported versions that are affected are 17.0-25.9. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9008V-17.0-25.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9008V-17.0-25.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU44"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9008V-17.0-25.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-30171",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-2025V-7.6.0.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "38634559"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security (Bouncy Castle Java Library)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-2025V-7.6.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-7.6.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1314"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-2025V-7.6.0.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-2025V-7.6.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-31141",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "38410879"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface (Apache Log4j)).  Supported versions that are affected are 17.0-25.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9019V-17.0-25.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-17.0-25.10"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU44"
        }
      ]
    },
    {
      "cve": "CVE-2024-35195",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.11"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Stream Analytics",
          "text": "37182654"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Stream Analytics product of Oracle GoldenGate (component: General (Requests)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-14015V-19.1.0.0.0-19.1.0.0.11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14015V-19.1.0.0.0-19.1.0.0.11"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.11"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-42516",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "38257292"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (Apache HTTP Server)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1042(Core)V-12.2.1.4.0",
          "P-1042(Core)V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Core)V-12.2.1.4.0",
            "P-1042(Core)V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1042(Core)V-12.2.1.4.0",
            "P-1042(Core)V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-43204",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "38255470"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_proxy (Apache HTTP Server)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1042(mod_proxy)V-14.1.2.0.0",
          "P-1042(mod_proxy)V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(mod_proxy)V-12.2.1.4.0",
            "P-1042(mod_proxy)V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1042(mod_proxy)V-12.2.1.4.0",
            "P-1042(mod_proxy)V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-43796",
      "ids": [
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "37723872"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Express.js)).  Supported versions that are affected are 9.2.0.0-9.2.9.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4781V-9.2.0.0-9.2.9.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU45"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-45720",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38311415"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Subversion)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        }
      ]
    },
    {
      "cve": "CVE-2024-46901",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38311415"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Subversion)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-47252",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "38543389"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL module (Apache HTTP Server)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1042(SSL module)V-14.1.2.0.0",
          "P-1042(SSL module)V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(SSL module)V-14.1.2.0.0",
            "P-1042(SSL module)V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1042(SSL module)V-14.1.2.0.0",
            "P-1042(SSL module)V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-47554",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5760V-21.3-21.14"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
          "text": "36725517"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Health Sciences Information Manager",
          "text": "37477115"
        },
        {
          "system_name": "Oracle Bug ID of Oracle WebLogic Server",
          "text": "38593169"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Apache Commons IO)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console (Apache Commons IO)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Health Sciences Information Manager product of Oracle HealthCare Applications (component: Install (Apache Commons IO)).   The supported version that is affected is 4.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences Information Manager.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Health Sciences Information Manager. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5242V-12.2.1.4.0",
          "P-9177V-4.0.0",
          "P-5242V-14.1.1.0.0"
        ],
        "known_not_affected": [
          "P-5760V-21.3-21.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5760V-21.3-21.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9177V-4.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU52"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5760V-21.3-21.14"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-9177V-4.0.0",
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5760V-21.3-21.14"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-51504",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-2241V-2.5.0.1.16",
            "P-2241V-2.6.0.1.9",
            "P-2241V-2.5.0.2.10"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
          "text": "38237936"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Core (Apache ZooKeeper)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-2241V-2.5.0.2.10",
          "P-2241V-2.5.0.1.16",
          "P-2241V-2.6.0.1.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2241V-2.5.0.1.16",
            "P-2241V-2.6.0.1.9",
            "P-2241V-2.5.0.2.10"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU31"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-2241V-2.5.0.1.16",
            "P-2241V-2.6.0.1.9",
            "P-2241V-2.5.0.2.10"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-2241V-2.5.0.1.16",
            "P-2241V-2.6.0.1.9",
            "P-2241V-2.5.0.2.10"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-52046",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Health Sciences Information Manager",
          "text": "37444790"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Health Sciences Information Manager product of Oracle HealthCare Applications (component: XAD-PID Change Management XPID (Apache Mina)).   The supported version that is affected is 4.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Health Sciences Information Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Health Sciences Information Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9177V-4.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9177V-4.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU52"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9177V-4.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-56406",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Fusion Middleware",
          "text": "37889127"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Fusion Middleware (component: Third Party (Perl)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Fusion Middleware.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Fusion Middleware as well as  unauthorized update, insert or delete access to some of Oracle Fusion Middleware accessible data and  unauthorized read access to a subset of Oracle Fusion Middleware accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1032V-12.2.1.4.0",
          "P-1032V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1032V-12.2.1.4.0",
            "P-1032V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.6,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "P-1032V-12.2.1.4.0",
            "P-1032V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-57699",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "38177006"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (json-smart)).  Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2025V-7.6.0.0.0",
          "P-2025V-8.2.0.0.0",
          "P-2025V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-12.2.1.4.0",
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1314"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2025V-12.2.1.4.0",
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-6763",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
          "text": "37664955"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Eclipse Jetty)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  While the vulnerability is in Oracle Middleware Common Libraries and Tools, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Middleware Common Libraries and Tools accessible data as well as  unauthorized read access to a subset of Oracle Middleware Common Libraries and Tools accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4647V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4647V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ]
    },
    {
      "cve": "CVE-2025-10148",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
          "text": "38448041"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Enterprise Backup",
          "text": "38448033"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38448069"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Enterprise Backup product of Oracle MySQL (component: Enterprise Backup (curl)).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Enterprise Backup.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Enterprise Backup.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: File Processing (curl)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: MDEX, Forge (curl)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4629V-8.0.0-8.0.43",
          "P-4629V-8.4.0-8.4.6",
          "P-9633(MDEX, Forge)V-11.4.0",
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-4629V-9.0.0-9.4.0",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4629V-8.0.0-8.0.43",
            "P-4629V-8.4.0-8.4.6",
            "P-4629V-9.0.0-9.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU47"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633(MDEX, Forge)V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU49"
        }
      ]
    },
    {
      "cve": "CVE-2025-10911",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38199561"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (libxslt)).  Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u471-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u471-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU41"
        }
      ]
    },
    {
      "cve": "CVE-2025-12183",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle JDK Mission Control",
          "text": "38755146"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle JDK Mission Control product of Oracle Java SE (component: Mission Control (lz4-java)).   The supported version that is affected is Oracle JDK Mission Control: 9.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle JDK Mission Control.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle JDK Mission Control accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle JDK Mission Control. CVSS 3.1 Base Score 5.4 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V- 9.1.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V- 9.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU41"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-856V- 9.1.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-12383",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38685366"
        },
        {
          "system_name": "Oracle Bug ID of Oracle WebLogic Server",
          "text": "38687100"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Global Lifecycle Management NextGen OUI Framework",
          "text": "38687354"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Fleet Patching and Provisioning (Eclipse Jersey) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Fleet Patching and Provisioning (Eclipse Jersey).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Fleet Patching and Provisioning (Eclipse Jersey) accessible data as well as  unauthorized access to critical data or complete access to all Fleet Patching and Provisioning (Eclipse Jersey) accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Third Party Jars (Eclipse Jersey)).  Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer (Eclipse Jersey)).  Supported versions that are affected are 15.1.1.0.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Global Lifecycle Management NextGen OUI Framework.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Global Lifecycle Management NextGen OUI Framework accessible data as well as  unauthorized access to critical data or complete access to all Oracle Global Lifecycle Management NextGen OUI Framework accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5242V-15.1.1.0.0",
          "P-5242V-14.1.2.0.0",
          "P-12738V-15.1.1.0.0",
          "P-5242V-14.1.1.0.0",
          "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-15.1.1.0.0",
            "P-5242V-14.1.1.0.0",
            "P-5242V-14.1.2.0.0",
            "P-12738V-15.1.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5242V-15.1.1.0.0",
            "P-5242V-14.1.1.0.0",
            "P-5242V-14.1.2.0.0",
            "P-12738V-15.1.1.0.0",
            "P-5(Fleet Patching and Provisioning)V-23.4.0-23.26.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-12816",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38737823"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (node-forge)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        }
      ]
    },
    {
      "cve": "CVE-2025-13836",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38496873"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the RDBMS (Python) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.20 and  23.4.0-23.26.0. Easily exploitable vulnerability allows high privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS (Python) executes to compromise RDBMS (Python).  Successful attacks of this vulnerability can result in takeover of RDBMS (Python).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(RDBMS)V-21.3-21.20",
          "P-5(RDBMS)V-23.4.0-23.26.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.20",
            "P-5(RDBMS)V-23.4.0-23.26.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ]
    },
    {
      "cve": "CVE-2025-13837",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38496873"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the RDBMS (Python) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.20 and  23.4.0-23.26.0. Easily exploitable vulnerability allows high privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS (Python) executes to compromise RDBMS (Python).  Successful attacks of this vulnerability can result in takeover of RDBMS (Python).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(RDBMS)V-21.3-21.20",
          "P-5(RDBMS)V-23.4.0-23.26.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.20",
            "P-5(RDBMS)V-23.4.0-23.26.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ]
    },
    {
      "cve": "CVE-2025-22228",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
          "text": "38592883"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common Core (Spring Security)).   The supported version that is affected is 14.5.0.14.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Liquidity Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Banking Liquidity Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13304V-14.5.0.14.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13304V-14.5.0.14.0"
          ],
          "url": "https://support.oracle.com"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-13304V-14.5.0.14.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-22233",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
          "text": "38661372"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security (Spring Framework)).   The supported version that is affected is 15.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications BRM - Elastic Charging Engine accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9742V-15.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9742V-15.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU12"
        }
      ]
    },
    {
      "cve": "CVE-2025-23048",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "38255749"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (Apache HTTP Server)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data as well as  unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1042(SSL Module)V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(SSL Module)V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1042(SSL Module)V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-23084",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38231271"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards (Node.js)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU47"
        }
      ]
    },
    {
      "cve": "CVE-2025-25193",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
          "text": "38497047"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security (Netty)).  Supported versions that are affected are 15.0.0.0 and  15.0.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications BRM - Elastic Charging Engine executes to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications BRM - Elastic Charging Engine. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9742V-15.0.0.0",
          "P-9742V-15.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9742V-15.0.0.0",
            "P-9742V-15.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU12"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9742V-15.0.0.0",
            "P-9742V-15.0.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-26333",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5757V-19.1.0.0.0-19.29.0.0.251021",
            "P-1870V-22.1.1.1.0-22.1.1.35.0",
            "P-5757V-23.4-23.10",
            "P-5757V-21.3-21.20"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle TimesTen In-Memory Database",
          "text": "38540171"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Security Service",
          "text": "38377882"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate",
          "text": "38540147"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Predictive Application Server",
          "text": "38540166"
        },
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "38540122"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
          "text": "38540165"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
          "text": "38540167"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
          "text": "38540134"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Fusion Middleware",
          "text": "38796805"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle GoldenGate (component: Libraries (BSAFE Crypto-J)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (BSAFE Crypto-J)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Integration Bus accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Predictive Application Server product of Oracle Retail Applications (component: RPAS Server (BSAFE Crypto-J)).   The supported version that is affected is 15.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Predictive Application Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Predictive Application Server accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (BSAFE Crypto-J)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Service Backbone accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle TimesTen In-Memory Database (component: Install (BSAFE Crypto-J)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle Fusion Middleware (component: Oracle Database Client for Fusion Middleware (BSAFE Crypto-J)).   The supported version that is affected is 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Fusion Middleware.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Fusion Middleware accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: Third Party (BSAFE Crypto-J)).   The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Security Service.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Security Service accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (BSAFE Crypto-J)).  Supported versions that are affected are 9.2.0.0-9.2.9.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications (component: Platform (BSAFE Crypto-J)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0 and  15.1.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2136(Platform)V-15.1.0.0.0",
          "P-1823V-15.0.3",
          "P-10867V-16.0.3",
          "P-1807V-19.0.1",
          "P-991V-12.2.1.4.0",
          "P-2136(Platform)V-15.0.1.0.0",
          "P-1032V-14.1.2.0.0",
          "P-10867V-19.0.1",
          "P-2136(Platform)V-15.0.0.0.0",
          "P-4781V-9.2.0.0-9.2.9.4",
          "P-1807V-16.0.3"
        ],
        "known_not_affected": [
          "P-5757V-19.1.0.0.0-19.29.0.0.251021",
          "P-1870V-22.1.1.1.0-22.1.1.35.0",
          "P-5757V-23.4-23.10",
          "P-5757V-21.3-21.20"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5757V-19.1.0.0.0-19.29.0.0.251021",
            "P-1870V-22.1.1.1.0-22.1.1.35.0",
            "P-5757V-23.4-23.10",
            "P-5757V-21.3-21.20"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1823V-15.0.3",
            "P-10867V-16.0.3",
            "P-1807V-19.0.1",
            "P-10867V-19.0.1",
            "P-1807V-16.0.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU16"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-991V-12.2.1.4.0",
            "P-1032V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU45"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2136(Platform)V-15.1.0.0.0",
            "P-2136(Platform)V-15.0.1.0.0",
            "P-2136(Platform)V-15.0.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU8"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5757V-19.1.0.0.0-19.29.0.0.251021",
            "P-5757V-23.4-23.10",
            "P-5757V-21.3-21.20"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-2136(Platform)V-15.1.0.0.0",
            "P-1823V-15.0.3",
            "P-10867V-16.0.3",
            "P-1807V-19.0.1",
            "P-991V-12.2.1.4.0",
            "P-2136(Platform)V-15.0.1.0.0",
            "P-1032V-14.1.2.0.0",
            "P-10867V-19.0.1",
            "P-2136(Platform)V-15.0.0.0.0",
            "P-4781V-9.2.0.0-9.2.9.4",
            "P-1807V-16.0.3"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1870V-22.1.1.1.0-22.1.1.35.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5757V-19.1.0.0.0-19.29.0.0.251021",
            "P-1870V-22.1.1.1.0-22.1.1.35.0",
            "P-5757V-23.4-23.10",
            "P-5757V-21.3-21.20"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-26791",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Primavera P6 Enterprise Project Portfolio Management",
          "text": "37932475"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Team Member (DOMPurify)).  Supported versions that are affected are 21.12.0.0-21.12.21.5, 22.12.0.0-22.12.20.0, 23.12.0.0-23.12.17.0 and    24.12.0.0-24.12.11.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Primavera P6 Enterprise Project Portfolio Management executes to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.1 Base Score 3.9 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5579V-23.12.0.0-23.12.17.0",
          "P-5579V-22.12.0.0-22.12.20.0",
          "P-5579V-24.12.0.0-24.12.11.0",
          "P-5579V-21.12.0.0-21.12.21.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5579V-23.12.0.0-23.12.17.0",
            "P-5579V-22.12.0.0-22.12.20.0",
            "P-5579V-24.12.0.0-24.12.11.0",
            "P-5579V-21.12.0.0-21.12.21.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU30"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.9,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5579V-23.12.0.0-23.12.17.0",
            "P-5579V-22.12.0.0-22.12.20.0",
            "P-5579V-24.12.0.0-24.12.11.0",
            "P-5579V-21.12.0.0-21.12.21.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27152",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5757V-23.4-23.10",
            "P-5757V-21.3-21.20"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate",
          "text": "38695224"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle GoldenGate (component: Embedded Web UI for Services (Axios)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5757V-23.4-23.10",
          "P-5757V-21.3-21.20"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5757V-23.4-23.10",
            "P-5757V-21.3-21.20"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5757V-23.4-23.10",
            "P-5757V-21.3-21.20"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5757V-23.4-23.10",
            "P-5757V-21.3-21.20"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27209",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38231271"
        },
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "38231245"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Node.js)).  Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards (Node.js)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-4781V-9.2.0.0-9.2.9.4",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU45"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU47"
        }
      ]
    },
    {
      "cve": "CVE-2025-27210",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38231271"
        },
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "38231245"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (Node.js)).  Supported versions that are affected are 9.2.0.0-9.2.9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards (Node.js)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-4781V-9.2.0.0-9.2.9.4",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU45"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU47"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-4781V-9.2.0.0-9.2.9.4",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27363",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Financial Reporting",
          "text": "37735469"
        },
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "37735415"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud (FreeType)).  Supported versions that are affected are 9.2.0.0-9.2.9.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Install (FreeType)).   The supported version that is affected is 11.2.23. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4781V-9.2.0.0-9.2.9.4",
          "P-8776V-11.2.23"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU45"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8776V-11.2.23"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA812"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8776V-11.2.23",
            "P-4781V-9.2.0.0-9.2.9.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27533",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Element Manager",
          "text": "38268766"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
          "text": "38268767"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Third Party (Apache ActiveMQ)).  Supported versions that are affected are 9.0.0-9.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Element Manager. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: Third Party (Apache ActiveMQ)).  Supported versions that are affected are 9.0.0-9.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Report Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11052V-9.0.0-9.0.4",
          "P-10770V-9.0.0-9.0.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11052V-9.0.0-9.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863845"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10770V-9.0.0-9.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863846"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10770V-9.0.0-9.0.4",
            "P-11052V-9.0.0-9.0.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27817",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "38410879"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
          "text": "38128811"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Cash Management",
          "text": "38128804"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Cash Management product of Oracle Financial Services Applications (component: Accessibility (Apache Kafka)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Cash Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Banking Cash Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common Core (Apache Kafka)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Banking Liquidity Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface (Apache Log4j)).  Supported versions that are affected are 17.0-25.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14195V-14.5.0.15.0",
          "P-14195V-14.8.1.0.0",
          "P-13304V-14.7.0.9.0",
          "P-9019V-17.0-25.10",
          "P-13304V-14.8.0.1.0",
          "P-14195V-14.8.0.1.0",
          "P-13304V-14.5.0.15.0",
          "P-14195V-14.6.0.11.0",
          "P-14195V-14.7.0.9.0",
          "P-13304V-14.8.1.0.0",
          "P-13304V-14.6.0.11.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14195V-14.5.0.15.0",
            "P-14195V-14.8.1.0.0",
            "P-13304V-14.7.0.9.0",
            "P-13304V-14.8.0.1.0",
            "P-14195V-14.8.0.1.0",
            "P-13304V-14.5.0.15.0",
            "P-14195V-14.6.0.11.0",
            "P-14195V-14.7.0.9.0",
            "P-13304V-14.8.1.0.0",
            "P-13304V-14.6.0.11.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-17.0-25.10"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU44"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14195V-14.5.0.15.0",
            "P-14195V-14.8.1.0.0",
            "P-13304V-14.7.0.9.0",
            "P-9019V-17.0-25.10",
            "P-13304V-14.8.0.1.0",
            "P-14195V-14.8.0.1.0",
            "P-13304V-14.5.0.15.0",
            "P-14195V-14.6.0.11.0",
            "P-14195V-14.7.0.9.0",
            "P-13304V-14.8.1.0.0",
            "P-13304V-14.6.0.11.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27818",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
          "text": "38128811"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Cash Management",
          "text": "38128804"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Cash Management product of Oracle Financial Services Applications (component: Accessibility (Apache Kafka)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Cash Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Banking Cash Management accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common Core (Apache Kafka)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Banking Liquidity Management accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14195V-14.5.0.15.0",
          "P-14195V-14.8.1.0.0",
          "P-13304V-14.7.0.9.0",
          "P-13304V-14.8.0.1.0",
          "P-14195V-14.8.0.1.0",
          "P-13304V-14.5.0.15.0",
          "P-14195V-14.6.0.11.0",
          "P-14195V-14.7.0.9.0",
          "P-13304V-14.8.1.0.0",
          "P-13304V-14.6.0.11.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14195V-14.5.0.15.0",
            "P-14195V-14.8.1.0.0",
            "P-13304V-14.7.0.9.0",
            "P-13304V-14.8.0.1.0",
            "P-14195V-14.8.0.1.0",
            "P-13304V-14.5.0.15.0",
            "P-14195V-14.6.0.11.0",
            "P-14195V-14.7.0.9.0",
            "P-13304V-14.8.1.0.0",
            "P-13304V-14.6.0.11.0"
          ],
          "url": "https://support.oracle.com"
        }
      ]
    },
    {
      "cve": "CVE-2025-30065",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle NoSQL Database",
          "text": "37810341"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle NoSQL Database (component: Administration (Apache Parquet Java)).  Supported versions that are affected are 1.5 and  1.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle NoSQL Database executes to compromise Oracle NoSQL Database.  Successful attacks of this vulnerability can result in takeover of Oracle NoSQL Database. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13373V-1.6",
          "P-13373V-1.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13373V-1.6",
            "P-13373V-1.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.0,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13373V-1.6",
            "P-13373V-1.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-31672",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "38176485"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
          "text": "37899545"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Agile PLM",
          "text": "37896705"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Fusion Middleware",
          "text": "38796698"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Document Management (Apache POI)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache POI)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Apache POI)).  Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle Fusion Middleware (component: Oracle Database Client for Fusion Middleware (Apache POI)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Fusion Middleware.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Fusion Middleware accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2025V-12.2.1.4.0",
          "P-4647V-14.1.2.0.0",
          "P-4461V-9.3.6",
          "P-4647V-12.2.1.4.0",
          "P-2025V-7.6.0.0.0",
          "P-2025V-8.2.0.0.0",
          "P-1032V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4461V-9.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU46"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4647V-14.1.2.0.0",
            "P-4647V-12.2.1.4.0",
            "P-1032V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-12.2.1.4.0",
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1314"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4647V-14.1.2.0.0",
            "P-4461V-9.3.6",
            "P-4647V-12.2.1.4.0",
            "P-1032V-14.1.2.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-2025V-12.2.1.4.0",
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-32988",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38206356"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Cloud Native Session Border Controller",
          "text": "37656527"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38206358"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Cloud Native Session Border Controller product of Oracle Communications (component: Third Party (GnuTLS)).   The supported version that is affected is 25.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Cloud Native Session Border Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Cloud Native Session Border Controller as well as  unauthorized update, insert or delete access to some of Oracle Cloud Native Session Border Controller accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (GnuTLS)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Policy Management as well as  unauthorized update, insert or delete access to some of Oracle Communications Policy Management accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Platform (GnuTLS)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director as well as  unauthorized update, insert or delete access to some of Oracle Communications Network Analytics Data Director accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-24.2.0-24.2.1",
          "P-14547V-24.3.0",
          "P-14547V-25.1.200",
          "P-10900V-15.0.0.0",
          "P-14547V-25.1.100",
          "P-14762V-25.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14762V-25.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU43"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863847"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14762V-25.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-32989",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38206356"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38206358"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Platform (GnuTLS)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director as well as  unauthorized update, insert or delete access to some of Oracle Communications Network Analytics Data Director accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (GnuTLS)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Policy Management as well as  unauthorized update, insert or delete access to some of Oracle Communications Policy Management accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-24.2.0-24.2.1",
          "P-14547V-24.3.0",
          "P-14547V-25.1.200",
          "P-14547V-25.1.100",
          "P-10900V-15.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863847"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        }
      ]
    },
    {
      "cve": "CVE-2025-32990",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38206356"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38206358"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Platform (GnuTLS)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director as well as  unauthorized update, insert or delete access to some of Oracle Communications Network Analytics Data Director accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (GnuTLS)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Policy Management as well as  unauthorized update, insert or delete access to some of Oracle Communications Policy Management accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-24.2.0-24.2.1",
          "P-14547V-24.3.0",
          "P-14547V-25.1.200",
          "P-14547V-25.1.100",
          "P-10900V-15.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863847"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-10900V-15.0.0.0",
            "P-14547V-24.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-41234",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
          "text": "38661372"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security (Spring Framework)).   The supported version that is affected is 15.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications BRM - Elastic Charging Engine accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9742V-15.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9742V-15.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU12"
        }
      ]
    },
    {
      "cve": "CVE-2025-41242",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Platform",
          "text": "38750069"
        },
        {
          "system_name": "Oracle Bug ID of Primavera Unifier",
          "text": "38482189"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
          "text": "38661372"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Integration (Spring Framework)).  Supported versions that are affected are 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.12 and  25.12.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Primavera Unifier accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security (Spring Framework)).   The supported version that is affected is 15.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications BRM - Elastic Charging Engine accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework (Spring Framework)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10354V-22.12.0-22.12.15",
          "P-9348V-11.4.0",
          "P-10354V-23.12.0-23.12.16",
          "P-10354V-24.12.0-24.12.12",
          "P-9742V-15.1.0.0",
          "P-10354V-25.12.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10354V-22.12.0-22.12.15",
            "P-10354V-23.12.0-23.12.16",
            "P-10354V-24.12.0-24.12.12",
            "P-10354V-25.12.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU30"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9742V-15.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU12"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9348V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU49"
        }
      ]
    },
    {
      "cve": "CVE-2025-41248",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
          "text": "38517117"
        },
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
          "text": "38517130"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Spring Security)).   The supported version that is affected is 8.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Model Management and Governance accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Core (Spring Security)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14276V-8.1.3.2",
          "P-9617V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14276V-8.1.3.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU50"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9617V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9617V-14.1.2.0.0",
            "P-14276V-8.1.3.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-41249",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-1479V-7.6.0.0.0",
            "P-1479V-8.2.0.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Integrity",
          "text": "38517491"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
          "text": "38034429"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Financial Integration",
          "text": "38517532"
        },
        {
          "system_name": "Oracle Bug ID of Primavera Unifier",
          "text": "38482189"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Identity Manager",
          "text": "38517522"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Bulk Data Integration",
          "text": "38517531"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Healthcare Master Person Index",
          "text": "38517520"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
          "text": "38661372"
        },
        {
          "system_name": "Oracle Bug ID of Oracle BI Publisher",
          "text": "38480861"
        },
        {
          "system_name": "Oracle Bug ID of Primavera Gateway",
          "text": "38517551"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
          "text": "38517538"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Platform",
          "text": "38750069"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
          "text": "38517506"
        },
        {
          "system_name": "Oracle Bug ID of Oracle WebLogic Server",
          "text": "38517548"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Predictive Application Server",
          "text": "38517537"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
          "text": "38517534"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
          "text": "38517479"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
          "text": "38517509"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Service Backbone accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core (Spring Framework)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Spring Framework)).  Supported versions that are affected are 21.12.0-21.12.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Primavera Gateway accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Security (Spring Framework)).   The supported version that is affected is 15.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications BRM - Elastic Charging Engine accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework (Spring Framework)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Platform accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Predictive Application Server product of Oracle Retail Applications (component: RPAS Client (Spring Framework)).  Supported versions that are affected are 15.0.3 and  16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Predictive Application Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Predictive Application Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Integration Bus accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Financial Integration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Bulk Data Integration product of Oracle Retail Applications (component: BDI Job Scheduler (Spring Framework)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Bulk Data Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Bulk Data Integration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Installer (Spring Framework)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Spring Framework)).   The supported version that is affected is 8.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Model Management and Governance accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Master Person Index product of Oracle HealthCare Applications (component: Master Index Data Manager (Spring Framework)).  Supported versions that are affected are 5.0.0.0-5.0.9.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Master Person Index.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Healthcare Master Person Index accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (Spring Framework)).   The supported version that is affected is 2.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Compliance Studio accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Integrity product of Oracle Communications (component: Platform, MSS Cartridge (Spring Framework)).  Supported versions that are affected are 7.3.6, 7.4.0 and  7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Integrity.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Network Integrity accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System, Workbench, Endeca Application Controller (Spring Framework)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Integration (Spring Framework)).  Supported versions that are affected are 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.12 and  25.12.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Primavera Unifier accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle BI Publisher product of Oracle Analytics (component: Development Operations (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Spring Framework)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10722V-19.0.1",
          "P-1980V-14.1.2.1.0",
          "P-1807V-19.0.1",
          "P-9633(Content Acquisition System, Workbench, Endeca Application Controller)V-11.4.0",
          "P-10354V-25.12.0",
          "P-1823V-15.0.3",
          "P-4491V-7.4.0",
          "P-1980V-12.2.1.4.0",
          "P-4491V-7.5.0",
          "P-9742V-15.1.0.0",
          "P-4491V-7.3.6",
          "P-5242V-12.2.1.4.0",
          "P-10867V-19.0.1",
          "P-14276V-8.1.3.2",
          "P-9348V-11.4.0",
          "P-14392V-2.6.0",
          "P-4647V-14.1.2.0.0",
          "P-12968V-19.0.1",
          "P-8575V-5.0.0.0-5.0.9.5",
          "P-5242V-14.1.2.0.0",
          "P-1823V-16.0.3",
          "P-10722V-16.0.3",
          "P-1807V-16.0.3",
          "P-5242V-15.1.1.0.0",
          "P-10354V-22.12.0-22.12.15",
          "P-10354V-23.12.0-23.12.16",
          "P-10605V-21.12.0-21.12.16",
          "P-10354V-24.12.0-24.12.12",
          "P-10867V-16.0.3",
          "P-5242V-14.1.1.0.0",
          "P-4647V-12.2.1.4.0",
          "P-12968V-16.0.3"
        ],
        "known_not_affected": [
          "P-1479V-8.2.0.0.0",
          "P-1479V-7.6.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10867V-16.0.3",
            "P-1823V-15.0.3",
            "P-10722V-19.0.1",
            "P-1807V-19.0.1",
            "P-12968V-19.0.1",
            "P-1823V-16.0.3",
            "P-10867V-19.0.1",
            "P-10722V-16.0.3",
            "P-1807V-16.0.3",
            "P-12968V-16.0.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU16"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-15.1.1.0.0",
            "P-1980V-14.1.2.1.0",
            "P-1980V-12.2.1.4.0",
            "P-5242V-14.1.1.0.0",
            "P-4647V-14.1.2.0.0",
            "P-4647V-12.2.1.4.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10354V-22.12.0-22.12.15",
            "P-10354V-23.12.0-23.12.16",
            "P-10605V-21.12.0-21.12.16",
            "P-10354V-24.12.0-24.12.12",
            "P-10354V-25.12.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU30"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9742V-15.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU12"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9348V-11.4.0",
            "P-9633(Content Acquisition System, Workbench, Endeca Application Controller)V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU49"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14276V-8.1.3.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU50"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8575V-5.0.0.0-5.0.9.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU52"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14392V-2.6.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863933"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4491V-7.4.0",
            "P-4491V-7.5.0",
            "P-4491V-7.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU10"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1479V-7.6.0.0.0",
            "P-1479V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1314"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10722V-19.0.1",
            "P-1980V-14.1.2.1.0",
            "P-1807V-19.0.1",
            "P-9633(Content Acquisition System, Workbench, Endeca Application Controller)V-11.4.0",
            "P-10354V-25.12.0",
            "P-1823V-15.0.3",
            "P-4491V-7.4.0",
            "P-1980V-12.2.1.4.0",
            "P-4491V-7.5.0",
            "P-9742V-15.1.0.0",
            "P-4491V-7.3.6",
            "P-5242V-12.2.1.4.0",
            "P-10867V-19.0.1",
            "P-14276V-8.1.3.2",
            "P-9348V-11.4.0",
            "P-14392V-2.6.0",
            "P-4647V-14.1.2.0.0",
            "P-12968V-19.0.1",
            "P-8575V-5.0.0.0-5.0.9.5",
            "P-5242V-14.1.2.0.0",
            "P-1823V-16.0.3",
            "P-10722V-16.0.3",
            "P-1807V-16.0.3",
            "P-5242V-15.1.1.0.0",
            "P-10354V-22.12.0-22.12.15",
            "P-10354V-23.12.0-23.12.16",
            "P-10605V-21.12.0-21.12.16",
            "P-10354V-24.12.0-24.12.12",
            "P-10867V-16.0.3",
            "P-5242V-14.1.1.0.0",
            "P-4647V-12.2.1.4.0",
            "P-12968V-16.0.3"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1479V-7.6.0.0.0",
            "P-1479V-8.2.0.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-1479V-7.6.0.0.0",
            "P-1479V-8.2.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-43272",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38512663"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)).  Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u471-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u471-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU41"
        }
      ]
    },
    {
      "cve": "CVE-2025-43342",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38512663"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)).  Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u471-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u471-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU41"
        }
      ]
    },
    {
      "cve": "CVE-2025-43356",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38512663"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)).  Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u471-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u471-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU41"
        }
      ]
    },
    {
      "cve": "CVE-2025-43368",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38512663"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (WebKitGTK)).  Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u471-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u471-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU41"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u471-b50"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-43966",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Financial Reporting",
          "text": "38577957"
        },
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
          "text": "38577960"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Install (libheif)).   The supported version that is affected is 11.2.23. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Reporting.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle (libheif)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Enterprise Capture.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8776V-11.2.23",
          "P-10212V-14.1.2.0.0",
          "P-10212V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8776V-11.2.23"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA812"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10212V-14.1.2.0.0",
            "P-10212V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ]
    },
    {
      "cve": "CVE-2025-43967",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Financial Reporting",
          "text": "38577957"
        },
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
          "text": "38577960"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Install (libheif)).   The supported version that is affected is 11.2.23. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle (libheif)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8776V-11.2.23",
          "P-10212V-14.1.2.0.0",
          "P-10212V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8776V-11.2.23"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA812"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10212V-14.1.2.0.0",
            "P-10212V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10212V-14.1.2.0.0",
            "P-10212V-12.2.1.4.0",
            "P-8776V-11.2.23"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-4575",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "38410909"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (OpenSSL)).  Supported versions that are affected are 17.0-25.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9019V-17.0-25.11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-17.0-25.11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU44"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-9019V-17.0-25.11"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-46727",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38577830"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Rack)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-46817",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
          "text": "38512733"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Infrastructure (valkey)).   The supported version that is affected is 5.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  While the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10761V-5.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10761V-5.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863848"
        }
      ]
    },
    {
      "cve": "CVE-2025-46818",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
          "text": "38512733"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Infrastructure (valkey)).   The supported version that is affected is 5.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  While the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10761V-5.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10761V-5.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863848"
        }
      ]
    },
    {
      "cve": "CVE-2025-46819",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
          "text": "38512733"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Infrastructure (valkey)).   The supported version that is affected is 5.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  While the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10761V-5.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10761V-5.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863848"
        }
      ]
    },
    {
      "cve": "CVE-2025-47183",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38360357"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (gstreamer)).  Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Java SE accessible data.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u471-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u471-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU41"
        }
      ]
    },
    {
      "cve": "CVE-2025-47219",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38360357"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (gstreamer)).  Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Java SE accessible data.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u471-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u471-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU41"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.1,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u471-b50"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-47910",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-1870V-22.1.1.1.0-22.1.1.35.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle TimesTen In-Memory Database",
          "text": "38470390"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle TimesTen In-Memory Database (component: Kubernetes Operator (Golang Go)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-1870V-22.1.1.1.0-22.1.1.35.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1870V-22.1.1.1.0-22.1.1.35.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1870V-22.1.1.1.0-22.1.1.35.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-1870V-22.1.1.1.0-22.1.1.35.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-47947",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "38543443"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_security (ModSecurity)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1042(mod_security)V-12.2.1.4.0",
          "P-1042(mod_security)V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(mod_security)V-12.2.1.4.0",
            "P-1042(mod_security)V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ]
    },
    {
      "cve": "CVE-2025-48060",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Cloud Native Session Border Controller",
          "text": "38352625"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Cloud Native Session Border Controller product of Oracle Communications (component: Third Party (jq)).   The supported version that is affected is 25.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Cloud Native Session Border Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Cloud Native Session Border Controller. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14762V-25.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14762V-25.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU43"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14762V-25.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-48734",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-10945V-23.8.0-23.9.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Banking Cash Management",
          "text": "38012205"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
          "text": "38012213"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Field Service",
          "text": "38648072"
        },
        {
          "system_name": "Oracle Bug ID of Primavera P6 Enterprise Project Portfolio Management",
          "text": "38012438"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Fiscal Management",
          "text": "38012373"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38012261"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Agile PLM",
          "text": "38012195"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Time and Labor",
          "text": "38700466"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Allocation",
          "text": "38012365"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Advanced Inventory Planning",
          "text": "38012363"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Human Resources",
          "text": "38648252"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Succession planning",
          "text": "38700399"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Studio",
          "text": "38745010"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Cash Management product of Oracle Financial Services Applications (component: Accessibility (Apache Commons BeanUtils)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Cash Management.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Cash Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common Core (Apache Commons BeanUtils)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (Apache Commons BeanUtils)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Advanced Inventory Planning product of Oracle Retail Applications (component: Operations and Maintenance (Apache Commons BeanUtils)).  Supported versions that are affected are 15.0.3 and  16.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Advanced Inventory Planning.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Advanced Inventory Planning. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Allocation product of Oracle Retail Applications (component: Security (Apache Commons BeanUtils)).  Supported versions that are affected are 15.0.3 and  16.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Allocation.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Allocation. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Fiscal Management product of Oracle Retail Applications (component: NF Issuing (Apache Commons BeanUtils)).   The supported version that is affected is 14.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Fiscal Management.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Fiscal Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access (Apache Commons BeanUtils)).  Supported versions that are affected are 21.12.0.0-21.12.21.5,   22.12.0.0-22.12.20.0,    23.12.0.0-23.12.17.0 and     24.12.0.0-24.12.6.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: HTML Dispatch Center (Apache Commons BeanUtils)).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service.  Successful attacks of this vulnerability can result in takeover of Oracle Field Service. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: iRecruitment (Apache Commons BeanUtils)).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Human Resources.  Successful attacks of this vulnerability can result in takeover of Oracle Human Resources. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Succession planning product of Oracle E-Business Suite (component: Suitability Analyzer (Apache Commons BeanUtils)).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Succession planning.  Successful attacks of this vulnerability can result in takeover of Oracle Succession planning. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Time and Labor product of Oracle E-Business Suite (component: Core (Apache Commons BeanUtils)).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Time and Labor.  Successful attacks of this vulnerability can result in takeover of Oracle Time and Labor. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Studio product of Oracle GoldenGate (component: OGG Orchestration Service (Apache Commons BeanUtils)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security (Apache Commons BeanUtils)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1786V-16.0.3",
          "P-5579V-24.12.0.0-24.12.6.0",
          "P-5579V-23.12.0.0-23.12.17.0",
          "P-13304V-14.5.0.15.0",
          "P-311V-12.2.3-12.2.15",
          "P-4461V-9.3.6",
          "P-14195V-14.6.0.11.0",
          "P-14195V-14.7.0.9.0",
          "P-5709V-12.2.3-12.2.15",
          "P-13304V-14.6.0.11.0",
          "P-5579V-21.12.0.0-21.12.21.5",
          "P-14195V-14.5.0.15.0",
          "P-14195V-14.8.1.0.0",
          "P-13304V-14.8.0.1.0",
          "P-10900V-15.0.0.0",
          "P-747V-12.2.3-12.2.15",
          "P-9038V-14.2",
          "P-13304V-14.8.1.0.0",
          "P-13304V-14.7.0.9.0",
          "P-14195V-14.8.0.1.0",
          "P-1785V-15.0.3",
          "P-5579V-22.12.0.0-22.12.20.0",
          "P-1786V-15.0.3",
          "P-1785V-16.0.3",
          "P-507V-12.2.3-12.2.15"
        ],
        "known_not_affected": [
          "P-10945V-23.8.0-23.9.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14195V-14.5.0.15.0",
            "P-14195V-14.8.1.0.0",
            "P-13304V-14.7.0.9.0",
            "P-13304V-14.8.0.1.0",
            "P-14195V-14.8.0.1.0",
            "P-13304V-14.5.0.15.0",
            "P-14195V-14.6.0.11.0",
            "P-14195V-14.7.0.9.0",
            "P-13304V-14.8.1.0.0",
            "P-13304V-14.6.0.11.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1785V-15.0.3",
            "P-1786V-15.0.3",
            "P-1786V-16.0.3",
            "P-9038V-14.2",
            "P-1785V-16.0.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU16"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5579V-23.12.0.0-23.12.17.0",
            "P-5579V-22.12.0.0-22.12.20.0",
            "P-5579V-24.12.0.0-24.12.6.0",
            "P-5579V-21.12.0.0-21.12.21.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU30"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-747V-12.2.3-12.2.15",
            "P-311V-12.2.3-12.2.15",
            "P-5709V-12.2.3-12.2.15",
            "P-507V-12.2.3-12.2.15"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA923"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10945V-23.8.0-23.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4461V-9.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU46"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14195V-14.5.0.15.0",
            "P-14195V-14.8.1.0.0",
            "P-13304V-14.8.0.1.0",
            "P-10900V-15.0.0.0",
            "P-747V-12.2.3-12.2.15",
            "P-1786V-16.0.3",
            "P-9038V-14.2",
            "P-13304V-14.8.1.0.0",
            "P-13304V-14.7.0.9.0",
            "P-14195V-14.8.0.1.0",
            "P-13304V-14.5.0.15.0",
            "P-1785V-15.0.3",
            "P-1786V-15.0.3",
            "P-311V-12.2.3-12.2.15",
            "P-4461V-9.3.6",
            "P-14195V-14.6.0.11.0",
            "P-14195V-14.7.0.9.0",
            "P-1785V-16.0.3",
            "P-5709V-12.2.3-12.2.15",
            "P-13304V-14.6.0.11.0",
            "P-507V-12.2.3-12.2.15"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5579V-23.12.0.0-23.12.17.0",
            "P-5579V-22.12.0.0-22.12.20.0",
            "P-5579V-24.12.0.0-24.12.6.0",
            "P-5579V-21.12.0.0-21.12.21.5"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10945V-23.8.0-23.9.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-10945V-23.8.0-23.9.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-4877",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38263975"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Pricing Design Center",
          "text": "38263977"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38263971"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Communications Broker",
          "text": "38594505"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38263978"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (libssh)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Policy Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Policy Management accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Security (libssh)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100, 25.1.200 and  25.2.100. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Network Analytics Data Director accessible data as well as  unauthorized read access to a subset of Oracle Communications Network Analytics Data Director accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment (libssh)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0 and  15.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Pricing Design Center accessible data as well as  unauthorized read access to a subset of Oracle Communications Pricing Design Center accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (libssh)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications (component: Routing (libssh)).  Supported versions that are affected are 4.2.0 and  5.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Enterprise Communications Broker.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Communications Broker.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-24.2.0-24.2.1",
          "P-14547V-25.1.200",
          "P-10758V-4.2.0",
          "P-10900V-15.0.0.0",
          "P-14547V-25.1.100",
          "P-14597V-6.1.0-6.1.1",
          "P-14547V-24.3.0",
          "P-10758V-5.0.0",
          "P-9437V-15.1.0.0.0",
          "P-14547V-25.2.100",
          "P-9437V-15.0.0.0.0",
          "P-9437V-15.0.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.2.100",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863847"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9437V-15.0.0.0.0",
            "P-9437V-15.0.1.0.0",
            "P-9437V-15.1.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU11"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10758V-4.2.0",
            "P-10758V-5.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU40"
        }
      ]
    },
    {
      "cve": "CVE-2025-4878",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38263975"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Pricing Design Center",
          "text": "38263977"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38263971"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Communications Broker",
          "text": "38594505"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38263978"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Security (libssh)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100, 25.1.200 and  25.2.100. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Network Analytics Data Director accessible data as well as  unauthorized read access to a subset of Oracle Communications Network Analytics Data Director accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (libssh)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications (component: Routing (libssh)).  Supported versions that are affected are 4.2.0 and  5.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Enterprise Communications Broker.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Communications Broker.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (libssh)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Policy Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Policy Management accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment (libssh)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0 and  15.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Pricing Design Center accessible data as well as  unauthorized read access to a subset of Oracle Communications Pricing Design Center accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-24.2.0-24.2.1",
          "P-14547V-25.1.200",
          "P-10758V-4.2.0",
          "P-14547V-25.1.100",
          "P-10900V-15.0.0.0",
          "P-14597V-6.1.0-6.1.1",
          "P-14547V-24.3.0",
          "P-10758V-5.0.0",
          "P-9437V-15.1.0.0.0",
          "P-14547V-25.2.100",
          "P-9437V-15.0.0.0.0",
          "P-9437V-15.0.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.2.100",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863847"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10758V-4.2.0",
            "P-10758V-5.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU40"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9437V-15.0.0.0.0",
            "P-9437V-15.0.1.0.0",
            "P-9437V-15.1.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU11"
        }
      ]
    },
    {
      "cve": "CVE-2025-48795",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
          "text": "38237586"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Cash Management",
          "text": "38237578"
        },
        {
          "system_name": "Oracle Bug ID of Primavera P6 Enterprise Project Portfolio Management",
          "text": "38237605"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Integrators (Apache CXF)).  Supported versions that are affected are 22.12.0.0-22.12.20.0, 23.12.0.0-23.12.17.0 and  24.12.0.0-24.12.11.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Primavera P6 Enterprise Project Portfolio Management. CVSS 3.1 Base Score 5.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Cash Management product of Oracle Financial Services Applications (component: Accessibility (Apache CXF)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Cash Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Cash Management accessible data as well as  unauthorized read access to a subset of Oracle Banking Cash Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Cash Management. CVSS 3.1 Base Score 5.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common Core (Apache CXF)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Liquidity Management accessible data as well as  unauthorized read access to a subset of Oracle Banking Liquidity Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 5.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14195V-14.5.0.15.0",
          "P-14195V-14.8.1.0.0",
          "P-13304V-14.8.0.1.0",
          "P-13304V-14.8.1.0.0",
          "P-5579V-24.12.0.0-24.12.11.0",
          "P-5579V-23.12.0.0-23.12.17.0",
          "P-13304V-14.7.0.9.0",
          "P-14195V-14.8.0.1.0",
          "P-13304V-14.5.0.15.0",
          "P-5579V-22.12.0.0-22.12.20.0",
          "P-14195V-14.6.0.11.0",
          "P-14195V-14.7.0.9.0",
          "P-13304V-14.6.0.11.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5579V-23.12.0.0-23.12.17.0",
            "P-5579V-22.12.0.0-22.12.20.0",
            "P-5579V-24.12.0.0-24.12.11.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU30"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14195V-14.5.0.15.0",
            "P-14195V-14.8.1.0.0",
            "P-13304V-14.7.0.9.0",
            "P-13304V-14.8.0.1.0",
            "P-14195V-14.8.0.1.0",
            "P-13304V-14.5.0.15.0",
            "P-14195V-14.6.0.11.0",
            "P-14195V-14.7.0.9.0",
            "P-13304V-14.8.1.0.0",
            "P-13304V-14.6.0.11.0"
          ],
          "url": "https://support.oracle.com"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.6,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14195V-14.5.0.15.0",
            "P-14195V-14.8.1.0.0",
            "P-13304V-14.8.0.1.0",
            "P-13304V-14.8.1.0.0",
            "P-5579V-24.12.0.0-24.12.11.0",
            "P-5579V-23.12.0.0-23.12.17.0",
            "P-13304V-14.7.0.9.0",
            "P-14195V-14.8.0.1.0",
            "P-13304V-14.5.0.15.0",
            "P-5579V-22.12.0.0-22.12.20.0",
            "P-14195V-14.6.0.11.0",
            "P-14195V-14.7.0.9.0",
            "P-13304V-14.6.0.11.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-48866",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "38543443"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_security (ModSecurity)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1042(mod_security)V-12.2.1.4.0",
          "P-1042(mod_security)V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(mod_security)V-12.2.1.4.0",
            "P-1042(mod_security)V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ]
    },
    {
      "cve": "CVE-2025-48924",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Retail Fiscal Management",
          "text": "38420999"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Identity Manager",
          "text": "38421149"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Access Manager",
          "text": "38421205"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Financial Close Management",
          "text": "38421304"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
          "text": "38421305"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Financial Reporting",
          "text": "38421229"
        },
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
          "text": "38420910"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Identity Manager Connector",
          "text": "38420899"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
          "text": "38420932"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38421047"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Stream Analytics",
          "text": "38421246"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Infrastructure Technology",
          "text": "38421301"
        },
        {
          "system_name": "Oracle Bug ID of Siebel CRM Integration",
          "text": "38421185"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Calculation Manager",
          "text": "38421144"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
          "text": "38196162"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Service Bus",
          "text": "38421070"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Supply Chain Finance",
          "text": "38420938"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Cloud Native Session Border Controller",
          "text": "38345548"
        },
        {
          "system_name": "Oracle Bug ID of Oracle SOA Suite",
          "text": "38570770"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Cash Management",
          "text": "38420922"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
          "text": "38420924"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Insurance Policy Administration J2EE",
          "text": "38421237"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Application Testing Suite",
          "text": "38420841"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Branch",
          "text": "38420921"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
          "text": "38421299"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hospitality OPERA 5 Property Services",
          "text": "38161314"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38421279"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications ASAP",
          "text": "38421031"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications IP Service Activator",
          "text": "38421273"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Planning",
          "text": "38421230"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Profitability and Cost Management",
          "text": "38421231"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "38198052"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Element Manager",
          "text": "38421282"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
          "text": "38421283"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Platform",
          "text": "38744220"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
          "text": "38421081"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Managed File Transfer",
          "text": "38420904"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications ASAP product of Oracle Communications (component: Security (Apache Commons Lang)).  Supported versions that are affected are 7.4.0 and  7.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications ASAP.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications ASAP. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch (Apache Commons Lang)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: Core (Apache Commons Lang)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Service Bus.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Service Bus. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Security (Apache Commons Lang)).  Supported versions that are affected are 4.3.0.5.0, 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0, 4.4.0.4.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4 and  25.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Utilities Application Framework. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security (Apache Commons Lang)).   The supported version that is affected is 11.2.23. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Calculation Manager. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Third Party (Apache Commons Lang)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Identity Manager. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST (Apache Commons Lang)).  Supported versions that are affected are 17.0-25.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Integration. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Identity Store Access (Apache Commons Lang)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Access Manager. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server Components (Apache Commons Lang)).   The supported version that is affected is 11.2.23. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Planning product of Oracle Hyperion (component: Security (Apache Commons Lang)).   The supported version that is affected is 11.2.23. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Planning.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Planning. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Install (Apache Commons Lang)).   The supported version that is affected is 11.2.23. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Profitability and Cost Management. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Insurance Policy Administration J2EE product of Oracle Financial Services Applications (component: Architecture (Apache Commons Lang)).  Supported versions that are affected are 11.3.1-12.0.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration J2EE.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Insurance Policy Administration J2EE. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Stream Analytics product of Oracle GoldenGate (component: General (Apache Commons Lang)).  Supported versions that are affected are 19.1.0.0.0-19.1.0.0.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GoldenGate Stream Analytics. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications IP Service Activator product of Oracle Communications (component: System (Apache Commons Lang)).   The supported version that is affected is 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications IP Service Activator.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications IP Service Activator. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (Apache Commons Lang)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Policy Management. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Third Party (Apache Commons Lang)).  Supported versions that are affected are 9.0.0-9.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Element Manager. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: Third Party (Apache Commons Lang)).  Supported versions that are affected are 9.0.0-9.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Report Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen (Apache Commons Lang)).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Install and Configuration (Apache Commons Lang)).   The supported version that is affected is 11.2.23. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Financial Close Management product of Oracle Hyperion (component: Close Manager (Apache Commons Lang)).   The supported version that is affected is 11.2.23. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Close Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Close Management. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security (Apache Commons Lang)).   The supported version that is affected is 11.2.23. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Adapters (Apache Commons Lang)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle SOA Suite. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Fiscal Management product of Oracle Retail Applications (component: NF Issuing (Apache Commons Lang)).   The supported version that is affected is 14.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Fiscal Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Fiscal Management. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Supply Chain Finance product of Oracle Financial Services Applications (component: Security (Apache Commons Lang)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Supply Chain Finance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Supply Chain Finance. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework (Apache Commons Lang)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Platform. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Apache Commons Lang)).  Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and  14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Cash Management product of Oracle Financial Services Applications (component: Accessibility (Apache Commons Lang)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Cash Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Cash Management. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports (Apache Commons Lang)).  Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0, 14.7.0.0.0 and  14.8.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Branch.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Branch. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Core (Apache Commons Lang)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: Runtime Server (Apache Commons Lang)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Managed File Transfer.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Managed File Transfer. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core (Apache Commons Lang)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Identity Manager Connector. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Load Testing for Web Apps (Apache Commons Lang)).   The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Application Testing Suite. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Cloud Native Session Border Controller product of Oracle Communications (component: Third Party (Apache Commons Lang)).   The supported version that is affected is 25.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Cloud Native Session Border Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Cloud Native Session Border Controller. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security (Apache Commons Lang)).  Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Composer (Apache Commons Lang)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Process Management Suite. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera (Apache Commons Lang)).  Supported versions that are affected are 5.6.19, 5.6.25, 5.6.26 and  5.6.27. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality OPERA 5 Property Services. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common Core (Apache Commons Lang)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5325V-14.1.2.0.0",
          "P-5308V-14.1.2.0.0",
          "P-9008V-17.0-25.9",
          "P-2261V-7.5.0",
          "P-2025V-8.2.0.0.0",
          "P-2245V-4.3.0.6.0",
          "P-2245V-4.4.0.3.0",
          "P-1162V-14.1.2.0.0",
          "P-4403V-11.2.23",
          "P-5279V-11.3.1-12.0.6",
          "P-13304V-14.5.0.15.0",
          "P-14324V-14.7.0.0.0",
          "P-10198V-12.2.1.4.0",
          "P-10770V-9.0.0-9.0.4",
          "P-14195V-14.6.0.11.0",
          "P-8776V-11.2.23",
          "P-1370V-13.5",
          "P-13701V-14.7.0.0.0",
          "P-13304V-14.6.0.11.0",
          "P-9348V-11.4.0",
          "P-4622V-13.3.0.1",
          "P-14195V-14.8.1.0.0",
          "P-10900V-15.0.0.0",
          "P-9617V-14.1.2.0.0",
          "P-2245V-4.5.0.2.0",
          "P-13872V-14.7.0.9.0",
          "P-11052V-9.0.0-9.0.4",
          "P-2245V-4.5.0.0.0",
          "P-13872V-14.8.0.1.0",
          "P-13304V-14.8.1.0.0",
          "P-13304V-14.7.0.9.0",
          "P-1370V-24.1",
          "P-9617V-12.2.1.4.0",
          "P-13701V-14.6.0.0.0",
          "P-14015V-19.1.0.0.0-19.1.0.0.11",
          "P-2245V-25.10",
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5565V-12.2.1.4.0",
          "P-5085V-8.62",
          "P-14324V-14.6.0.0.0",
          "P-2260V-7.4.0",
          "P-2260V-7.4.1",
          "P-2025V-7.6.0.0.0",
          "P-2245V-4.4.0.0.0",
          "P-4392V-11.2.23",
          "P-2245V-4.4.0.2.0",
          "P-2245V-4.4.0.4.0",
          "P-4402V-11.2.23",
          "P-13872V-14.6.0.11.0",
          "P-1999V-14.1.2.1.0",
          "P-13701V-14.5.0.0.0",
          "P-1980V-12.2.1.4.0",
          "P-2245V-4.3.0.5.0",
          "P-2245V-25.4",
          "P-5616V-11.2.23",
          "P-13872V-14.5.0.15.0",
          "P-14195V-14.7.0.9.0",
          "P-13872V-14.8.1.0.0",
          "P-14195V-14.5.0.15.0",
          "P-14324V-14.5.0.0.0",
          "P-4390V-11.2.23",
          "P-2025V-12.2.1.4.0",
          "P-13304V-14.8.0.1.0",
          "P-10198V-14.1.2.0.0",
          "P-1999V-12.2.1.4.0",
          "P-9038V-14.2",
          "P-2245V-4.5.0.1.1",
          "P-11580V-5.6.25",
          "P-5565V-14.1.2.1.0",
          "P-11580V-5.6.26",
          "P-11580V-5.6.27",
          "P-11580V-5.6.19",
          "P-14324V-14.8.0.0.0",
          "P-14195V-14.8.0.1.0",
          "P-2245V-4.5.0.1.3",
          "P-14762V-25.1.0",
          "P-5685V-11.2.23"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2260V-7.4.0",
            "P-2260V-7.4.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU13"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU47"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1999V-14.1.2.1.0",
            "P-5325V-14.1.2.0.0",
            "P-1980V-12.2.1.4.0",
            "P-10198V-14.1.2.0.0",
            "P-5308V-14.1.2.0.0",
            "P-1999V-12.2.1.4.0",
            "P-9617V-12.2.1.4.0",
            "P-10198V-12.2.1.4.0",
            "P-9617V-14.1.2.0.0",
            "P-5565V-14.1.2.1.0",
            "P-5565V-12.2.1.4.0",
            "P-1162V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2245V-4.3.0.5.0",
            "P-2245V-4.5.0.1.3",
            "P-2245V-4.5.0.1.1",
            "P-2245V-4.5.0.2.0",
            "P-2245V-25.4",
            "P-2245V-4.3.0.6.0",
            "P-2245V-4.5.0.0.0",
            "P-2245V-25.10",
            "P-2245V-4.4.0.0.0",
            "P-2245V-4.4.0.2.0",
            "P-2245V-4.4.0.3.0",
            "P-2245V-4.4.0.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU31"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4403V-11.2.23",
            "P-4390V-11.2.23",
            "P-5685V-11.2.23",
            "P-5616V-11.2.23",
            "P-8776V-11.2.23",
            "P-4392V-11.2.23",
            "P-4402V-11.2.23"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA812"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9008V-17.0-25.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU44"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5279V-11.3.1-12.0.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU42"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2261V-7.5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU14"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11052V-9.0.0-9.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863845"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10770V-9.0.0-9.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863846"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4622V-13.3.0.1",
            "P-1370V-24.1",
            "P-1370V-13.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU6"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9038V-14.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU16"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14195V-14.5.0.15.0",
            "P-14324V-14.5.0.0.0",
            "P-14195V-14.8.1.0.0",
            "P-13304V-14.8.0.1.0",
            "P-13872V-14.7.0.9.0",
            "P-13872V-14.8.0.1.0",
            "P-13304V-14.8.1.0.0",
            "P-13872V-14.6.0.11.0",
            "P-14324V-14.8.0.0.0",
            "P-13304V-14.7.0.9.0",
            "P-13701V-14.5.0.0.0",
            "P-14195V-14.8.0.1.0",
            "P-13304V-14.5.0.15.0",
            "P-14324V-14.7.0.0.0",
            "P-13701V-14.6.0.0.0",
            "P-13872V-14.5.0.15.0",
            "P-14195V-14.6.0.11.0",
            "P-14195V-14.7.0.9.0",
            "P-13872V-14.8.1.0.0",
            "P-13701V-14.7.0.0.0",
            "P-14324V-14.6.0.0.0",
            "P-13304V-14.6.0.11.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9348V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU49"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14762V-25.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU43"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-12.2.1.4.0",
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1314"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11580V-5.6.19",
            "P-11580V-5.6.25",
            "P-11580V-5.6.26",
            "P-11580V-5.6.27"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU28"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-5325V-14.1.2.0.0",
            "P-5308V-14.1.2.0.0",
            "P-9008V-17.0-25.9",
            "P-2261V-7.5.0",
            "P-2025V-8.2.0.0.0",
            "P-2245V-4.3.0.6.0",
            "P-2245V-4.4.0.3.0",
            "P-1162V-14.1.2.0.0",
            "P-4403V-11.2.23",
            "P-5279V-11.3.1-12.0.6",
            "P-13304V-14.5.0.15.0",
            "P-14324V-14.7.0.0.0",
            "P-10198V-12.2.1.4.0",
            "P-10770V-9.0.0-9.0.4",
            "P-14195V-14.6.0.11.0",
            "P-8776V-11.2.23",
            "P-1370V-13.5",
            "P-13701V-14.7.0.0.0",
            "P-13304V-14.6.0.11.0",
            "P-9348V-11.4.0",
            "P-4622V-13.3.0.1",
            "P-14195V-14.8.1.0.0",
            "P-10900V-15.0.0.0",
            "P-9617V-14.1.2.0.0",
            "P-2245V-4.5.0.2.0",
            "P-13872V-14.7.0.9.0",
            "P-11052V-9.0.0-9.0.4",
            "P-2245V-4.5.0.0.0",
            "P-13872V-14.8.0.1.0",
            "P-13304V-14.8.1.0.0",
            "P-13304V-14.7.0.9.0",
            "P-1370V-24.1",
            "P-9617V-12.2.1.4.0",
            "P-13701V-14.6.0.0.0",
            "P-2245V-25.10",
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5565V-12.2.1.4.0",
            "P-5085V-8.62",
            "P-14324V-14.6.0.0.0",
            "P-2260V-7.4.0",
            "P-2260V-7.4.1",
            "P-2025V-7.6.0.0.0",
            "P-2245V-4.4.0.0.0",
            "P-4392V-11.2.23",
            "P-2245V-4.4.0.2.0",
            "P-2245V-4.4.0.4.0",
            "P-4402V-11.2.23",
            "P-13872V-14.6.0.11.0",
            "P-1999V-14.1.2.1.0",
            "P-13701V-14.5.0.0.0",
            "P-1980V-12.2.1.4.0",
            "P-2245V-4.3.0.5.0",
            "P-2245V-25.4",
            "P-5616V-11.2.23",
            "P-13872V-14.5.0.15.0",
            "P-14195V-14.7.0.9.0",
            "P-13872V-14.8.1.0.0",
            "P-14195V-14.5.0.15.0",
            "P-14324V-14.5.0.0.0",
            "P-4390V-11.2.23",
            "P-2025V-12.2.1.4.0",
            "P-13304V-14.8.0.1.0",
            "P-10198V-14.1.2.0.0",
            "P-1999V-12.2.1.4.0",
            "P-9038V-14.2",
            "P-2245V-4.5.0.1.1",
            "P-11580V-5.6.25",
            "P-5565V-14.1.2.1.0",
            "P-11580V-5.6.26",
            "P-11580V-5.6.27",
            "P-11580V-5.6.19",
            "P-14324V-14.8.0.0.0",
            "P-14195V-14.8.0.1.0",
            "P-2245V-4.5.0.1.3",
            "P-14762V-25.1.0",
            "P-5685V-11.2.23"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14015V-19.1.0.0.0-19.1.0.0.11"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-48976",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5758V-12.2.1.4.0-12.2.1.4.250531"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Element Manager",
          "text": "38189950"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
          "text": "38190467"
        },
        {
          "system_name": "Oracle Bug ID of Oracle WebLogic Server",
          "text": "38381127"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Agile PLM",
          "text": "38140643"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Veridata",
          "text": "38200220"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
          "text": "38189914"
        },
        {
          "system_name": "Oracle Bug ID of Siebel Apps - Marketing",
          "text": "38201504"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
          "text": "38189951"
        },
        {
          "system_name": "Oracle Bug ID of Oracle SOA Suite",
          "text": "38403551"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Cash Management",
          "text": "38183614"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hospitality OPERA 5 Property Services",
          "text": "38392720"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38189949"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Service Bus",
          "text": "38825444"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files and Attachments (Apache Commons FileUpload)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Cash Management product of Oracle Financial Services Applications (component: Accessibility (Apache Commons FileUpload)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Cash Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Cash Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common Core (Apache Commons FileUpload)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (Apache Commons FileUpload)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Policy Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Third Party (Apache Commons FileUpload)).  Supported versions that are affected are 9.0.0-9.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Element Manager. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: Third Party (Apache Commons FileUpload)).  Supported versions that are affected are 9.0.0-9.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Report Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Composer (Apache Commons FileUpload)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Process Management Suite. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Veridata product of Oracle GoldenGate (component: Third Party (Apache Commons FileUpload)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Email Marketing (Apache Commons FileUpload)).  Supported versions that are affected are 17.0-25.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel Apps - Marketing. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Third Party Jars (Apache Commons FileUpload)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera (Apache Commons FileUpload)).  Supported versions that are affected are 5.6.19, 5.6.25, 5.6.26 and  5.6.27. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality OPERA 5 Property Services. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Rest Converters (Apache Commons FileUpload)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SOA Suite. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: Core (Apache Commons FileUpload)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Service Bus.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Service Bus. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5325V-14.1.2.0.0",
          "P-5325V-12.2.1.4.0",
          "P-1162V-14.1.2.0.0",
          "P-13304V-14.5.0.15.0",
          "P-10770V-9.0.0-9.0.4",
          "P-5308V-12.2.1.4.0",
          "P-4461V-9.3.6",
          "P-5242V-12.2.1.4.0",
          "P-14195V-14.6.0.11.0",
          "P-14195V-14.7.0.9.0",
          "P-13304V-14.6.0.11.0",
          "P-14195V-14.5.0.15.0",
          "P-14195V-14.8.1.0.0",
          "P-13304V-14.8.0.1.0",
          "P-10900V-15.0.0.0",
          "P-8974V-17.0-25.9",
          "P-11052V-9.0.0-9.0.4",
          "P-11580V-5.6.25",
          "P-13304V-14.8.1.0.0",
          "P-11580V-5.6.26",
          "P-11580V-5.6.27",
          "P-11580V-5.6.19",
          "P-13304V-14.7.0.9.0",
          "P-14195V-14.8.0.1.0",
          "P-5242V-14.1.1.0.0",
          "P-1162V-12.2.1.4.0"
        ],
        "known_not_affected": [
          "P-5758V-12.2.1.4.0-12.2.1.4.250531"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4461V-9.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU46"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14195V-14.5.0.15.0",
            "P-14195V-14.8.1.0.0",
            "P-13304V-14.7.0.9.0",
            "P-13304V-14.8.0.1.0",
            "P-14195V-14.8.0.1.0",
            "P-13304V-14.5.0.15.0",
            "P-14195V-14.6.0.11.0",
            "P-14195V-14.7.0.9.0",
            "P-13304V-14.8.1.0.0",
            "P-13304V-14.6.0.11.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11052V-9.0.0-9.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863845"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10770V-9.0.0-9.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863846"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5325V-14.1.2.0.0",
            "P-5242V-14.1.1.0.0",
            "P-5308V-12.2.1.4.0",
            "P-5242V-12.2.1.4.0",
            "P-5325V-12.2.1.4.0",
            "P-1162V-14.1.2.0.0",
            "P-1162V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5758V-12.2.1.4.0-12.2.1.4.250531"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8974V-17.0-25.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU44"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11580V-5.6.19",
            "P-11580V-5.6.25",
            "P-11580V-5.6.26",
            "P-11580V-5.6.27"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU28"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5325V-14.1.2.0.0",
            "P-5325V-12.2.1.4.0",
            "P-1162V-14.1.2.0.0",
            "P-13304V-14.5.0.15.0",
            "P-10770V-9.0.0-9.0.4",
            "P-5308V-12.2.1.4.0",
            "P-4461V-9.3.6",
            "P-5242V-12.2.1.4.0",
            "P-14195V-14.6.0.11.0",
            "P-14195V-14.7.0.9.0",
            "P-13304V-14.6.0.11.0",
            "P-14195V-14.5.0.15.0",
            "P-14195V-14.8.1.0.0",
            "P-13304V-14.8.0.1.0",
            "P-10900V-15.0.0.0",
            "P-8974V-17.0-25.9",
            "P-11052V-9.0.0-9.0.4",
            "P-11580V-5.6.25",
            "P-13304V-14.8.1.0.0",
            "P-11580V-5.6.26",
            "P-11580V-5.6.27",
            "P-11580V-5.6.19",
            "P-13304V-14.7.0.9.0",
            "P-14195V-14.8.0.1.0",
            "P-5242V-14.1.1.0.0",
            "P-1162V-12.2.1.4.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5758V-12.2.1.4.0-12.2.1.4.250531"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5758V-12.2.1.4.0-12.2.1.4.250531"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-48989",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
          "text": "38313398"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Agile PLM",
          "text": "38313369"
        },
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "38313400"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security (Apache Tomcat)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface (Apache Tomcat)).  Supported versions that are affected are 17.0-25.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Core (Apache Tomcat)).  Supported versions that are affected are 7.0.0.0.6, 7.0.0.1.4 and  25.4.0.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Testing Accelerator. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4461V-9.3.6",
          "P-9019V-17.0-25.10",
          "P-13784V-25.4.0.0.1",
          "P-13784V-7.0.0.1.4",
          "P-13784V-7.0.0.0.6"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4461V-9.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU46"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-17.0-25.10"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU44"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13784V-25.4.0.0.1",
            "P-13784V-7.0.0.1.4",
            "P-13784V-7.0.0.0.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU31"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9019V-17.0-25.10",
            "P-4461V-9.3.6",
            "P-13784V-25.4.0.0.1",
            "P-13784V-7.0.0.1.4",
            "P-13784V-7.0.0.0.6"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-4949",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Fusion Middleware",
          "text": "38796796"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Data Integrator",
          "text": "38142161"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Fusion Middleware (component: Oracle Database Client for Fusion Middleware (Eclipse JGit)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Fusion Middleware.  Successful attacks of this vulnerability can result in takeover of Oracle Fusion Middleware. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Security (Eclipse JGit)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2196V-14.1.2.0.0",
          "P-1032V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2196V-14.1.2.0.0",
            "P-1032V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2196V-14.1.2.0.0",
            "P-1032V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-49794",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "38338350"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Infrastructure Technology",
          "text": "38338341"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
          "text": "38338310"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
          "text": "38338314"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Branch",
          "text": "38338306"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Supply Chain Finance",
          "text": "38338318"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Cash Management",
          "text": "38338307"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (libxml2)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common Core (libxml2)).   The supported version that is affected is 14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Liquidity Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Supply Chain Finance product of Oracle Financial Services Applications (component: Security (libxml2)).   The supported version that is affected is 14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Supply Chain Finance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Supply Chain Finance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Supply Chain Finance.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Install and Configuration (libxml2)).   The supported version that is affected is 11.2.23. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Infrastructure Technology.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Cash Management product of Oracle Financial Services Applications (component: Accessibility (libxml2)).   The supported version that is affected is 14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Cash Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Cash Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Cash Management.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports (libxml2)).  Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0, 14.7.0.0.0 and  14.8.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Branch.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Branch accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Branch.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (libxml2)).  Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and  14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Corporate Lending Process Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending Process Management.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14324V-14.5.0.0.0",
          "P-14195V-14.8.1.0.0",
          "P-1042(Core)V-14.1.2.0.0",
          "P-13304V-14.8.1.0.0",
          "P-4392V-11.2.23",
          "P-14324V-14.8.0.0.0",
          "P-13701V-14.5.0.0.0",
          "P-1042(Core)V-12.2.1.4.0",
          "P-14324V-14.7.0.0.0",
          "P-13701V-14.6.0.0.0",
          "P-13872V-14.8.1.0.0",
          "P-13701V-14.7.0.0.0",
          "P-14324V-14.6.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Core)V-12.2.1.4.0",
            "P-1042(Core)V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14324V-14.5.0.0.0",
            "P-14195V-14.8.1.0.0",
            "P-14324V-14.8.0.0.0",
            "P-13701V-14.5.0.0.0",
            "P-14324V-14.7.0.0.0",
            "P-13701V-14.6.0.0.0",
            "P-13304V-14.8.1.0.0",
            "P-13872V-14.8.1.0.0",
            "P-13701V-14.7.0.0.0",
            "P-14324V-14.6.0.0.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4392V-11.2.23"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA812"
        }
      ]
    },
    {
      "cve": "CVE-2025-49795",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "38338350"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Infrastructure Technology",
          "text": "38338341"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
          "text": "38338310"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
          "text": "38338314"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Branch",
          "text": "38338306"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Cash Management",
          "text": "38338307"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Supply Chain Finance",
          "text": "38338318"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (libxml2)).  Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and  14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Corporate Lending Process Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending Process Management.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Cash Management product of Oracle Financial Services Applications (component: Accessibility (libxml2)).   The supported version that is affected is 14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Cash Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Cash Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Cash Management.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports (libxml2)).  Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0, 14.7.0.0.0 and  14.8.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Branch.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Branch accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Branch.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common Core (libxml2)).   The supported version that is affected is 14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Liquidity Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (libxml2)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Install and Configuration (libxml2)).   The supported version that is affected is 11.2.23. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Infrastructure Technology.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Supply Chain Finance product of Oracle Financial Services Applications (component: Security (libxml2)).   The supported version that is affected is 14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Supply Chain Finance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Supply Chain Finance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Supply Chain Finance.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14324V-14.5.0.0.0",
          "P-14195V-14.8.1.0.0",
          "P-1042(Core)V-14.1.2.0.0",
          "P-13304V-14.8.1.0.0",
          "P-4392V-11.2.23",
          "P-14324V-14.8.0.0.0",
          "P-13701V-14.5.0.0.0",
          "P-14324V-14.7.0.0.0",
          "P-1042(Core)V-12.2.1.4.0",
          "P-13701V-14.6.0.0.0",
          "P-13872V-14.8.1.0.0",
          "P-13701V-14.7.0.0.0",
          "P-14324V-14.6.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14324V-14.5.0.0.0",
            "P-14195V-14.8.1.0.0",
            "P-14324V-14.8.0.0.0",
            "P-13701V-14.5.0.0.0",
            "P-14324V-14.7.0.0.0",
            "P-13701V-14.6.0.0.0",
            "P-13304V-14.8.1.0.0",
            "P-13872V-14.8.1.0.0",
            "P-13701V-14.7.0.0.0",
            "P-14324V-14.6.0.0.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Core)V-12.2.1.4.0",
            "P-1042(Core)V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4392V-11.2.23"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA812"
        }
      ]
    },
    {
      "cve": "CVE-2025-49796",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "38338350"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Infrastructure Technology",
          "text": "38338341"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
          "text": "38338310"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
          "text": "38338314"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Branch",
          "text": "38338306"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Cash Management",
          "text": "38338307"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Supply Chain Finance",
          "text": "38338318"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports (libxml2)).  Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0, 14.7.0.0.0 and  14.8.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Branch.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Branch accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Branch. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Cash Management product of Oracle Financial Services Applications (component: Accessibility (libxml2)).   The supported version that is affected is 14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Cash Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Cash Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Cash Management. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (libxml2)).  Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and  14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Corporate Lending Process Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common Core (libxml2)).   The supported version that is affected is 14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Liquidity Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Supply Chain Finance product of Oracle Financial Services Applications (component: Security (libxml2)).   The supported version that is affected is 14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Supply Chain Finance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Supply Chain Finance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Supply Chain Finance. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Install and Configuration (libxml2)).   The supported version that is affected is 11.2.23. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (libxml2)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14324V-14.5.0.0.0",
          "P-14195V-14.8.1.0.0",
          "P-1042(Core)V-14.1.2.0.0",
          "P-13304V-14.8.1.0.0",
          "P-4392V-11.2.23",
          "P-14324V-14.8.0.0.0",
          "P-13701V-14.5.0.0.0",
          "P-14324V-14.7.0.0.0",
          "P-1042(Core)V-12.2.1.4.0",
          "P-13701V-14.6.0.0.0",
          "P-13872V-14.8.1.0.0",
          "P-13701V-14.7.0.0.0",
          "P-14324V-14.6.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14324V-14.5.0.0.0",
            "P-14324V-14.8.0.0.0",
            "P-14195V-14.8.1.0.0",
            "P-13701V-14.5.0.0.0",
            "P-14324V-14.7.0.0.0",
            "P-13701V-14.6.0.0.0",
            "P-13304V-14.8.1.0.0",
            "P-13872V-14.8.1.0.0",
            "P-13701V-14.7.0.0.0",
            "P-14324V-14.6.0.0.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4392V-11.2.23"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA812"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Core)V-12.2.1.4.0",
            "P-1042(Core)V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14324V-14.5.0.0.0",
            "P-14195V-14.8.1.0.0",
            "P-1042(Core)V-14.1.2.0.0",
            "P-13304V-14.8.1.0.0",
            "P-4392V-11.2.23",
            "P-14324V-14.8.0.0.0",
            "P-13701V-14.5.0.0.0",
            "P-14324V-14.7.0.0.0",
            "P-1042(Core)V-12.2.1.4.0",
            "P-13701V-14.6.0.0.0",
            "P-13872V-14.8.1.0.0",
            "P-13701V-14.7.0.0.0",
            "P-14324V-14.6.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-49812",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "38543389"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL module (Apache HTTP Server)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1042(SSL module)V-14.1.2.0.0",
          "P-1042(SSL module)V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(SSL module)V-14.1.2.0.0",
            "P-1042(SSL module)V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ]
    },
    {
      "cve": "CVE-2025-49844",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
          "text": "38512733"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Infrastructure (valkey)).   The supported version that is affected is 5.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  While the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10761V-5.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10761V-5.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863848"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.9,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10761V-5.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50059",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
          "text": "38525150"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System, Workbench, Endeca Application Controller (Oracle Java SE)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  While the vulnerability is in Oracle Commerce Guided Search, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9633(Content Acquisition System, Workbench, Endeca Application Controller)V-11.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633(Content Acquisition System, Workbench, Endeca Application Controller)V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU49"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.6,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9633(Content Acquisition System, Workbench, Endeca Application Controller)V-11.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-5115",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38419977"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
          "text": "38419943"
        },
        {
          "system_name": "Oracle Bug ID of Oracle AutoVue Office",
          "text": "38419937"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
          "text": "38419948"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Coherence",
          "text": "38419959"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Branch",
          "text": "38419939"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Autovue for Agile Product Lifecycle Management",
          "text": "38419891"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Cash Management",
          "text": "38419940"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Supply Chain Finance",
          "text": "38419950"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Autovue for Agile Product Lifecycle Management product of Oracle Supply Chain (component: Internal Operations (Eclipse Jetty)).   The supported version that is affected is 21.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Autovue for Agile Product Lifecycle Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Autovue for Agile Product Lifecycle Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle AutoVue Office product of Oracle Supply Chain (component: Security (Eclipse Jetty)).   The supported version that is affected is 21.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle AutoVue Office.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle AutoVue Office.  Note: This vulnerability applies to Oracle AutoVue Office, Oracle AutoVue 2D Professional, Oracle AutoVue 3D Professional Advanced, Oracle AutoVue EDA Professional and Oracle AutoVue Electro-Mechanical Professional. Please refer to Patch Availability Document for more details. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports (Eclipse Jetty)).  Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0, 14.7.0.0.0 and  14.8.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Branch.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Branch. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Cash Management product of Oracle Financial Services Applications (component: Accessibility (Eclipse Jetty)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Cash Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Cash Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Eclipse Jetty)).  Supported versions that are affected are 14.5.0.0.0, 14.6.0.0.0 and  14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common Core (Eclipse Jetty)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Supply Chain Finance product of Oracle Financial Services Applications (component: Security (Eclipse Jetty)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Supply Chain Finance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Supply Chain Finance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars (Eclipse Jetty)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Eclipse Jetty)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP/2 to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2545V-14.1.1.0.0",
          "P-13872V-14.6.0.11.0",
          "P-13701V-14.5.0.0.0",
          "P-13304V-14.5.0.15.0",
          "P-14324V-14.7.0.0.0",
          "P-14195V-14.6.0.11.0",
          "P-14195V-14.7.0.9.0",
          "P-13872V-14.5.0.15.0",
          "P-13872V-14.8.1.0.0",
          "P-13701V-14.7.0.0.0",
          "P-13304V-14.6.0.11.0",
          "P-14324V-14.5.0.0.0",
          "P-14195V-14.5.0.15.0",
          "P-14195V-14.8.1.0.0",
          "P-13304V-14.8.0.1.0",
          "P-2545V-12.2.1.4.0",
          "P-13872V-14.7.0.9.0",
          "P-14597V-6.1.0-6.1.1",
          "P-13872V-14.8.0.1.0",
          "P-13304V-14.8.1.0.0",
          "P-14324V-14.8.0.0.0",
          "P-13304V-14.7.0.9.0",
          "P-14195V-14.8.0.1.0",
          "P-4434V-21.1.0",
          "P-13701V-14.6.0.0.0",
          "P-4449V-21.1.0",
          "P-14324V-14.6.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4434V-21.1.0",
            "P-4449V-21.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU46"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14324V-14.5.0.0.0",
            "P-14195V-14.5.0.15.0",
            "P-14195V-14.8.1.0.0",
            "P-13304V-14.8.0.1.0",
            "P-13872V-14.7.0.9.0",
            "P-13872V-14.8.0.1.0",
            "P-13304V-14.8.1.0.0",
            "P-13872V-14.6.0.11.0",
            "P-14324V-14.8.0.0.0",
            "P-13304V-14.7.0.9.0",
            "P-14195V-14.8.0.1.0",
            "P-13701V-14.5.0.0.0",
            "P-13304V-14.5.0.15.0",
            "P-14324V-14.7.0.0.0",
            "P-13701V-14.6.0.0.0",
            "P-14195V-14.6.0.11.0",
            "P-14195V-14.7.0.9.0",
            "P-13872V-14.5.0.15.0",
            "P-13872V-14.8.1.0.0",
            "P-13701V-14.7.0.0.0",
            "P-14324V-14.6.0.0.0",
            "P-13304V-14.6.0.11.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2545V-12.2.1.4.0",
            "P-2545V-14.1.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2545V-14.1.1.0.0",
            "P-13872V-14.6.0.11.0",
            "P-13701V-14.5.0.0.0",
            "P-13304V-14.5.0.15.0",
            "P-14324V-14.7.0.0.0",
            "P-14195V-14.6.0.11.0",
            "P-14195V-14.7.0.9.0",
            "P-13872V-14.5.0.15.0",
            "P-13872V-14.8.1.0.0",
            "P-13701V-14.7.0.0.0",
            "P-13304V-14.6.0.11.0",
            "P-14324V-14.5.0.0.0",
            "P-14195V-14.5.0.15.0",
            "P-14195V-14.8.1.0.0",
            "P-13304V-14.8.0.1.0",
            "P-2545V-12.2.1.4.0",
            "P-13872V-14.7.0.9.0",
            "P-13872V-14.8.0.1.0",
            "P-13304V-14.8.1.0.0",
            "P-14324V-14.8.0.0.0",
            "P-13304V-14.7.0.9.0",
            "P-14195V-14.8.0.1.0",
            "P-4434V-21.1.0",
            "P-13701V-14.6.0.0.0",
            "P-4449V-21.1.0",
            "P-14324V-14.6.0.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-52520",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
          "text": "38313398"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Core (Apache Tomcat)).  Supported versions that are affected are 7.0.0.0.6, 7.0.0.1.4 and  25.4.0.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Testing Accelerator.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13784V-25.4.0.0.1",
          "P-13784V-7.0.0.1.4",
          "P-13784V-7.0.0.0.6"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13784V-25.4.0.0.1",
            "P-13784V-7.0.0.1.4",
            "P-13784V-7.0.0.0.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU31"
        }
      ]
    },
    {
      "cve": "CVE-2025-52891",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "38543443"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_security (ModSecurity)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1042(mod_security)V-12.2.1.4.0",
          "P-1042(mod_security)V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(mod_security)V-12.2.1.4.0",
            "P-1042(mod_security)V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ]
    },
    {
      "cve": "CVE-2025-52999",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "38620093"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (jackson-core)).  Supported versions that are affected are 7.6.0.0.0 and  8.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2025V-7.6.0.0.0",
          "P-2025V-8.2.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1314"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-5318",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38263975"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Pricing Design Center",
          "text": "38263977"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38263971"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38206356"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38263978"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (libssh)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Policy Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Policy Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Security (libssh)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100, 25.1.200 and  25.2.100. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Network Analytics Data Director accessible data as well as  unauthorized read access to a subset of Oracle Communications Network Analytics Data Director accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Platform (GnuTLS)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director as well as  unauthorized update, insert or delete access to some of Oracle Communications Network Analytics Data Director accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment (libssh)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0 and  15.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Pricing Design Center accessible data as well as  unauthorized read access to a subset of Oracle Communications Pricing Design Center accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (libssh)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-24.2.0-24.2.1",
          "P-14547V-25.2.100",
          "P-14547V-25.1.200",
          "P-10900V-15.0.0.0",
          "P-14547V-25.1.100",
          "P-9437V-15.0.0.0.0",
          "P-9437V-15.0.1.0.0",
          "P-14597V-6.1.0-6.1.1",
          "P-14547V-24.3.0",
          "P-9437V-15.1.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.2.100",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863847"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9437V-15.0.0.0.0",
            "P-9437V-15.0.1.0.0",
            "P-9437V-15.1.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU11"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.2.100",
            "P-14547V-25.1.200",
            "P-10900V-15.0.0.0",
            "P-14547V-25.1.100",
            "P-9437V-15.0.0.0.0",
            "P-9437V-15.0.1.0.0",
            "P-14597V-6.1.0-6.1.1",
            "P-14547V-24.3.0",
            "P-9437V-15.1.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-5351",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38263975"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Pricing Design Center",
          "text": "38263977"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38263971"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Communications Broker",
          "text": "38594505"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38263978"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Security (libssh)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100, 25.1.200 and  25.2.100. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Network Analytics Data Director accessible data as well as  unauthorized read access to a subset of Oracle Communications Network Analytics Data Director accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (libssh)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Policy Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Policy Management accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment (libssh)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0 and  15.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Pricing Design Center accessible data as well as  unauthorized read access to a subset of Oracle Communications Pricing Design Center accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (libssh)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications (component: Routing (libssh)).  Supported versions that are affected are 4.2.0 and  5.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Enterprise Communications Broker.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Communications Broker.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-24.2.0-24.2.1",
          "P-14547V-25.1.200",
          "P-10758V-4.2.0",
          "P-14547V-25.1.100",
          "P-10900V-15.0.0.0",
          "P-14597V-6.1.0-6.1.1",
          "P-14547V-24.3.0",
          "P-10758V-5.0.0",
          "P-9437V-15.1.0.0.0",
          "P-14547V-25.2.100",
          "P-9437V-15.0.0.0.0",
          "P-9437V-15.0.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.2.100",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863847"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9437V-15.0.0.0.0",
            "P-9437V-15.0.1.0.0",
            "P-9437V-15.1.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU11"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10758V-4.2.0",
            "P-10758V-5.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU40"
        }
      ]
    },
    {
      "cve": "CVE-2025-53547",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
          "text": "38327075"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (Helm)).  Supported versions that are affected are 17.0-25.9. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14107V-17.0-25.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14107V-17.0-25.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU44"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.6,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14107V-17.0-25.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53643",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
          "text": "38368477"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (AIOHTTP)).  Supported versions that are affected are 17.0-25.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14107V-17.0-25.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14107V-17.0-25.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU44"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14107V-17.0-25.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-5372",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38263975"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Pricing Design Center",
          "text": "38263977"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38263971"
        },
        {
          "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
          "text": "38607371"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Communications Broker",
          "text": "38594505"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38263978"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (libssh)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Policy Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Policy Management accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment (libssh)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0 and  15.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Pricing Design Center accessible data as well as  unauthorized read access to a subset of Oracle Communications Pricing Design Center accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (libssh)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications (component: Routing (libssh)).  Supported versions that are affected are 4.2.0 and  5.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Enterprise Communications Broker.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Communications Broker.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Security (libssh)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100, 25.1.200 and  25.2.100. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Network Analytics Data Director accessible data as well as  unauthorized read access to a subset of Oracle Communications Network Analytics Data Director accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Containers and Related Services (libssh)).  Supported versions that are affected are 17.0-25.9. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data as well as  unauthorized read access to a subset of Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 5.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-24.2.0-24.2.1",
          "P-10758V-4.2.0",
          "P-14547V-25.1.200",
          "P-10900V-15.0.0.0",
          "P-14547V-25.1.100",
          "P-14597V-6.1.0-6.1.1",
          "P-14547V-24.3.0",
          "P-14107V-17.0-25.9",
          "P-10758V-5.0.0",
          "P-9437V-15.1.0.0.0",
          "P-14547V-25.2.100",
          "P-9437V-15.0.0.0.0",
          "P-9437V-15.0.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9437V-15.0.0.0.0",
            "P-9437V-15.0.1.0.0",
            "P-9437V-15.1.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU11"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10758V-4.2.0",
            "P-10758V-5.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU40"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.2.100",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863847"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14107V-17.0-25.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU44"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.0,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14107V-17.0-25.9"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53864",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebLogic Server",
          "text": "38184939"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Third Party Jars (Nimbus JOSE+JWT)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 5.8 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5242V-12.2.1.4.0",
          "P-5242V-14.1.2.0.0",
          "P-5242V-14.1.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-5449",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38263975"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Pricing Design Center",
          "text": "38263977"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38263971"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Communications Broker",
          "text": "38594505"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38263978"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Security (libssh)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100, 25.1.200 and  25.2.100. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Network Analytics Data Director accessible data as well as  unauthorized read access to a subset of Oracle Communications Network Analytics Data Director accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (libssh)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Policy Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Policy Management accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment (libssh)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0 and  15.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Pricing Design Center accessible data as well as  unauthorized read access to a subset of Oracle Communications Pricing Design Center accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (libssh)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications (component: Routing (libssh)).  Supported versions that are affected are 4.2.0 and  5.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Enterprise Communications Broker.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Communications Broker.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-24.2.0-24.2.1",
          "P-14547V-25.1.200",
          "P-10758V-4.2.0",
          "P-14547V-25.1.100",
          "P-10900V-15.0.0.0",
          "P-14597V-6.1.0-6.1.1",
          "P-14547V-24.3.0",
          "P-10758V-5.0.0",
          "P-9437V-15.1.0.0.0",
          "P-14547V-25.2.100",
          "P-9437V-15.0.0.0.0",
          "P-9437V-15.0.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.2.100",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863847"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9437V-15.0.0.0.0",
            "P-9437V-15.0.1.0.0",
            "P-9437V-15.1.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU11"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10758V-4.2.0",
            "P-10758V-5.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU40"
        }
      ]
    },
    {
      "cve": "CVE-2025-54571",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38722951"
        },
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "38543443"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_security (ModSecurity)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (ModSecurity)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1",
          "P-1042(mod_security)V-12.2.1.4.0",
          "P-1042(mod_security)V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(mod_security)V-12.2.1.4.0",
            "P-1042(mod_security)V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-1042(mod_security)V-12.2.1.4.0",
            "P-1042(mod_security)V-14.1.2.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-54874",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle AutoVue Office",
          "text": "38470372"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38470375"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Outside In Technology",
          "text": "38470379"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Core (OpenJPEG)).  Supported versions that are affected are 8.5.7 and  8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in takeover of Oracle Outside In Technology. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Spatial and Graph (OpenJPEG) component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.0. Easily exploitable vulnerability allows low privileged attacker having None privilege with logon to the infrastructure where Oracle Spatial and Graph (OpenJPEG) executes to compromise Oracle Spatial and Graph (OpenJPEG).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Spatial and Graph (OpenJPEG). CVSS 3.1 Base Score 2.8 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle AutoVue Office product of Oracle Supply Chain (component: Security (OpenJPEG)).   The supported version that is affected is 21.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle AutoVue Office.  Successful attacks of this vulnerability can result in takeover of Oracle AutoVue Office.  Note: This vulnerability applies to Oracle AutoVue Office, Oracle AutoVue 2D Professional, Oracle AutoVue 3D Professional Advanced, Oracle AutoVue EDA Professional and Oracle AutoVue Electro-Mechanical Professional. Please refer to Patch Availability Document for more details. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-619(Oracle Spatial and Graph)V-23.4.0-23.26.0",
          "P-2276V-8.5.8",
          "P-2276V-8.5.7",
          "P-4449V-21.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2276V-8.5.8",
            "P-2276V-8.5.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-619(Oracle Spatial and Graph)V-23.4.0-23.26.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4449V-21.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU46"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2276V-8.5.8",
            "P-2276V-8.5.7",
            "P-4449V-21.1.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 2.8,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-619(Oracle Spatial and Graph)V-23.4.0-23.26.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-54988",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
          "text": "38427043"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
          "text": "38386412"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38744523"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch (Apache Tika)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Tika)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  While the vulnerability is in Oracle Middleware Common Libraries and Tools, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Middleware Common Libraries and Tools.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Oracle Business Rules (Apache Commons Compress)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in takeover of Oracle Business Process Management Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4647V-12.2.1.4.0",
          "P-5325V-14.1.2.0.0",
          "P-5085V-8.61",
          "P-4647V-14.1.2.0.0",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU47"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5325V-14.1.2.0.0",
            "P-4647V-14.1.2.0.0",
            "P-4647V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5325V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-55039",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Stream Analytics",
          "text": "38552116"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Stream Analytics product of Oracle GoldenGate (component: General (Apache Spark)).  Supported versions that are affected are 19.1.0.0.0-19.1.0.0.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle GoldenGate Stream Analytics accessible data as well as  unauthorized read access to a subset of Oracle GoldenGate Stream Analytics accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14015V-19.1.0.0.0-19.1.0.0.11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14015V-19.1.0.0.0-19.1.0.0.11"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-55163",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
          "text": "38312702"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Cash Management",
          "text": "38312689"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38312788"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38312737"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Supply Chain Finance",
          "text": "38312705"
        },
        {
          "system_name": "Oracle Bug ID of Service Delivery Platform",
          "text": "38312682"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
          "text": "38312786"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Data Integrator",
          "text": "38312740"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38312730"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Netty)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP/2 to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 4.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Security (Netty)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100, 25.1.200 and  25.2.100. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP/2 to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 3.1 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Supply Chain Finance product of Oracle Financial Services Applications (component: Security (Netty)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Banking Supply Chain Finance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Supply Chain Finance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common Core (Netty)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Cash Management product of Oracle Financial Services Applications (component: Accessibility (Netty)).  Supported versions that are affected are 14.5.0.15.0, 14.6.0.11.0, 14.7.0.9.0, 14.8.0.1.0 and  14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Banking Cash Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Cash Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler (Netty)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Service Delivery Platform. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Runtime Java agent (Netty)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Data Integrator. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch (Netty)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Core (Netty)).  Supported versions that are affected are 2.5.0.2.10, 2.6.0.1.9 and  2.6.0.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Network Management System. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-24.3.0",
          "P-13872V-14.6.0.11.0",
          "P-14547V-25.2.100",
          "P-13304V-14.5.0.15.0",
          "P-13872V-14.5.0.15.0",
          "P-14195V-14.6.0.11.0",
          "P-14195V-14.7.0.9.0",
          "P-13872V-14.8.1.0.0",
          "P-13304V-14.6.0.11.0",
          "P-14547V-24.2.0-24.2.1",
          "P-14195V-14.5.0.15.0",
          "P-14195V-14.8.1.0.0",
          "P-13304V-14.8.0.1.0",
          "P-14547V-25.1.200",
          "P-2241V-2.6.0.1.9",
          "P-14547V-25.1.100",
          "P-14597V-6.1.0-6.1.1",
          "P-13872V-14.7.0.9.0",
          "P-2241V-2.5.0.2.10",
          "P-13872V-14.8.0.1.0",
          "P-2241V-2.6.0.2.5",
          "P-13304V-14.8.1.0.0",
          "P-13304V-14.7.0.9.0",
          "P-14195V-14.8.0.1.0",
          "P-2063V-14.1.2.0.0",
          "P-2196V-12.2.1.4.0",
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.2.100",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863847"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14195V-14.5.0.15.0",
            "P-14195V-14.8.1.0.0",
            "P-13304V-14.8.0.1.0",
            "P-13872V-14.7.0.9.0",
            "P-13872V-14.8.0.1.0",
            "P-13304V-14.8.1.0.0",
            "P-13872V-14.6.0.11.0",
            "P-13304V-14.7.0.9.0",
            "P-13304V-14.5.0.15.0",
            "P-14195V-14.8.0.1.0",
            "P-13872V-14.5.0.15.0",
            "P-14195V-14.6.0.11.0",
            "P-14195V-14.7.0.9.0",
            "P-13872V-14.8.1.0.0",
            "P-13304V-14.6.0.11.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2063V-14.1.2.0.0",
            "P-2196V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU47"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2241V-2.6.0.1.9",
            "P-2241V-2.5.0.2.10",
            "P-2241V-2.6.0.2.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU31"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 3.1,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.2.100",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14195V-14.5.0.15.0",
            "P-14195V-14.8.1.0.0",
            "P-13304V-14.8.0.1.0",
            "P-2241V-2.6.0.1.9",
            "P-13872V-14.7.0.9.0",
            "P-2241V-2.5.0.2.10",
            "P-13872V-14.8.0.1.0",
            "P-2241V-2.6.0.2.5",
            "P-13304V-14.8.1.0.0",
            "P-13872V-14.6.0.11.0",
            "P-13304V-14.7.0.9.0",
            "P-13304V-14.5.0.15.0",
            "P-14195V-14.8.0.1.0",
            "P-2063V-14.1.2.0.0",
            "P-2196V-12.2.1.4.0",
            "P-13872V-14.5.0.15.0",
            "P-14195V-14.6.0.11.0",
            "P-14195V-14.7.0.9.0",
            "P-13872V-14.8.1.0.0",
            "P-13304V-14.6.0.11.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-55753",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Secure Backup",
          "text": "38740545"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38740535"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache HTTP Server)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle Secure Backup (component: Oracle Secure Backup (Apache HTTP Server)).  Supported versions that are affected are 19.1.0.0.0-19.1.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Secure Backup.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Secure Backup accessible data as well as  unauthorized read access to a subset of Oracle Secure Backup accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1",
          "P-1522V-19.1.0.0.0-19.1.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1522V-19.1.0.0.0-19.1.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ]
    },
    {
      "cve": "CVE-2025-55754",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.29",
            "P-5(Oracle Database)V-21.3-21.20"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38640885"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Database (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5(Oracle Database)V-19.3-19.29",
          "P-5(Oracle Database)V-21.3-21.20"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.29",
            "P-5(Oracle Database)V-21.3-21.20"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Oracle Database)V-19.3-19.29",
            "P-5(Oracle Database)V-21.3-21.20"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.29",
            "P-5(Oracle Database)V-21.3-21.20"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-58056",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38312737"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
          "text": "38695312"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Netty)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP/2 to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Netty)).  Supported versions that are affected are 21.3-21.20 and  23.4-23.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate Big Data and Application Adapters.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate Big Data and Application Adapters.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1",
          "P-5760V-23.4-23.10",
          "P-5760V-21.3-21.20"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5760V-23.4-23.10",
            "P-5760V-21.3-21.20"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ]
    },
    {
      "cve": "CVE-2025-58057",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Cloud Native Session Border Controller",
          "text": "38456878"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
          "text": "38695312"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Cloud Native Session Border Controller product of Oracle Communications (component: Security (Netty)).   The supported version that is affected is 25.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Cloud Native Session Border Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Cloud Native Session Border Controller. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Netty)).  Supported versions that are affected are 21.3-21.20 and  23.4-23.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate Big Data and Application Adapters.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate Big Data and Application Adapters.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5760V-23.4-23.10",
          "P-14762V-25.1.0",
          "P-5760V-21.3-21.20"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14762V-25.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU43"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5760V-23.4-23.10",
            "P-5760V-21.3-21.20"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14762V-25.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-58098",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Secure Backup",
          "text": "38740545"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38740535"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache HTTP Server)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle Secure Backup (component: Oracle Secure Backup (Apache HTTP Server)).  Supported versions that are affected are 19.1.0.0.0-19.1.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Secure Backup.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Secure Backup accessible data as well as  unauthorized read access to a subset of Oracle Secure Backup accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1",
          "P-1522V-19.1.0.0.0-19.1.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1522V-19.1.0.0.0-19.1.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-58754",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5757V-23.4-23.10",
            "P-5757V-21.3-21.20"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate",
          "text": "38695224"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle GoldenGate (component: Embedded Web UI for Services (Axios)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5757V-23.4-23.10",
          "P-5757V-21.3-21.20"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5757V-23.4-23.10",
            "P-5757V-21.3-21.20"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5757V-23.4-23.10",
            "P-5757V-21.3-21.20"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5757V-23.4-23.10",
            "P-5757V-21.3-21.20"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-59250",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
          "text": "38695035"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (JDBC Driver for SQL Server)).  Supported versions that are affected are 21.3-21.20 and   23.4-23.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GoldenGate Big Data and Application Adapters.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle GoldenGate Big Data and Application Adapters accessible data as well as  unauthorized access to critical data or complete access to all Oracle GoldenGate Big Data and Application Adapters accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5760V-23.4-23.10",
          "P-5760V-21.3-21.20"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5760V-23.4-23.10",
            "P-5760V-21.3-21.20"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5760V-23.4-23.10",
            "P-5760V-21.3-21.20"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-59375",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "38452618"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38452601"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38452600"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Outside In Technology",
          "text": "38452631"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (LibExpat)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100, 25.1.200 and  25.2.100. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (LibExpat)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (LibExpat)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Core (LibExpat)).  Supported versions that are affected are 8.5.7 and  8.5.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-24.2.0-24.2.1",
          "P-14547V-25.2.100",
          "P-14547V-25.1.200",
          "P-14547V-25.1.100",
          "P-1042(Core)V-12.2.1.4.0",
          "P-1042(Core)V-14.1.2.0.0",
          "P-14597V-6.1.0-6.1.1",
          "P-14547V-24.3.0",
          "P-2276V-8.5.8",
          "P-2276V-8.5.7"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.2.100",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863847"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Core)V-12.2.1.4.0",
            "P-1042(Core)V-14.1.2.0.0",
            "P-2276V-8.5.8",
            "P-2276V-8.5.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.2.100",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-1042(Core)V-12.2.1.4.0",
            "P-1042(Core)V-14.1.2.0.0",
            "P-14547V-24.3.0",
            "P-2276V-8.5.8",
            "P-2276V-8.5.7"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-59419",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
          "text": "38695312"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Netty)).  Supported versions that are affected are 21.3-21.20 and  23.4-23.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate Big Data and Application Adapters.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate Big Data and Application Adapters. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5760V-23.4-23.10",
          "P-5760V-21.3-21.20"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5760V-23.4-23.10",
            "P-5760V-21.3-21.20"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5760V-23.4-23.10",
            "P-5760V-21.3-21.20"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-59775",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Secure Backup",
          "text": "38740545"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38740535"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Secure Backup (component: Oracle Secure Backup (Apache HTTP Server)).  Supported versions that are affected are 19.1.0.0.0-19.1.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Secure Backup.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Secure Backup accessible data as well as  unauthorized read access to a subset of Oracle Secure Backup accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache HTTP Server)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1",
          "P-1522V-19.1.0.0.0-19.1.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1522V-19.1.0.0.0-19.1.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        }
      ]
    },
    {
      "cve": "CVE-2025-5987",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38263975"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Pricing Design Center",
          "text": "38263977"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38263971"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Communications Broker",
          "text": "38594505"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38263978"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (libssh)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications (component: On-premise Deployment (libssh)).  Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0 and  15.1.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Pricing Design Center accessible data as well as  unauthorized read access to a subset of Oracle Communications Pricing Design Center accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (libssh)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Policy Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Policy Management accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications (component: Routing (libssh)).  Supported versions that are affected are 4.2.0 and  5.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Enterprise Communications Broker.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Communications Broker. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Security (libssh)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100, 25.1.200 and  25.2.100. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Network Analytics Data Director accessible data as well as  unauthorized read access to a subset of Oracle Communications Network Analytics Data Director accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-24.2.0-24.2.1",
          "P-14547V-25.2.100",
          "P-14547V-25.1.200",
          "P-10758V-4.2.0",
          "P-10900V-15.0.0.0",
          "P-14547V-25.1.100",
          "P-9437V-15.0.0.0.0",
          "P-9437V-15.0.1.0.0",
          "P-14597V-6.1.0-6.1.1",
          "P-14547V-24.3.0",
          "P-10758V-5.0.0",
          "P-9437V-15.1.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9437V-15.0.0.0.0",
            "P-9437V-15.0.1.0.0",
            "P-9437V-15.1.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU11"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10758V-4.2.0",
            "P-10758V-5.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU40"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.2.100",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863847"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10758V-4.2.0",
            "P-10758V-5.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-6021",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38177043"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (libxml2)).  Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u471-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u471-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU41"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u471-b50"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-6052",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38167626"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (glibc)).  Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u471-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u471-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU41"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u471-b50"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-6069",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
          "text": "38540246"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38496873"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Communications Broker",
          "text": "38540244"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38540250"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Session Border Controller",
          "text": "38540252"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38540251"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the RDBMS (Python) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.20 and  23.4.0-23.26.0. Easily exploitable vulnerability allows high privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS (Python) executes to compromise RDBMS (Python).  Successful attacks of this vulnerability can result in takeover of RDBMS (Python).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications (component: Routing (Python)).  Supported versions that are affected are 4.1.0, 4.2.0 and  5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Communications Broker.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Communications Broker.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Python)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routing (Python)).  Supported versions that are affected are 9.3.0 and  10.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Border Controller.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (Python)).  Supported versions that are affected are 9.0.0, 9.0.1 and  9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security (Python)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10750V-10.0.0",
          "P-10758V-4.2.0",
          "P-4516V-7.7.0",
          "P-10758V-4.1.0",
          "P-4516V-7.8.0",
          "P-14597V-6.1.0-6.1.1",
          "P-5(RDBMS)V-23.4.0-23.26.0",
          "P-10758V-5.0.0",
          "P-10750V-9.3.0",
          "P-10899V-9.0.0",
          "P-10899V-9.0.1",
          "P-10899V-9.1.0",
          "P-5(RDBMS)V-21.3-21.20",
          "P-4516V-8.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.20",
            "P-5(RDBMS)V-23.4.0-23.26.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10758V-4.2.0",
            "P-10758V-4.1.0",
            "P-10758V-5.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU40"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10750V-10.0.0",
            "P-10750V-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU32"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10899V-9.0.0",
            "P-10899V-9.0.1",
            "P-10899V-9.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863843"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0",
            "P-4516V-7.8.0",
            "P-4516V-8.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU9"
        }
      ]
    },
    {
      "cve": "CVE-2025-6075",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38496873"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the RDBMS (Python) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.20 and  23.4.0-23.26.0. Easily exploitable vulnerability allows high privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS (Python) executes to compromise RDBMS (Python).  Successful attacks of this vulnerability can result in takeover of RDBMS (Python).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(RDBMS)V-21.3-21.20",
          "P-5(RDBMS)V-23.4.0-23.26.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.20",
            "P-5(RDBMS)V-23.4.0-23.26.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ]
    },
    {
      "cve": "CVE-2025-61755",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38548511"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the GraalVM Multilingual Engine component of Oracle Database Server.  Supported versions that are affected are 21.3-21.20 and  23.4.0-23.26.0. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via multiple protocols to compromise GraalVM Multilingual Engine.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of GraalVM Multilingual Engine accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(GraalVM Multilingual Engine)V-23.4.0-23.26.0",
          "P-5(GraalVM Multilingual Engine)V-21.3-21.20"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(GraalVM Multilingual Engine)V-23.4.0-23.26.0",
            "P-5(GraalVM Multilingual Engine)V-21.3-21.20"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.1,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(GraalVM Multilingual Engine)V-23.4.0-23.26.0",
            "P-5(GraalVM Multilingual Engine)V-21.3-21.20"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-61795",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.29",
            "P-5(Oracle Database)V-21.3-21.20"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
          "text": "38599941"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
          "text": "38599915"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38640885"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38599925"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
          "text": "38599924"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Graph Server and Client",
          "text": "38599935"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Element Manager",
          "text": "38599923"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38599922"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
          "text": "38599933"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Tomcat)).  Supported versions that are affected are 6.1.0-6.1.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: Third Party (Apache Tomcat)).  Supported versions that are affected are 9.0.0-9.0.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Session Report Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Web UI (Apache Tomcat)).  Supported versions that are affected are 9.0.0-9.0.4. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Element Manager. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (Apache Tomcat)).   The supported version that is affected is 15.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Policy Management. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System, Workbench, Endeca Application Controller (Apache Tomcat)).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Tomcat)).   The supported version that is affected is 8.1.3.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Database (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Tomcat)).  Supported versions that are affected are 20.0.5, 21.0.4, 22.0.2, 23.0.2, 24.0.1 and  25.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle Graph Server and Client (component: Packaging (Apache Tomcat)).  Supported versions that are affected are 24.4.4 and  25.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Graph Server and Client.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Graph Server and Client. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9633(Content Acquisition System, Workbench, Endeca Application Controller)V-11.4.0",
          "P-11513V-25.0.0",
          "P-10900V-15.0.0.0",
          "P-11513V-22.0.2",
          "P-14597V-6.1.0-6.1.1",
          "P-11052V-9.0.0-9.0.4",
          "P-14069V-24.4.4",
          "P-11513V-20.0.5",
          "P-11513V-24.0.1",
          "P-14069V-25.4.0",
          "P-10770V-9.0.0-9.0.4",
          "P-11513V-23.0.2",
          "P-14276V-8.1.3.2",
          "P-11513V-21.0.4"
        ],
        "known_not_affected": [
          "P-5(Oracle Database)V-19.3-19.29",
          "P-5(Oracle Database)V-21.3-21.20"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10770V-9.0.0-9.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863846"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11052V-9.0.0-9.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863845"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633(Content Acquisition System, Workbench, Endeca Application Controller)V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU49"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14276V-8.1.3.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU50"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14069V-25.4.0",
            "P-5(Oracle Database)V-19.3-19.29",
            "P-5(Oracle Database)V-21.3-21.20",
            "P-14069V-24.4.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11513V-25.0.0",
            "P-11513V-22.0.2",
            "P-11513V-24.0.1",
            "P-11513V-23.0.2",
            "P-11513V-21.0.4",
            "P-11513V-20.0.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU16"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.2,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9633(Content Acquisition System, Workbench, Endeca Application Controller)V-11.4.0",
            "P-11513V-25.0.0",
            "P-10900V-15.0.0.0",
            "P-11513V-22.0.2",
            "P-11052V-9.0.0-9.0.4",
            "P-14069V-24.4.4",
            "P-11513V-20.0.5",
            "P-11513V-24.0.1",
            "P-14069V-25.4.0",
            "P-10770V-9.0.0-9.0.4",
            "P-11513V-23.0.2",
            "P-14276V-8.1.3.2",
            "P-11513V-21.0.4"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Oracle Database)V-19.3-19.29",
            "P-5(Oracle Database)V-21.3-21.20"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.29",
            "P-5(Oracle Database)V-21.3-21.20"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-6395",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38206356"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38206358"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Platform (GnuTLS)).  Supported versions that are affected are 24.2.0-24.2.1, 24.3.0, 25.1.100 and  25.1.200. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director as well as  unauthorized update, insert or delete access to some of Oracle Communications Network Analytics Data Director accessible data.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (GnuTLS)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Policy Management as well as  unauthorized update, insert or delete access to some of Oracle Communications Policy Management accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-24.2.0-24.2.1",
          "P-14547V-24.3.0",
          "P-14547V-25.1.200",
          "P-14547V-25.1.100",
          "P-10900V-15.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0-24.2.1",
            "P-14547V-25.1.200",
            "P-14547V-25.1.100",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863847"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        }
      ]
    },
    {
      "cve": "CVE-2025-64505",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38722250"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38722261"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libpng)).  Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Workbench executes to compromise MySQL Workbench.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Workbench accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (libpng)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1",
          "P-4627V-8.0.0-8.0.45"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.45"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        }
      ]
    },
    {
      "cve": "CVE-2025-64506",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38722250"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38722261"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libpng)).  Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Workbench executes to compromise MySQL Workbench.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Workbench accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (libpng)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1",
          "P-4627V-8.0.0-8.0.45"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.45"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        }
      ]
    },
    {
      "cve": "CVE-2025-64718",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38737823"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (node-forge)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 2.4 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.4,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-64720",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38722250"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38722261"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libpng)).  Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Workbench executes to compromise MySQL Workbench.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Workbench accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (libpng)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1",
          "P-4627V-8.0.0-8.0.45"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.45"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        }
      ]
    },
    {
      "cve": "CVE-2025-65018",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38722261"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38722250"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (libpng)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 5.8 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libpng)).  Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Workbench executes to compromise MySQL Workbench.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Workbench accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1",
          "P-4627V-8.0.0-8.0.45"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.45"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4627V-8.0.0-8.0.45"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-65082",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Secure Backup",
          "text": "38740545"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38740535"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache HTTP Server)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle Secure Backup (component: Oracle Secure Backup (Apache HTTP Server)).  Supported versions that are affected are 19.1.0.0.0-19.1.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Secure Backup.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Secure Backup accessible data as well as  unauthorized read access to a subset of Oracle Secure Backup accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1",
          "P-1522V-19.1.0.0.0-19.1.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1522V-19.1.0.0.0-19.1.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1522V-19.1.0.0.0-19.1.0.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-66200",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Secure Backup",
          "text": "38740545"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38740535"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache HTTP Server)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle Secure Backup (component: Oracle Secure Backup (Apache HTTP Server)).  Supported versions that are affected are 19.1.0.0.0-19.1.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Secure Backup.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Secure Backup accessible data as well as  unauthorized read access to a subset of Oracle Secure Backup accessible data.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.1.0-6.1.1",
          "P-1522V-19.1.0.0.0-19.1.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1522V-19.1.0.0.0-19.1.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ]
    },
    {
      "cve": "CVE-2025-66418",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.13"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
          "text": "38740334"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
          "text": "38740322"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Stream Analytics",
          "text": "38740361"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38740327"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (urllib3)).  Supported versions that are affected are 5.2, 6.0 and  6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security (urllib3)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (urllib3)).   The supported version that is affected is 2.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Compliance Studio. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Stream Analytics product of Oracle GoldenGate (component: General (urllib3)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10761V-6.0",
          "P-4516V-7.7.0",
          "P-14392V-2.6.0",
          "P-4516V-7.8.0",
          "P-10761V-5.2",
          "P-10761V-6.1",
          "P-4516V-8.0.0"
        ],
        "known_not_affected": [
          "P-14015V-19.1.0.0.0-19.1.0.0.13"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10761V-6.0",
            "P-10761V-5.2",
            "P-10761V-6.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863848"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0",
            "P-4516V-7.8.0",
            "P-4516V-8.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU9"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14392V-2.6.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863933"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.13"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10761V-6.0",
            "P-4516V-7.7.0",
            "P-14392V-2.6.0",
            "P-4516V-7.8.0",
            "P-10761V-5.2",
            "P-10761V-6.1",
            "P-4516V-8.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14015V-19.1.0.0.0-19.1.0.0.13"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.13"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-66471",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.13"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
          "text": "38740334"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
          "text": "38740322"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Stream Analytics",
          "text": "38740361"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38740327"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Stream Analytics product of Oracle GoldenGate (component: General (urllib3)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (urllib3)).  Supported versions that are affected are 5.2, 6.0 and  6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Operations Monitor.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security (urllib3)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Reports (urllib3)).   The supported version that is affected is 2.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Compliance Studio.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10761V-6.0",
          "P-4516V-7.7.0",
          "P-14392V-2.6.0",
          "P-4516V-7.8.0",
          "P-10761V-5.2",
          "P-10761V-6.1",
          "P-4516V-8.0.0"
        ],
        "known_not_affected": [
          "P-14015V-19.1.0.0.0-19.1.0.0.13"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.13"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10761V-6.0",
            "P-10761V-5.2",
            "P-10761V-6.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863848"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0",
            "P-4516V-7.8.0",
            "P-4516V-8.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU9"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14392V-2.6.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863933"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14015V-19.1.0.0.0-19.1.0.0.13"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.13"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-66516",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
          "text": "38744506"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38744508"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
          "text": "38744492"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
          "text": "38427043"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
          "text": "38744463"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38744523"
        },
        {
          "system_name": "Oracle Bug ID of Primavera Unifier",
          "text": "38744524"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Tika)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Integration (Apache Tika)).  Supported versions that are affected are 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.16, 24.12.0-24.12.12 and  25.12.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  While the vulnerability is in Primavera Unifier, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera Unifier accessible data as well as  unauthorized read access to a subset of Primavera Unifier accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Primavera Unifier. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch (Apache Tika)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications (component: Security (Apache Tika)).  Supported versions that are affected are 7.5.0 and  8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  While the vulnerability is in Oracle Communications Order and Service Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Order and Service Management. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Workbench (Apache Tika)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  While the vulnerability is in Oracle Commerce Guided Search, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Runtime Engine (Apache Tika)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  While the vulnerability is in Oracle Business Process Management Suite, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Business Process Management Suite. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Tika)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  While the vulnerability is in Oracle Middleware Common Libraries and Tools, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5325V-14.1.2.0.0",
          "P-4647V-14.1.2.0.0",
          "P-2270V-8.0.0",
          "P-14597V-6.1.0-6.1.1",
          "P-2270V-7.5.0",
          "P-5325V-12.2.1.4.0",
          "P-10354V-25.12.0",
          "P-10354V-22.12.0-22.12.15",
          "P-9633(Workbench)V-11.4.0",
          "P-10354V-23.12.0-23.12.16",
          "P-10354V-24.12.0-24.12.12",
          "P-10354V-21.12.0-21.12.17",
          "P-4647V-12.2.1.4.0",
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10354V-22.12.0-22.12.15",
            "P-10354V-23.12.0-23.12.16",
            "P-10354V-24.12.0-24.12.12",
            "P-10354V-21.12.0-21.12.17",
            "P-10354V-25.12.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU30"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU47"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2270V-8.0.0",
            "P-2270V-7.5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU5"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633(Workbench)V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU49"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5325V-14.1.2.0.0",
            "P-4647V-14.1.2.0.0",
            "P-4647V-12.2.1.4.0",
            "P-5325V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 8.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-10354V-22.12.0-22.12.15",
            "P-10354V-23.12.0-23.12.16",
            "P-10354V-24.12.0-24.12.12",
            "P-10354V-21.12.0-21.12.17",
            "P-10354V-25.12.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 10.0,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9633(Workbench)V-11.4.0",
            "P-5325V-14.1.2.0.0",
            "P-4647V-14.1.2.0.0",
            "P-2270V-8.0.0",
            "P-4647V-12.2.1.4.0",
            "P-2270V-7.5.0",
            "P-5325V-12.2.1.4.0",
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-66566",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Essbase",
          "text": "38776241"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Essbase (component: Essbase Web Platform (lz4-java)).   The supported version that is affected is 21.8.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Essbase.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Essbase accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4379V-21.8.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4379V-21.8.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4379V-21.8.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-67735",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Graal Development Kit for Micronaut (Nimbus JOSE+JWT)",
          "text": "38790952"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Graal Development Kit for Micronaut (Nimbus JOSE+JWT) component of Oracle Database Server.  Supported versions that are affected are 19.3-19.29 and  23.4.0-23.26.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Graal Development Kit for Micronaut (Nimbus JOSE+JWT).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Graal Development Kit for Micronaut (Nimbus JOSE+JWT) accessible data as well as  unauthorized read access to a subset of Oracle Graal Development Kit for Micronaut (Nimbus JOSE+JWT) accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14599V-19.3-19.29",
          "P-14599V-23.4.0-23.26.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14599V-19.3-19.29",
            "P-14599V-23.4.0-23.26.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14599V-19.3-19.29",
            "P-14599V-23.4.0-23.26.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-68161",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Primavera Gateway",
          "text": "38797880"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
          "text": "38797730"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Integrity",
          "text": "38797620"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Health Sciences Information Manager",
          "text": "38797736"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications IP Service Activator",
          "text": "38797615"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Healthcare Data Repository",
          "text": "38797737"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Healthcare Master Person Index",
          "text": "38797739"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Apache Log4j)).  Supported versions that are affected are 21.12.0-21.12.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Primavera Gateway.  While the vulnerability is in Primavera Gateway, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera Gateway accessible data as well as  unauthorized read access to a subset of Primavera Gateway accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Third Party (Apache Log4j)).  Supported versions that are affected are 19.1.0.0.0-19.1.0.0.20, 21.3-21.20 and  23.4-23.10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle GoldenGate Big Data and Application Adapters.  While the vulnerability is in Oracle GoldenGate Big Data and Application Adapters, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle GoldenGate Big Data and Application Adapters accessible data as well as  unauthorized read access to a subset of Oracle GoldenGate Big Data and Application Adapters accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Health Sciences Information Manager product of Oracle HealthCare Applications (component: Health Record Locator (Apache Log4j)).   The supported version that is affected is 4.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Health Sciences Information Manager.  While the vulnerability is in Oracle Health Sciences Information Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Health Sciences Information Manager accessible data as well as  unauthorized read access to a subset of Oracle Health Sciences Information Manager accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications IP Service Activator product of Oracle Communications (component: Logging (Apache Log4j)).   The supported version that is affected is 7.5.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Communications IP Service Activator.  While the vulnerability is in Oracle Communications IP Service Activator, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications IP Service Activator accessible data as well as  unauthorized read access to a subset of Oracle Communications IP Service Activator accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Integrity product of Oracle Communications (component: Logging (Apache Log4j)).  Supported versions that are affected are 7.3.6, 7.4.0, 7.5.0 and  8.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Communications Network Integrity.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Network Integrity accessible data as well as  unauthorized read access to a subset of Oracle Communications Network Integrity accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Master Person Index product of Oracle HealthCare Applications (component: Master Index Data Manager (Apache Log4j)).  Supported versions that are affected are 5.0.0.0-5.0.9.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Healthcare Master Person Index.  While the vulnerability is in Oracle Healthcare Master Person Index, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Healthcare Master Person Index accessible data as well as  unauthorized read access to a subset of Oracle Healthcare Master Person Index accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR Server (Apache Log4j)).  Supported versions that are affected are 8.2.0.5 and  8.2.0.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Healthcare Data Repository.  While the vulnerability is in Oracle Healthcare Data Repository, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Healthcare Data Repository accessible data as well as  unauthorized read access to a subset of Oracle Healthcare Data Repository accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9177V-4.0.0",
          "P-2261V-7.5.0",
          "P-8575V-5.0.0.0-5.0.9.5",
          "P-5760V-23.4-23.10",
          "P-10605V-21.12.0-21.12.16",
          "P-4491V-7.4.0",
          "P-9161V-8.2.0.6",
          "P-4491V-7.5.0",
          "P-9161V-8.2.0.5",
          "P-5760V-19.1.0.0.0-19.1.0.0.20",
          "P-4491V-7.3.6",
          "P-4491V-8.0.0",
          "P-5760V-21.3-21.20"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10605V-21.12.0-21.12.16"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU30"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5760V-19.1.0.0.0-19.1.0.0.20",
            "P-5760V-23.4-23.10",
            "P-5760V-21.3-21.20"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9177V-4.0.0",
            "P-9161V-8.2.0.6",
            "P-9161V-8.2.0.5",
            "P-8575V-5.0.0.0-5.0.9.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU52"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2261V-7.5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU14"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4491V-7.4.0",
            "P-4491V-7.5.0",
            "P-4491V-7.3.6",
            "P-4491V-8.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU10"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10605V-21.12.0-21.12.16",
            "P-9177V-4.0.0",
            "P-9161V-8.2.0.6",
            "P-9161V-8.2.0.5",
            "P-2261V-7.5.0",
            "P-5760V-19.1.0.0.0-19.1.0.0.20",
            "P-8575V-5.0.0.0-5.0.9.5",
            "P-5760V-23.4-23.10",
            "P-5760V-21.3-21.20"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4491V-7.4.0",
            "P-4491V-7.5.0",
            "P-4491V-7.3.6",
            "P-4491V-8.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-6965",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
          "text": "38608753"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "38720647"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38201043"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager (OpenSearch Dashboards)).  Supported versions that are affected are 17.0-25.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Docker Images (SQLite)).  Supported versions that are affected are 8.4.0-8.4.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in takeover of MySQL Server.  Note: This vulnerability applies to MySQL server docker images and SQLite isn't directly used by MySQL server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Porting (SQLite)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-8478(Server: Docker Images)V-8.4.0-8.4.7",
          "P-5085V-8.60",
          "P-14107V-17.0-25.11",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14107V-17.0-25.11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU44"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Docker Images)V-8.4.0-8.4.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU47"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Docker Images)V-8.4.0-8.4.7",
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-14107V-17.0-25.11",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-7424",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38199561"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (libxslt)).  Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u471-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u471-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU41"
        }
      ]
    },
    {
      "cve": "CVE-2025-7425",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38199561"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (libxslt)).  Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u471-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u471-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU41"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u471-b50"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-7962",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Office",
          "text": "38668894"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security (Jakarta Mail)).   The supported version that is affected is 25.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Xstore Office accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11560V-25.0.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11560V-25.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU16"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-11560V-25.0.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-8176",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38645312"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (LibTIFF)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10900V-15.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        }
      ]
    },
    {
      "cve": "CVE-2025-8177",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38645312"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (LibTIFF)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10900V-15.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        }
      ]
    },
    {
      "cve": "CVE-2025-8194",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
          "text": "38540246"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38496873"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Communications Broker",
          "text": "38540244"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38540250"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Session Border Controller",
          "text": "38540252"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38540251"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Automated Test Suite (Python)).  Supported versions that are affected are 9.0.0, 9.0.1 and  9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Python)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications (component: Security (Python)).  Supported versions that are affected are 7.7.0, 7.8.0 and  8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications (component: Routing (Python)).  Supported versions that are affected are 4.1.0, 4.2.0 and  5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Communications Broker.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Communications Broker. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the RDBMS (Python) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.20 and  23.4.0-23.26.0. Easily exploitable vulnerability allows high privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS (Python) executes to compromise RDBMS (Python).  Successful attacks of this vulnerability can result in takeover of RDBMS (Python). CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routing (Python)).  Supported versions that are affected are 9.3.0 and  10.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Border Controller. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10750V-10.0.0",
          "P-4516V-7.7.0",
          "P-10758V-4.2.0",
          "P-4516V-7.8.0",
          "P-10758V-4.1.0",
          "P-14597V-6.1.0-6.1.1",
          "P-10758V-5.0.0",
          "P-5(RDBMS)V-23.4.0-23.26.0",
          "P-10750V-9.3.0",
          "P-10899V-9.0.0",
          "P-10899V-9.0.1",
          "P-10899V-9.1.0",
          "P-5(RDBMS)V-21.3-21.20",
          "P-4516V-8.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10899V-9.0.0",
            "P-10899V-9.0.1",
            "P-10899V-9.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863843"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.7.0",
            "P-4516V-7.8.0",
            "P-4516V-8.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU9"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10758V-4.2.0",
            "P-10758V-4.1.0",
            "P-10758V-5.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU40"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.20",
            "P-5(RDBMS)V-23.4.0-23.26.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10750V-10.0.0",
            "P-10750V-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU32"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10750V-10.0.0",
            "P-4516V-7.7.0",
            "P-10758V-4.2.0",
            "P-4516V-7.8.0",
            "P-10758V-4.1.0",
            "P-4516V-8.0.0",
            "P-10758V-5.0.0",
            "P-10750V-9.3.0",
            "P-10899V-9.0.0",
            "P-10899V-9.0.1",
            "P-10899V-9.1.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 6.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5(RDBMS)V-21.3-21.20",
            "P-5(RDBMS)V-23.4.0-23.26.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-8291",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38496873"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the RDBMS (Python) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.20 and  23.4.0-23.26.0. Easily exploitable vulnerability allows high privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS (Python) executes to compromise RDBMS (Python).  Successful attacks of this vulnerability can result in takeover of RDBMS (Python).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(RDBMS)V-21.3-21.20",
          "P-5(RDBMS)V-23.4.0-23.26.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.20",
            "P-5(RDBMS)V-23.4.0-23.26.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ]
    },
    {
      "cve": "CVE-2025-8732",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38177043"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (libxml2)).  Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u471-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u471-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU41"
        }
      ]
    },
    {
      "cve": "CVE-2025-8869",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38496873"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the RDBMS (Python) component of Oracle Database Server.  Supported versions that are affected are 21.3-21.20 and  23.4.0-23.26.0. Easily exploitable vulnerability allows high privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS (Python) executes to compromise RDBMS (Python).  Successful attacks of this vulnerability can result in takeover of RDBMS (Python).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(RDBMS)V-21.3-21.20",
          "P-5(RDBMS)V-23.4.0-23.26.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS)V-21.3-21.20",
            "P-5(RDBMS)V-23.4.0-23.26.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ]
    },
    {
      "cve": "CVE-2025-8885",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-2025V-7.6.0.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "38634559"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security (Bouncy Castle Java Library)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-2025V-7.6.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-7.6.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1314"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-2025V-7.6.0.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-2025V-7.6.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-8916",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38676050"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
          "text": "38557615"
        },
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "38366209"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (Bouncy Castle Java Library)).  Supported versions that are affected are 17.0-25.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Security (Bouncy Castle Java Library)).  Supported versions that are affected are 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0, 4.4.0.4.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4 and  25.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Utilities Application Framework.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Utilities Application Framework. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Bouncy Castle Java Library)).  Supported versions that are affected are 6.1.0-6.1.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 2.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2245V-4.5.0.1.1",
          "P-2245V-4.5.0.2.0",
          "P-14597V-6.1.0-6.1.1",
          "P-2245V-4.3.0.6.0",
          "P-2245V-4.5.0.0.0",
          "P-2245V-4.4.0.0.0",
          "P-2245V-4.4.0.2.0",
          "P-2245V-4.4.0.3.0",
          "P-2245V-4.4.0.4.0",
          "P-2245V-4.5.0.1.3",
          "P-2245V-25.4",
          "P-2245V-25.10",
          "P-9019V-17.0-25.9"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-17.0-25.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU44"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2245V-4.5.0.1.3",
            "P-2245V-4.5.0.1.1",
            "P-2245V-4.5.0.2.0",
            "P-2245V-25.4",
            "P-2245V-4.3.0.6.0",
            "P-2245V-4.5.0.0.0",
            "P-2245V-25.10",
            "P-2245V-4.4.0.0.0",
            "P-2245V-4.4.0.2.0",
            "P-2245V-4.4.0.3.0",
            "P-2245V-4.4.0.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU31"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.1.0-6.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU7"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-2245V-4.5.0.1.3",
            "P-2245V-4.5.0.1.1",
            "P-2245V-4.5.0.2.0",
            "P-2245V-25.4",
            "P-2245V-4.3.0.6.0",
            "P-2245V-4.5.0.0.0",
            "P-2245V-25.10",
            "P-9019V-17.0-25.9",
            "P-2245V-4.4.0.0.0",
            "P-2245V-4.4.0.2.0",
            "P-2245V-4.4.0.3.0",
            "P-2245V-4.4.0.4.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 2.4,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.1.0-6.1.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-8961",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38645312"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (LibTIFF)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10900V-15.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        }
      ]
    },
    {
      "cve": "CVE-2025-9086",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
          "text": "38448041"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Enterprise Backup",
          "text": "38448033"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38448069"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Enterprise Backup product of Oracle MySQL (component: Enterprise Backup (curl)).  Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and  9.0.0-9.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Enterprise Backup.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Enterprise Backup. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: File Processing (curl)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: MDEX, Forge (curl)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4629V-8.0.0-8.0.43",
          "P-4629V-8.4.0-8.4.6",
          "P-9633(MDEX, Forge)V-11.4.0",
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-4629V-9.0.0-9.4.0",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4629V-8.0.0-8.0.43",
            "P-4629V-8.4.0-8.4.6",
            "P-4629V-9.0.0-9.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU47"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633(MDEX, Forge)V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU49"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4629V-8.0.0-8.0.43",
            "P-4629V-8.4.0-8.4.6",
            "P-9633(MDEX, Forge)V-11.4.0",
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-4629V-9.0.0-9.4.0",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-9230",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5(Oracle Database Security)V-23.4.0-23.26.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Banking Cash Management",
          "text": "38511597"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Enterprise Backup",
          "text": "38511585"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38837229"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Connectors",
          "text": "38511584"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Connectors",
          "text": "38511583"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38511589"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "38511587"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38491032"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
          "text": "38511603"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "38624670"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Supply Chain Finance",
          "text": "38511606"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Database Security (OpenSSL) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging (OpenSSL)).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (OpenSSL)).  Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Cash Management product of Oracle Financial Services Applications (component: Accessibility (OpenSSL)).   The supported version that is affected is 14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Banking Cash Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Cash Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common Core (OpenSSL)).   The supported version that is affected is 14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Supply Chain Finance product of Oracle Financial Services Applications (component: Security (OpenSSL)).   The supported version that is affected is 14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Banking Supply Chain Finance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Supply Chain Finance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security (OpenSSL)).  Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++ (OpenSSL)).  Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC (OpenSSL)).  Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security (OpenSSL)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Enterprise Backup product of Oracle MySQL (component: Enterprise Backup (OpenSSL)).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise MySQL Enterprise Backup.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Enterprise Backup. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14195V-14.8.1.0.0",
          "P-4629V-8.0.0-8.0.44",
          "P-2025V-12.2.1.4.0",
          "P-8478(Server: Packaging)V-9.0.0-9.5.0",
          "P-8576(Connector/ODBC)V-9.0.0-9.5.0",
          "P-4629V-8.4.0-8.4.7",
          "P-2025V-7.6.0.0.0",
          "P-2025V-8.2.0.0.0",
          "P-13304V-14.8.1.0.0",
          "P-4627V-8.0.0-8.0.45",
          "P-8576(Connector/C++)V-9.0.0-9.5.0",
          "P-4629V-9.0.0-9.5.0",
          "P-8478(Server: Packaging)V-8.0.0-8.0.44",
          "P-13872V-14.8.1.0.0",
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-8478(Server: Packaging)V-8.4.0-8.4.7",
          "P-5085V-8.62"
        ],
        "known_not_affected": [
          "P-5(Oracle Database Security)V-23.4.0-23.26.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Oracle Database Security)V-23.4.0-23.26.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Packaging)V-8.0.0-8.0.44",
            "P-4629V-8.0.0-8.0.44",
            "P-8478(Server: Packaging)V-9.0.0-9.5.0",
            "P-8576(Connector/ODBC)V-9.0.0-9.5.0",
            "P-4629V-8.4.0-8.4.7",
            "P-4627V-8.0.0-8.0.45",
            "P-8576(Connector/C++)V-9.0.0-9.5.0",
            "P-4629V-9.0.0-9.5.0",
            "P-8478(Server: Packaging)V-8.4.0-8.4.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14195V-14.8.1.0.0",
            "P-13304V-14.8.1.0.0",
            "P-13872V-14.8.1.0.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-12.2.1.4.0",
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1314"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU47"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Oracle Database Security)V-23.4.0-23.26.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14195V-14.8.1.0.0",
            "P-4629V-8.0.0-8.0.44",
            "P-2025V-12.2.1.4.0",
            "P-8478(Server: Packaging)V-9.0.0-9.5.0",
            "P-8576(Connector/ODBC)V-9.0.0-9.5.0",
            "P-4629V-8.4.0-8.4.7",
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0",
            "P-13304V-14.8.1.0.0",
            "P-4627V-8.0.0-8.0.45",
            "P-8576(Connector/C++)V-9.0.0-9.5.0",
            "P-4629V-9.0.0-9.5.0",
            "P-8478(Server: Packaging)V-8.0.0-8.0.44",
            "P-13872V-14.8.1.0.0",
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-8478(Server: Packaging)V-8.4.0-8.4.7",
            "P-5085V-8.62"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5(Oracle Database Security)V-23.4.0-23.26.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-9231",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5(Oracle Database Security)V-23.4.0-23.26.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Banking Cash Management",
          "text": "38511597"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38837229"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38491032"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
          "text": "38511603"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Supply Chain Finance",
          "text": "38511606"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security (OpenSSL)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Cash Management product of Oracle Financial Services Applications (component: Accessibility (OpenSSL)).   The supported version that is affected is 14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Banking Cash Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Cash Management.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Database Security (OpenSSL) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Supply Chain Finance product of Oracle Financial Services Applications (component: Security (OpenSSL)).   The supported version that is affected is 14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Banking Supply Chain Finance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Supply Chain Finance.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common Core (OpenSSL)).   The supported version that is affected is 14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14195V-14.8.1.0.0",
          "P-5085V-8.61",
          "P-13872V-14.8.1.0.0",
          "P-13304V-14.8.1.0.0",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ],
        "known_not_affected": [
          "P-5(Oracle Database Security)V-23.4.0-23.26.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU47"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14195V-14.8.1.0.0",
            "P-13872V-14.8.1.0.0",
            "P-13304V-14.8.1.0.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Oracle Database Security)V-23.4.0-23.26.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Oracle Database Security)V-23.4.0-23.26.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5(Oracle Database Security)V-23.4.0-23.26.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-9232",
      "flags": [
        {
          "date": "2026-01-20T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5(Oracle Database Security)V-23.4.0-23.26.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Banking Cash Management",
          "text": "38511597"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Enterprise Backup",
          "text": "38511585"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Connectors",
          "text": "38511584"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38837229"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Connectors",
          "text": "38511583"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "38511589"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38491032"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "38511587"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Liquidity Management",
          "text": "38511603"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "38624670"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Supply Chain Finance",
          "text": "38511606"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security (OpenSSL)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC (OpenSSL)).  Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++ (OpenSSL)).  Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Enterprise Backup product of Oracle MySQL (component: Enterprise Backup (OpenSSL)).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise MySQL Enterprise Backup.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Enterprise Backup.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging (OpenSSL)).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (OpenSSL)).  Supported versions that are affected are 8.0.0-8.0.45. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Cash Management product of Oracle Financial Services Applications (component: Accessibility (OpenSSL)).   The supported version that is affected is 14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Banking Cash Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Cash Management.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Common Core (OpenSSL)).   The supported version that is affected is 14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Banking Liquidity Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Liquidity Management.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Database Security (OpenSSL) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security (OpenSSL)).  Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Supply Chain Finance product of Oracle Financial Services Applications (component: Security (OpenSSL)).   The supported version that is affected is 14.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Banking Supply Chain Finance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Supply Chain Finance.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4629V-8.0.0-8.0.44",
          "P-14195V-14.8.1.0.0",
          "P-2025V-12.2.1.4.0",
          "P-8478(Server: Packaging)V-9.0.0-9.5.0",
          "P-8576(Connector/ODBC)V-9.0.0-9.5.0",
          "P-4629V-8.4.0-8.4.7",
          "P-2025V-7.6.0.0.0",
          "P-2025V-8.2.0.0.0",
          "P-13304V-14.8.1.0.0",
          "P-4627V-8.0.0-8.0.45",
          "P-8576(Connector/C++)V-9.0.0-9.5.0",
          "P-4629V-9.0.0-9.5.0",
          "P-8478(Server: Packaging)V-8.0.0-8.0.44",
          "P-5085V-8.61",
          "P-13872V-14.8.1.0.0",
          "P-5085V-8.60",
          "P-5085V-8.62",
          "P-8478(Server: Packaging)V-8.4.0-8.4.7"
        ],
        "known_not_affected": [
          "P-5(Oracle Database Security)V-23.4.0-23.26.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU47"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4629V-8.0.0-8.0.44",
            "P-8478(Server: Packaging)V-8.0.0-8.0.44",
            "P-8478(Server: Packaging)V-9.0.0-9.5.0",
            "P-8576(Connector/ODBC)V-9.0.0-9.5.0",
            "P-4629V-8.4.0-8.4.7",
            "P-4627V-8.0.0-8.0.45",
            "P-8576(Connector/C++)V-9.0.0-9.5.0",
            "P-4629V-9.0.0-9.5.0",
            "P-8478(Server: Packaging)V-8.4.0-8.4.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14195V-14.8.1.0.0",
            "P-13304V-14.8.1.0.0",
            "P-13872V-14.8.1.0.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Oracle Database Security)V-23.4.0-23.26.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-12.2.1.4.0",
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1314"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Oracle Database Security)V-23.4.0-23.26.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-01-20T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5(Oracle Database Security)V-23.4.0-23.26.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-9900",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38645312"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Configuration Management Platform (LibTIFF)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10900V-15.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KB863844"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10900V-15.0.0.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Patrick Murphy"
          ],
          "organization": "Lockheed Martin Red Team"
        }
      ],
      "cve": "CVE-2026-21922",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Planning and Budgeting Cloud Service",
          "text": "38126803"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent).   The supported version that is affected is 25.04.07. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Planning and Budgeting Cloud Service executes to compromise Oracle Planning and Budgeting Cloud Service.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Planning and Budgeting Cloud Service accessible data.  Note: Update EPM Agent. Please refer to <a href=\"https://docs.oracle.com/en/cloud/saas/enterprise-performance-management-common/diepm/epm_agent_downloading_agent_110x80569d70.html\">Downloading the EPM Agent for more information. CVSS 3.1 Base Score 4.2 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10707V-25.04.07"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10707V-25.04.07"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA812"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.2,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10707V-25.04.07"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21923",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Life Sciences Central Designer",
          "text": "36997450"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Life Sciences Central Designer",
          "text": "36997394"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Life Sciences Central Designer",
          "text": "36997547"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform).   The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences Central Designer.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Life Sciences Central Designer accessible data as well as  unauthorized read access to a subset of Oracle Life Sciences Central Designer accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform).   The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences Central Designer.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Life Sciences Central Designer accessible data as well as  unauthorized read access to a subset of Oracle Life Sciences Central Designer accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform).   The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences Central Designer.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Life Sciences Central Designer accessible data as well as  unauthorized read access to a subset of Oracle Life Sciences Central Designer accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9645(Platform)V-7.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9645(Platform)V-7.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU33"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9645(Platform)V-7.0.1.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Kush Jijania"
          ]
        }
      ],
      "cve": "CVE-2026-21924",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
          "text": "37081498"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General).  Supported versions that are affected are 4.4.0.3.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4 and  25.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Application Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Utilities Application Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Utilities Application Framework accessible data as well as  unauthorized read access to a subset of Oracle Utilities Application Framework accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2245V-4.5.0.1.3",
          "P-2245V-4.5.0.1.1",
          "P-2245V-4.5.0.2.0",
          "P-2245V-25.4",
          "P-2245V-4.5.0.0.0",
          "P-2245V-25.10",
          "P-2245V-4.4.0.3.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2245V-4.5.0.1.3",
            "P-2245V-4.5.0.1.1",
            "P-2245V-4.5.0.2.0",
            "P-2245V-25.4",
            "P-2245V-4.5.0.0.0",
            "P-2245V-25.10",
            "P-2245V-4.4.0.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU31"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-2245V-4.5.0.1.3",
            "P-2245V-4.5.0.1.1",
            "P-2245V-4.5.0.2.0",
            "P-2245V-25.4",
            "P-2245V-4.5.0.0.0",
            "P-2245V-25.10",
            "P-2245V-4.4.0.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21925",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "37085030"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: RMI).  Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and  21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u471",
          "P-856V-21.0.9",
          "P-13497V-21.3.16",
          "P-856V-8u471-b50",
          "P-13497V-21.0.9",
          "P-856V-8u471-perf",
          "P-13497V-17.0.17",
          "P-856V-11.0.29",
          "P-856V-25.0.1",
          "P-856V-17.0.17"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u471",
            "P-856V-21.0.9",
            "P-13497V-21.3.16",
            "P-856V-8u471-b50",
            "P-13497V-21.0.9",
            "P-856V-8u471-perf",
            "P-13497V-17.0.17",
            "P-856V-11.0.29",
            "P-856V-25.0.1",
            "P-856V-17.0.17"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU41"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u471",
            "P-856V-21.0.9",
            "P-13497V-21.3.16",
            "P-856V-8u471-b50",
            "P-13497V-21.0.9",
            "P-856V-8u471-perf",
            "P-13497V-17.0.17",
            "P-856V-11.0.29",
            "P-856V-25.0.1",
            "P-856V-17.0.17"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21926",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "37486025"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-25.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9019V-17.0-25.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-17.0-25.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU44"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9019V-17.0-25.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21927",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Solaris",
          "text": "37508523"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver).   The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Solaris accessible data as well as  unauthorized access to critical data or complete access to all Oracle Solaris accessible data. CVSS 3.1 Base Score 5.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10006V-11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10006V-11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU34"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10006V-11"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Ao Wang"
          ],
          "organization": "Southeast University"
        }
      ],
      "cve": "CVE-2026-21928",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Solaris",
          "text": "37823481"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel).   The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Solaris.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Solaris accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10006V-11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10006V-11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU34"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10006V-11"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21929",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37866044"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser).  Supported versions that are affected are 9.0.0-9.5.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Parser)V-9.0.0-9.5.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Parser)V-9.0.0-9.5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Parser)V-9.0.0-9.5.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21930",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle ZFS Storage Appliance Kit",
          "text": "37896334"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems).   The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS Storage Appliance Kit.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle ZFS Storage Appliance Kit accessible data. CVSS 3.1 Base Score 2.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10026V-8.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10026V-8.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU34"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.3,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10026V-8.8"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Kanika Jalal"
          ]
        },
        {
          "names": [
            "Ved Prabhu"
          ]
        }
      ],
      "cve": "CVE-2026-21931",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle APEX Sample Applications",
          "text": "38007668"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle APEX Sample Applications product of Oracle APEX (component: Brookstrut Sample App).  Supported versions that are affected are 23.2.0, 23.2.1, 24.1.0, 24.2.0 and  24.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle APEX Sample Applications.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle APEX Sample Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle APEX Sample Applications accessible data as well as  unauthorized read access to a subset of Oracle APEX Sample Applications accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1348V-23.2.1",
          "P-1348V-24.1.0",
          "P-1348V-24.2.0",
          "P-1348V-23.2.0",
          "P-1348V-24.2.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1348V-23.2.1",
            "P-1348V-24.1.0",
            "P-1348V-24.2.0",
            "P-1348V-23.2.0",
            "P-1348V-24.2.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1348V-23.2.1",
            "P-1348V-24.1.0",
            "P-1348V-24.2.0",
            "P-1348V-23.2.0",
            "P-1348V-24.2.1"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Mingijung"
          ],
          "organization": "WebSec Lab"
        }
      ],
      "cve": "CVE-2026-21932",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38044180"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: AWT, JavaFX).  Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and  21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.4 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u471",
          "P-856V-21.0.9",
          "P-13497V-21.3.16",
          "P-856V-8u471-b50",
          "P-13497V-21.0.9",
          "P-856V-8u471-perf",
          "P-13497V-17.0.17",
          "P-856V-11.0.29",
          "P-856V-25.0.1",
          "P-856V-17.0.17"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u471",
            "P-856V-21.0.9",
            "P-13497V-21.3.16",
            "P-856V-8u471-b50",
            "P-13497V-21.0.9",
            "P-856V-8u471-perf",
            "P-13497V-17.0.17",
            "P-856V-11.0.29",
            "P-856V-25.0.1",
            "P-856V-17.0.17"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU41"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u471",
            "P-856V-21.0.9",
            "P-13497V-21.3.16",
            "P-856V-8u471-b50",
            "P-13497V-21.0.9",
            "P-856V-8u471-perf",
            "P-13497V-17.0.17",
            "P-856V-11.0.29",
            "P-856V-25.0.1",
            "P-856V-17.0.17"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Zhihui Chen"
          ]
        }
      ],
      "cve": "CVE-2026-21933",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38092279"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking).  Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and  21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u471",
          "P-856V-21.0.9",
          "P-13497V-21.3.16",
          "P-856V-8u471-b50",
          "P-13497V-21.0.9",
          "P-856V-8u471-perf",
          "P-13497V-17.0.17",
          "P-856V-11.0.29",
          "P-856V-25.0.1",
          "P-856V-17.0.17"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u471",
            "P-856V-21.0.9",
            "P-13497V-21.3.16",
            "P-856V-8u471-b50",
            "P-13497V-21.0.9",
            "P-856V-8u471-perf",
            "P-13497V-17.0.17",
            "P-856V-11.0.29",
            "P-856V-25.0.1",
            "P-856V-17.0.17"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU41"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u471",
            "P-856V-21.0.9",
            "P-13497V-21.3.16",
            "P-856V-8u471-b50",
            "P-13497V-21.0.9",
            "P-856V-8u471-perf",
            "P-13497V-17.0.17",
            "P-856V-11.0.29",
            "P-856V-25.0.1",
            "P-856V-17.0.17"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21934",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38123448"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Push Notifications).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU47"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21935",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Solaris",
          "text": "38174621"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver).   The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Solaris accessible data as well as  unauthorized access to critical data or complete access to all Oracle Solaris accessible data. CVSS 3.1 Base Score 5.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10006V-11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10006V-11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU34"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10006V-11"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21936",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "38208188"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Cluster",
          "text": "38770713"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.6.0-7.6.36, 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(InnoDB)V-9.0.0-9.5.0",
          "P-8479V-7.6.0-7.6.36",
          "P-8479V-8.0.0-8.0.44",
          "P-8479V-9.0.0-9.5.0",
          "P-8478(InnoDB)V-8.4.0-8.4.7",
          "P-8479V-8.4.0-8.4.7",
          "P-8478(InnoDB)V-8.0.0-8.0.44"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(InnoDB)V-9.0.0-9.5.0",
            "P-8479V-7.6.0-7.6.36",
            "P-8479V-8.0.0-8.0.44",
            "P-8479V-9.0.0-9.5.0",
            "P-8478(InnoDB)V-8.4.0-8.4.7",
            "P-8479V-8.4.0-8.4.7",
            "P-8478(InnoDB)V-8.0.0-8.0.44"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(InnoDB)V-9.0.0-9.5.0",
            "P-8479V-7.6.0-7.6.36",
            "P-8479V-8.0.0-8.0.44",
            "P-8479V-9.0.0-9.5.0",
            "P-8478(InnoDB)V-8.4.0-8.4.7",
            "P-8479V-8.4.0-8.4.7",
            "P-8478(InnoDB)V-8.0.0-8.0.44"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21937",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "38235957"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: DDL)V-9.0.0-9.5.0",
          "P-8478(Server: DDL)V-8.0.0-8.0.44",
          "P-8478(Server: DDL)V-8.4.0-8.4.7"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: DDL)V-9.0.0-9.5.0",
            "P-8478(Server: DDL)V-8.0.0-8.0.44",
            "P-8478(Server: DDL)V-8.4.0-8.4.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: DDL)V-9.0.0-9.5.0",
            "P-8478(Server: DDL)V-8.0.0-8.0.44",
            "P-8478(Server: DDL)V-8.4.0-8.4.7"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21938",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38237410"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU47"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Akira Hachiya"
          ]
        }
      ],
      "cve": "CVE-2026-21939",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38237952"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the SQLcl component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where SQLcl executes to compromise SQLcl.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of SQLcl. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(SQLcl)V-23.4.0-23.26.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(SQLcl)V-23.4.0-23.26.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.0,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5(SQLcl)V-23.4.0-23.26.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21940",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Agile PLM",
          "text": "38286869"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4461V-9.3.6"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4461V-9.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU46"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4461V-9.3.6"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21941",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "38298692"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-9.0.0-9.5.0",
          "P-8478(Server: Optimizer)V-8.0.0-8.0.44",
          "P-8478(Server: Optimizer)V-8.4.0-8.4.7"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.44",
            "P-8478(Server: Optimizer)V-9.0.0-9.5.0",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.44",
            "P-8478(Server: Optimizer)V-9.0.0-9.5.0",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.7"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21942",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Solaris",
          "text": "38319123"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems).  Supported versions that are affected are 10 and  11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.0 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10006V-10",
          "P-10006V-11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10006V-10",
            "P-10006V-11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU34"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.0,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10006V-10",
            "P-10006V-11"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Muhammad Zeeshan (Xib3rR4dAr)"
          ]
        }
      ],
      "cve": "CVE-2026-21943",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Scripting",
          "text": "38326852"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: Scripting Admin).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Scripting, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Scripting accessible data as well as  unauthorized read access to a subset of Oracle Scripting accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-433V-12.2.3-12.2.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-433V-12.2.3-12.2.15"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA923"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-433V-12.2.3-12.2.15"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "haidv35 (Dinh Viet Hai)"
          ],
          "organization": "Viettel Cyber Security"
        }
      ],
      "cve": "CVE-2026-21944",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Agile Product Lifecycle Management for Process",
          "text": "38404744"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management).   The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4445V-6.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4445V-6.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU46"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4445V-6.2.4"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Ireneusz Pastusiak"
          ]
        }
      ],
      "cve": "CVE-2026-21945",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38409729"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security).  Supported versions that are affected are Oracle Java SE: 8u471, 8u471-b50, 8u471-perf, 11.0.29, 17.0.17, 21.0.9, 25.0.1; Oracle GraalVM for JDK: 17.0.17 and  21.0.9; Oracle GraalVM Enterprise Edition: 21.3.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u471",
          "P-856V-21.0.9",
          "P-13497V-21.3.16",
          "P-856V-8u471-b50",
          "P-13497V-21.0.9",
          "P-856V-8u471-perf",
          "P-13497V-17.0.17",
          "P-856V-11.0.29",
          "P-856V-25.0.1",
          "P-856V-17.0.17"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u471",
            "P-856V-21.0.9",
            "P-13497V-21.3.16",
            "P-856V-8u471-b50",
            "P-13497V-21.0.9",
            "P-856V-8u471-perf",
            "P-13497V-17.0.17",
            "P-856V-11.0.29",
            "P-856V-25.0.1",
            "P-856V-17.0.17"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU41"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u471",
            "P-856V-21.0.9",
            "P-13497V-21.3.16",
            "P-856V-8u471-b50",
            "P-13497V-21.0.9",
            "P-856V-8u471-perf",
            "P-13497V-17.0.17",
            "P-856V-11.0.29",
            "P-856V-25.0.1",
            "P-856V-17.0.17"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21946",
      "ids": [
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "38416408"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC).  Supported versions that are affected are 9.2.0.0-9.2.26.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4781V-9.2.0.0-9.2.26.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.26.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU45"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4781V-9.2.0.0-9.2.26.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21947",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38431947"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX).  Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u471-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u471-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU41"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.1,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u471-b50"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Ryan Brothers"
          ]
        }
      ],
      "cve": "CVE-2026-21948",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "38448700"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-9.0.0-9.5.0",
          "P-8478(Server: Optimizer)V-8.0.0-8.0.44",
          "P-8478(Server: Optimizer)V-8.4.0-8.4.7"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.44",
            "P-8478(Server: Optimizer)V-9.0.0-9.5.0",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.44",
            "P-8478(Server: Optimizer)V-9.0.0-9.5.0",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.7"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Jingzhou Fu"
          ],
          "organization": "WingTecher Lab"
        },
        {
          "names": [
            "Zhiyong Wu"
          ],
          "organization": "WingTecher Lab"
        }
      ],
      "cve": "CVE-2026-21949",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "38465147"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-9.0.0-9.5.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-9.0.0-9.5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-9.0.0-9.5.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Jingzhou Fu"
          ],
          "organization": "WingTecher Lab"
        },
        {
          "names": [
            "Zhiyong Wu"
          ],
          "organization": "WingTecher Lab"
        }
      ],
      "cve": "CVE-2026-21950",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "38465178"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-9.0.0-9.5.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-9.0.0-9.5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-9.0.0-9.5.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21951",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "38468852"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU47"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21952",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "38483735"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser).  Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Parser)V-9.0.0-9.5.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Parser)V-9.0.0-9.5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Parser)V-9.0.0-9.5.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "VMBreakers (Gangmin Kim, Sangbin Kim, Un3xploitable) working with Trend Micro Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2026-21955",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38507844"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.14 and  7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.14",
          "P-8370V-7.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU48"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "VMBreakers (Gangmin Kim, Sangbin Kim, Un3xploitable) working with Trend Micro Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2026-21956",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38507952"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.14 and  7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.14",
          "P-8370V-7.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU48"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "NiNi (terrynini38514) from DEVCORE Research Team working with Trend Micro Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2026-21957",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38507964"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.14 and  7.2.4. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.14",
          "P-8370V-7.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU48"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Alexander Kornbrust"
          ],
          "organization": "Red Database Security"
        }
      ],
      "cve": "CVE-2026-21958",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Key Vault",
          "text": "38233683"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Key Vault (component: General Server/Appliance). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-10221V-21.1.0.0.0-21.11.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10221V-21.1.0.0.0-21.11.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10221V-21.1.0.0.0-21.11.0.0.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Maxime Escourbiac"
          ],
          "organization": "Michelin CERT"
        },
        {
          "names": [
            "Yassine Bengana"
          ],
          "organization": "Michelin CERT"
        }
      ],
      "cve": "CVE-2026-21959",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Workflow",
          "text": "38510999"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Loader).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Workflow.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Workflow accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-174V-12.2.3-12.2.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-174V-12.2.3-12.2.15"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA923"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-174V-12.2.3-12.2.15"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Maxime Escourbiac"
          ],
          "organization": "Michelin CERT"
        },
        {
          "names": [
            "Yassine Bengana"
          ],
          "organization": "Michelin CERT"
        }
      ],
      "cve": "CVE-2026-21960",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Applications DBA",
          "text": "38511010"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Java utils).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications DBA.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Applications DBA accessible data as well as  unauthorized access to critical data or complete access to all Oracle Applications DBA accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-166V-12.2.3-12.2.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-166V-12.2.3-12.2.15"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA923"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-166V-12.2.3-12.2.15"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21961",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise HCM Human Resources",
          "text": "38520309"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Company Dir / Org Chart Viewer, Employee Snapshot).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human Resources.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise HCM Human Resources, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM Human Resources accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise HCM Human Resources accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5071V-9.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5071V-9.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU47"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5071V-9.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21962",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in",
          "text": "38647125"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in.  While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as  unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data.  Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1042(Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS)V-14.1.2.0.0",
          "P-1042(Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS)V-14.1.1.0.0",
          "P-1042(Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS)V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS)V-12.2.1.4.0",
            "P-1042(Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS)V-14.1.2.0.0",
            "P-1042(Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS)V-14.1.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1396"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 10.0,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1042(Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS)V-12.2.1.4.0",
            "P-1042(Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS)V-14.1.2.0.0",
            "P-1042(Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS)V-14.1.1.0.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Viettel Cyber Security working with Trend Micro Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2026-21963",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38535134"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.14 and  7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.14",
          "P-8370V-7.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU48"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.0,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21964",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "38549372"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Thread Pooling)V-9.0.0-9.5.0",
          "P-8478(Server: Thread Pooling)V-8.4.0-8.4.7",
          "P-8478(Server: Thread Pooling)V-8.0.0-8.0.44"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Thread Pooling)V-9.0.0-9.5.0",
            "P-8478(Server: Thread Pooling)V-8.4.0-8.4.7",
            "P-8478(Server: Thread Pooling)V-8.0.0-8.0.44"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Thread Pooling)V-9.0.0-9.5.0",
            "P-8478(Server: Thread Pooling)V-8.4.0-8.4.7",
            "P-8478(Server: Thread Pooling)V-8.0.0-8.0.44"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21965",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "38560000"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth).  Supported versions that are affected are 9.0.0-9.5.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Pluggable Auth)V-9.0.0-9.5.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Pluggable Auth)V-9.0.0-9.5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Pluggable Auth)V-9.0.0-9.5.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "PwC HK Darklab"
          ]
        }
      ],
      "cve": "CVE-2026-21966",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Hospitality OPERA 5 Property Services",
          "text": "38568128"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera).  Supported versions that are affected are 5.6.19, 5.6.25, 5.6.26 and  5.6.27. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality OPERA 5 Property Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hospitality OPERA 5 Property Services accessible data as well as  unauthorized read access to a subset of Oracle Hospitality OPERA 5 Property Services accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11580V-5.6.19",
          "P-11580V-5.6.25",
          "P-11580V-5.6.26",
          "P-11580V-5.6.27"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11580V-5.6.19",
            "P-11580V-5.6.25",
            "P-11580V-5.6.26",
            "P-11580V-5.6.27"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU28"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-11580V-5.6.19",
            "P-11580V-5.6.25",
            "P-11580V-5.6.26",
            "P-11580V-5.6.27"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "PwC HK Darklab"
          ]
        }
      ],
      "cve": "CVE-2026-21967",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Hospitality OPERA 5 Property Services",
          "text": "38568130"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera Servlet).  Supported versions that are affected are 5.6.19, 5.6.25, 5.6.26 and  5.6.27. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hospitality OPERA 5 Property Services accessible data as well as  unauthorized update, insert or delete access to some of Oracle Hospitality OPERA 5 Property Services accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality OPERA 5 Property Services. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11580V-5.6.19",
          "P-11580V-5.6.25",
          "P-11580V-5.6.26",
          "P-11580V-5.6.27"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11580V-5.6.19",
            "P-11580V-5.6.25",
            "P-11580V-5.6.26",
            "P-11580V-5.6.27"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU28"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.6,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-11580V-5.6.19",
            "P-11580V-5.6.25",
            "P-11580V-5.6.26",
            "P-11580V-5.6.27"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Anton Fedorov"
          ]
        }
      ],
      "cve": "CVE-2026-21968",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "38573285"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.44, 8.4.0-8.4.7 and  9.0.0-9.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-9.0.0-9.5.0",
          "P-8478(Server: Optimizer)V-8.0.0-8.0.44",
          "P-8478(Server: Optimizer)V-8.4.0-8.4.7"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.44",
            "P-8478(Server: Optimizer)V-9.0.0-9.5.0",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU27"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.44",
            "P-8478(Server: Optimizer)V-9.0.0-9.5.0",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.7"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Zpt_dxpn"
          ],
          "organization": "Pentest Team Viettel Cyber Security"
        }
      ],
      "cve": "CVE-2026-21969",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Agile Product Lifecycle Management for Process",
          "text": "38625660"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal).   The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process.  Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4447V-6.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4447V-6.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU46"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4447V-6.2.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21970",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Life Sciences Central Designer",
          "text": "34492316"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform).   The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Life Sciences Central Designer.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Life Sciences Central Designer accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9645V-7.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9645V-7.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU33"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9645V-7.0.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21971",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise SCM Purchasing",
          "text": "38675664"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise SCM Purchasing product of Oracle PeopleSoft (component: Purchasing).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise SCM Purchasing accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise SCM Purchasing accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5133V-9.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5133V-9.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU47"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5133V-9.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21972",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Configurator",
          "text": "38694216"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: User Interface).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Configurator.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Configurator accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-31V-12.2.3-12.2.15"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-31V-12.2.3-12.2.15"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA923"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-31V-12.2.3-12.2.15"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Kritnarong Samertung"
          ]
        }
      ],
      "cve": "CVE-2026-21973",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle FLEXCUBE Investor Servicing",
          "text": "38118697"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Security Management System).  Supported versions that are affected are 14.5.0.15.0, 14.7.0.8.0 and  14.8.0.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle FLEXCUBE Investor Servicing accessible data as well as  unauthorized access to critical data or complete access to all Oracle FLEXCUBE Investor Servicing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9099V-14.5.0.15.0",
          "P-9099V-14.7.0.8.0",
          "P-9099V-14.8.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9099V-14.5.0.15.0",
            "P-9099V-14.7.0.8.0",
            "P-9099V-14.8.0.1.0"
          ],
          "url": "https://support.oracle.com"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9099V-14.5.0.15.0",
            "P-9099V-14.7.0.8.0",
            "P-9099V-14.8.0.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21974",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Life Sciences Central Designer",
          "text": "34492349"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform).   The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences Central Designer.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Life Sciences Central Designer accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9645V-7.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9645V-7.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU33"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9645V-7.0.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21975",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38659913"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.29 and  21.3-21.20. Easily exploitable vulnerability allows high privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise Java VM.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Java VM. CVSS 3.1 Base Score 4.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(Java VM)V-21.3-21.20",
          "P-5(Java VM)V-19.3-19.29"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Java VM)V-21.3-21.20",
            "P-5(Java VM)V-19.3-19.29"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5(Java VM)V-21.3-21.20",
            "P-5(Java VM)V-19.3-19.29"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21976",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "38750188"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Oracle Analytics Cloud).  Supported versions that are affected are 7.6.0.0.0 and  8.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2025V-7.6.0.0.0",
          "P-2025V-8.2.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA1314"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Alexander Kornbrust"
          ],
          "organization": "Red Database Security"
        }
      ],
      "cve": "CVE-2026-21977",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Zero Data Loss Recovery Appliance Software",
          "text": "38231951"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Zero Data Loss Recovery Appliance Software product of Oracle Zero Data Loss Recovery Appliance (component: Security).  Supported versions that are affected are 23.1.0-23.1.202509. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Zero Data Loss Recovery Appliance Software.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Zero Data Loss Recovery Appliance Software accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11342V-23.1.0-23.1.202509"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11342V-23.1.0-23.1.202509"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU4"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.1,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-11342V-23.1.0-23.1.202509"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Eangly Roeurn"
          ]
        }
      ],
      "cve": "CVE-2026-21978",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle FLEXCUBE Universal Banking",
          "text": "38118739"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Relationship Pricing).  Supported versions that are affected are 14.0.0.0.0-14.8.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9052V-14.0.0.0.0-14.8.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9052V-14.0.0.0.0-14.8.0.0.0"
          ],
          "url": "https://support.oracle.com"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9052V-14.0.0.0.0-14.8.0.0.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Patrick Murphy"
          ],
          "organization": "Lockheed Martin Red Team"
        }
      ],
      "cve": "CVE-2026-21979",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Planning and Budgeting Cloud Service",
          "text": "38126822"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent).   The supported version that is affected is 25.04.07. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Planning and Budgeting Cloud Service executes to compromise Oracle Planning and Budgeting Cloud Service.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Planning and Budgeting Cloud Service accessible data.  Note: Update EPM Agent. Please refer to <a href=\"https://docs.oracle.com/en/cloud/saas/enterprise-performance-management-common/diepm/epm_agent_downloading_agent_110x80569d70.html\">Downloading the EPM Agent for more information. CVSS 3.1 Base Score 4.2 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10707V-25.04.07"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10707V-25.04.07"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=KA812"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.2,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10707V-25.04.07"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2026-21980",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Life Sciences Central Coding",
          "text": "36997432"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Life Sciences Central Coding product of Oracle Health Sciences Applications (component: Platform).   The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences Central Coding.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Life Sciences Central Coding accessible data as well as  unauthorized read access to a subset of Oracle Life Sciences Central Coding accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9644V-7.0.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9644V-7.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU33"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9644V-7.0.1.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Yuhao Jiang"
          ]
        }
      ],
      "cve": "CVE-2026-21981",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38614868"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.14 and  7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 4.6 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.14",
          "P-8370V-7.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU48"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.6,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Ao Wang"
          ],
          "organization": "Southeast University"
        }
      ],
      "cve": "CVE-2026-21982",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38630305"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.14 and  7.2.4. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.14",
          "P-8370V-7.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU48"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Xiaobye (xiaobye_tw)"
          ],
          "organization": "DEVCORE Research Team working with Trend Micro Zero Day Initiative"
        }
      ],
      "cve": "CVE-2026-21983",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38733507"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.14 and  7.2.4. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.14",
          "P-8370V-7.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU48"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "VMBreakers (Gangmin Kim, Sangbin Kim, Un3xploitable) working with Trend Micro Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2026-21984",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38733516"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.14 and  7.2.4. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.14",
          "P-8370V-7.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU48"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Phudq"
          ],
          "organization": "Viettel Cybersecurity working with Trend Zero Day Initiative"
        }
      ],
      "cve": "CVE-2026-21985",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38733520"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.14 and  7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.14",
          "P-8370V-7.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU48"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.0,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Mohammed Ba Rashed"
          ]
        }
      ],
      "cve": "CVE-2026-21986",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38785502"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.14 and  7.2.4. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox.  Note: This vulnerability applies to Windows VMs only. CVSS 3.1 Base Score 7.1 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.14",
          "P-8370V-7.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU48"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Zhenghao Li"
          ],
          "organization": "ISCAS"
        }
      ],
      "cve": "CVE-2026-21987",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38785512"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.14 and  7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.14",
          "P-8370V-7.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU48"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Zhenghao Li"
          ],
          "organization": "ISCAS"
        }
      ],
      "cve": "CVE-2026-21988",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38785516"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.14 and  7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.14",
          "P-8370V-7.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU48"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "fstmpr"
          ]
        }
      ],
      "cve": "CVE-2026-21989",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38785565"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.14 and  7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data as well as  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.14",
          "P-8370V-7.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU48"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "fstmpr"
          ]
        }
      ],
      "cve": "CVE-2026-21990",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38785570"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).  Supported versions that are affected are 7.1.14 and  7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.14",
          "P-8370V-7.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=CPU48"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.2.4",
            "P-8370V-7.1.14"
          ]
        }
      ]
    }
  ]
}