{
  "document": {
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Oracle. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp"
      }
    },
    "publisher": {
      "category": "vendor",
      "name": "Oracle",
      "namespace": "https://www.oracle.com"
    },
    "references": [
      {
        "summary": "URL to html version of Advisory",
        "url": "https://www.oracle.com/security-alerts/cpujul2025.html"
      },
      {
        "category": "self",
        "summary": "URL to CSAF version of Advisory",
        "url": "https://www.oracle.com/docs/tech/security-alerts/cpujul2025csaf.json"
      }
    ],
    "title": "Oracle Critical Patch Update Advisory - July 2025 - Oracle CSAF",
    "tracking": {
      "current_release_date": "2025-07-28T14:00:00-07:00",
      "id": "CPUJul2025csaf",
      "initial_release_date": "2025-07-15T13:00:00-07:00",
      "revision_history": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "number": "1",
          "summary": "Initial Release"
        },
        {
          "date": "2025-07-16T13:00:00-07:00",
          "number": "2",
          "summary": "Updated credit name for CVE-2025-50064 and updated affected versions of Java for CVE-2025-50063"
        },
        {
          "date": "2025-07-23T13:00:00-07:00",
          "number": "3",
          "summary": "Added credit for CVE-2025-50059"
        },
        {
          "date": "2025-07-28T14:00:00-07:00",
          "number": "4",
          "summary": "Updated affected versions of Oracle Database for CVE-2025-30751"
        }
      ],
      "status": "final",
      "version": "4"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Application Express Version 24.2.4",
                    "product": {
                      "name": "Oracle Application Express Version 24.2.4",
                      "product_id": "P-1348V-24.2.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:application_express:24.2.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Application Express Version 24.2.5",
                    "product": {
                      "name": "Oracle Application Express Version 24.2.5",
                      "product_id": "P-1348V-24.2.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:application_express:24.2.5:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Application Express"
              }
            ],
            "category": "product_family",
            "name": "Oracle APEX"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle BI Publisher Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle BI Publisher Version 12.2.1.4.0",
                      "product_id": "P-1479V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle BI Publisher Version 7.6.0.0.0",
                    "product": {
                      "name": "Oracle BI Publisher Version 7.6.0.0.0",
                      "product_id": "P-1479V-7.6.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:bi_publisher:7.6.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle BI Publisher Version 8.2.0.0.0",
                    "product": {
                      "name": "Oracle BI Publisher Version 8.2.0.0.0",
                      "product_id": "P-1479V-8.2.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle BI Publisher"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Business Intelligence Enterprise Edition Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Business Intelligence Enterprise Edition Version 12.2.1.4.0",
                      "product_id": "P-2025V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Business Intelligence Enterprise Edition Version 7.6.0.0.0",
                    "product": {
                      "name": "Oracle Business Intelligence Enterprise Edition Version 7.6.0.0.0",
                      "product_id": "P-2025V-7.6.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:business_intelligence:7.6.0.0.0:*:*:*:enterprise:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Business Intelligence Enterprise Edition Version 8.2.0.0.0",
                    "product": {
                      "name": "Oracle Business Intelligence Enterprise Edition Version 8.2.0.0.0",
                      "product_id": "P-2025V-8.2.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Business Intelligence Enterprise Edition"
              }
            ],
            "category": "product_family",
            "name": "Oracle Analytics"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Autonomous Health Framework Version 24.11.0-25.4.0",
                    "product": {
                      "name": "Autonomous Health Framework Version 24.11.0-25.4.0",
                      "product_id": "P-14634V-24.11.0-25.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:autonomous_health_framework:24.11.0-25.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Autonomous Health Framework"
              }
            ],
            "category": "product_family",
            "name": "Oracle Autonomous Health Framework"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Blockchain Platform Version 21.4.3",
                    "product": {
                      "name": "Oracle Blockchain Platform Version 21.4.3",
                      "product_id": "P-13444V-21.4.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:blockchain_platform:21.4.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Blockchain Platform Version 24.1.3",
                    "product": {
                      "name": "Oracle Blockchain Platform Version 24.1.3",
                      "product_id": "P-13444V-24.1.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:blockchain_platform:24.1.3:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Blockchain Platform"
              }
            ],
            "category": "product_family",
            "name": "Oracle Blockchain Platform"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Commerce Guided Search(Developer Studio, Forge) Version 11.4.0",
                    "product": {
                      "name": "Oracle Commerce Guided Search(Developer Studio, Forge) Version 11.4.0",
                      "product_id": "P-9633(Developer Studio, Forge)V-11.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:commerce_guided_search:11.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Commerce Guided Search"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Commerce Guided Search Platform Services(Forge) Version 11.4.0",
                    "product": {
                      "name": "Oracle Commerce Guided Search Platform Services(Forge) Version 11.4.0",
                      "product_id": "P-9633(Forge)V-11.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:commerce_guided_search_platform_services:11.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Commerce Guided Search Platform Services"
              }
            ],
            "category": "product_family",
            "name": "Oracle Commerce"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Automated Test Suite Version 24.2.4",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Automated Test Suite Version 24.2.4",
                      "product_id": "P-14488V-24.2.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:24.2.4:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Automated Test Suite"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Cloud Native Core Binding Support Function Version 24.2.0-24.2.3",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Binding Support Function Version 24.2.0-24.2.3",
                      "product_id": "P-14121V-24.2.0-24.2.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:24.2.0-24.2.3:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Binding Support Function"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Console Version 24.2.4",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Console Version 24.2.4",
                      "product_id": "P-14250V-24.2.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_console:24.2.4:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Console"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core DBTier Version 24.2.5",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core DBTier Version 24.2.5",
                      "product_id": "P-14974V-24.2.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_dbtier:24.2.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core DBTier Version 24.3.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core DBTier Version 24.3.0",
                      "product_id": "P-14974V-24.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_dbtier:24.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core DBTier Version 25.1.100",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core DBTier Version 25.1.100",
                      "product_id": "P-14974V-25.1.100",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_dbtier:25.1.100:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core DBTier"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Data Analytics Function Version 22.4.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Data Analytics Function Version 22.4.0",
                      "product_id": "P-14489V-22.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_data_analytics_function:22.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Data Analytics Function Version 23.1.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Data Analytics Function Version 23.1.0",
                      "product_id": "P-14489V-23.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_data_analytics_function:23.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Data Analytics Function Version 23.4.3",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Data Analytics Function Version 23.4.3",
                      "product_id": "P-14489V-23.4.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_data_analytics_function:23.4.3:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Network Data Analytics Function"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Exposure Function(Platform) Version 24.2.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Exposure Function(Platform) Version 24.2.0",
                      "product_id": "P-14122(Platform)V-24.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:24.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Exposure Function Version 24.2.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Exposure Function Version 24.2.0",
                      "product_id": "P-14122V-24.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:24.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Network Exposure Function"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 25.1.100",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 25.1.100",
                      "product_id": "P-14125V-25.1.100",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:25.1.100:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Repository Function(ATS Framework) Version 24.2.4",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Repository Function(ATS Framework) Version 24.2.4",
                      "product_id": "P-14118(ATS Framework)V-24.2.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:24.2.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Repository Function(Configuration) Version 24.2.4",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Repository Function(Configuration) Version 24.2.4",
                      "product_id": "P-14118(Configuration)V-24.2.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:24.2.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Repository Function(Install/Upgrade) Version 24.2.4",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Repository Function(Install/Upgrade) Version 24.2.4",
                      "product_id": "P-14118(Install/Upgrade)V-24.2.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:24.2.4:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Network Repository Function"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Slice Selection Function Version 24.3.1",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Slice Selection Function Version 24.3.1",
                      "product_id": "P-14130V-24.3.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:24.3.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Network Slice Selection Function"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Cloud Native Core Policy Version 24.2.0-24.2.6",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Policy Version 24.2.0-24.2.6",
                      "product_id": "P-14277V-24.2.0-24.2.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_policy:24.2.0-24.2.6:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Policy"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 24.2.4",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 24.2.4",
                      "product_id": "P-14123V-24.2.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:24.2.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 25.1.100",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 25.1.100",
                      "product_id": "P-14123V-25.1.100",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:25.1.100:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 25.1.101",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 25.1.101",
                      "product_id": "P-14123V-25.1.101",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:25.1.101:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 24.2.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 24.2.0",
                      "product_id": "P-14117V-24.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:24.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 25.1.100",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 25.1.100",
                      "product_id": "P-14117V-25.1.100",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:25.1.100:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Service Communication Proxy"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Core Session Manager Version 9.1.5",
                    "product": {
                      "name": "Oracle Communications Core Session Manager Version 9.1.5",
                      "product_id": "P-10754V-9.1.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_core_session_manager:9.1.5:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Core Session Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Element Manager Version 9.0.0-9.0.4",
                    "product": {
                      "name": "Oracle Communications Element Manager Version 9.0.0-9.0.4",
                      "product_id": "P-11052V-9.0.0-9.0.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_element_manager:9.0.0-9.0.4:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Element Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Analytics Data Director Version 24.2.0",
                    "product": {
                      "name": "Oracle Communications Network Analytics Data Director Version 24.2.0",
                      "product_id": "P-14547V-24.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:24.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Analytics Data Director Version 24.3.0",
                    "product": {
                      "name": "Oracle Communications Network Analytics Data Director Version 24.3.0",
                      "product_id": "P-14547V-24.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:24.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Analytics Data Director Version 25.1.100",
                    "product": {
                      "name": "Oracle Communications Network Analytics Data Director Version 25.1.100",
                      "product_id": "P-14547V-25.1.100",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_analytics_data_director:25.1.100:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Network Analytics Data Director"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Operations Monitor Version 5.1",
                    "product": {
                      "name": "Oracle Communications Operations Monitor Version 5.1",
                      "product_id": "P-10761V-5.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_operations_monitor:5.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Operations Monitor Version 5.2",
                    "product": {
                      "name": "Oracle Communications Operations Monitor Version 5.2",
                      "product_id": "P-10761V-5.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_operations_monitor:5.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Operations Monitor"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Policy Management Version 15.0.0.0",
                    "product": {
                      "name": "Oracle Communications Policy Management Version 15.0.0.0",
                      "product_id": "P-10900V-15.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_policy_management:15.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Policy Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Session Border Controller Version 10.0.0",
                    "product": {
                      "name": "Oracle Communications Session Border Controller Version 10.0.0",
                      "product_id": "P-10750V-10.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_session_border_controller:10.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Session Border Controller Version 9.2.0",
                    "product": {
                      "name": "Oracle Communications Session Border Controller Version 9.2.0",
                      "product_id": "P-10750V-9.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_session_border_controller:9.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Session Border Controller Version 9.3.0",
                    "product": {
                      "name": "Oracle Communications Session Border Controller Version 9.3.0",
                      "product_id": "P-10750V-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_session_border_controller:9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Session Border Controller"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Session Report Manager Version 9.0.0-9.0.4",
                    "product": {
                      "name": "Oracle Communications Session Report Manager Version 9.0.0-9.0.4",
                      "product_id": "P-10770V-9.0.0-9.0.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_session_report_manager:9.0.0-9.0.4:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Session Report Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications User Data Repository Version 15.0.3",
                    "product": {
                      "name": "Oracle Communications User Data Repository Version 15.0.3",
                      "product_id": "P-11108V-15.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_user_data_repository:15.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications User Data Repository"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Communications Broker Version 4.1.0",
                    "product": {
                      "name": "Oracle Enterprise Communications Broker Version 4.1.0",
                      "product_id": "P-10758V-4.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_communications_broker:4.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Communications Broker Version 4.2.0",
                    "product": {
                      "name": "Oracle Enterprise Communications Broker Version 4.2.0",
                      "product_id": "P-10758V-4.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_communications_broker:4.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Communications Broker Version 5.0.0",
                    "product": {
                      "name": "Oracle Enterprise Communications Broker Version 5.0.0",
                      "product_id": "P-10758V-5.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_communications_broker:5.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Enterprise Communications Broker"
              }
            ],
            "category": "product_family",
            "name": "Oracle Communications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications BRM - Elastic Charging Engine Version 12.0.0.4-12.0.0.8",
                    "product": {
                      "name": "Oracle Communications BRM - Elastic Charging Engine Version 12.0.0.4-12.0.0.8",
                      "product_id": "P-9742V-12.0.0.4-12.0.0.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:12.0.0.4-12.0.0.8:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.0.0.0",
                    "product": {
                      "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.0.0.0",
                      "product_id": "P-9742V-15.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.0.1.0",
                    "product": {
                      "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.0.1.0",
                      "product_id": "P-9742V-15.0.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.0.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.1.0.0",
                    "product": {
                      "name": "Oracle Communications BRM - Elastic Charging Engine Version 15.1.0.0",
                      "product_id": "P-9742V-15.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:15.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications BRM - Elastic Charging Engine"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Billing and Revenue Management(SE_VFG_Security_Feature) Version 12.0.0.4.0-12.0.0.8.0",
                    "product": {
                      "name": "Oracle Communications Billing and Revenue Management(SE_VFG_Security_Feature) Version 12.0.0.4.0-12.0.0.8.0",
                      "product_id": "P-2136(SE_VFG_Security_Feature)V-12.0.0.4.0-12.0.0.8.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.4.0-12.0.0.8.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Billing and Revenue Management(SE_VFG_Security_Feature) Version 15.0.0.0.0",
                    "product": {
                      "name": "Oracle Communications Billing and Revenue Management(SE_VFG_Security_Feature) Version 15.0.0.0.0",
                      "product_id": "P-2136(SE_VFG_Security_Feature)V-15.0.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.0.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Billing and Revenue Management(SE_VFG_Security_Feature) Version 15.0.1.0.0",
                    "product": {
                      "name": "Oracle Communications Billing and Revenue Management(SE_VFG_Security_Feature) Version 15.0.1.0.0",
                      "product_id": "P-2136(SE_VFG_Security_Feature)V-15.0.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.0.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Billing and Revenue Management(SE_VFG_Security_Feature) Version 15.1.0.0.0",
                    "product": {
                      "name": "Oracle Communications Billing and Revenue Management(SE_VFG_Security_Feature) Version 15.1.0.0.0",
                      "product_id": "P-2136(SE_VFG_Security_Feature)V-15.1.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_billing_and_revenue_management:15.1.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Billing and Revenue Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Calendar Server Version 8.0.0.8.0",
                    "product": {
                      "name": "Oracle Communications Calendar Server Version 8.0.0.8.0",
                      "product_id": "P-8494V-8.0.0.8.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_calendar_server:8.0.0.8.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Calendar Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Contacts Server Version 8.0.0.9.0",
                    "product": {
                      "name": "Oracle Communications Contacts Server Version 8.0.0.9.0",
                      "product_id": "P-10696V-8.0.0.9.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_contacts_server:8.0.0.9.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Contacts Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Convergence Version 3.0.3.3.0",
                    "product": {
                      "name": "Oracle Communications Convergence Version 3.0.3.3.0",
                      "product_id": "P-8501V-3.0.3.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_convergence:3.0.3.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Convergence Version 3.0.3.4.0",
                    "product": {
                      "name": "Oracle Communications Convergence Version 3.0.3.4.0",
                      "product_id": "P-8501V-3.0.3.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_convergence:3.0.3.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Convergence"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Convergent Charging Controller Version 12.0.3.0.0-12.0.6.0.0",
                    "product": {
                      "name": "Oracle Communications Convergent Charging Controller Version 12.0.3.0.0-12.0.6.0.0",
                      "product_id": "P-12985V-12.0.3.0.0-12.0.6.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_convergent_charging_controller:12.0.3.0.0-12.0.6.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Convergent Charging Controller Version 15.0.0.0.0-15.0.1.0.0",
                    "product": {
                      "name": "Oracle Communications Convergent Charging Controller Version 15.0.0.0.0-15.0.1.0.0",
                      "product_id": "P-12985V-15.0.0.0.0-15.0.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_convergent_charging_controller:15.0.0.0.0-15.0.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Convergent Charging Controller Version 15.1.0.0.0",
                    "product": {
                      "name": "Oracle Communications Convergent Charging Controller Version 15.1.0.0.0",
                      "product_id": "P-12985V-15.1.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_convergent_charging_controller:15.1.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Convergent Charging Controller"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications IP Service Activator Version 7.4.0",
                    "product": {
                      "name": "Oracle Communications IP Service Activator Version 7.4.0",
                      "product_id": "P-2261V-7.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_ip_service_activator:7.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications IP Service Activator Version 7.5.0",
                    "product": {
                      "name": "Oracle Communications IP Service Activator Version 7.5.0",
                      "product_id": "P-2261V-7.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_ip_service_activator:7.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications IP Service Activator"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications MetaSolv Solution Version 6.3.1",
                    "product": {
                      "name": "Oracle Communications MetaSolv Solution Version 6.3.1",
                      "product_id": "P-2267V-6.3.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_metasolv_solution:6.3.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications MetaSolv Solution"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Network Charging and Control Version 12.0.3.0.0-12.0.6.0.0",
                    "product": {
                      "name": "Oracle Communications Network Charging and Control Version 12.0.3.0.0-12.0.6.0.0",
                      "product_id": "P-4623V-12.0.3.0.0-12.0.6.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_charging_and_control:12.0.3.0.0-12.0.6.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Network Charging and Control Version 15.0.0.0.0-15.0.1.0.0",
                    "product": {
                      "name": "Oracle Communications Network Charging and Control Version 15.0.0.0.0-15.0.1.0.0",
                      "product_id": "P-4623V-15.0.0.0.0-15.0.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_charging_and_control:15.0.0.0.0-15.0.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Charging and Control Version 15.1.0.0.0",
                    "product": {
                      "name": "Oracle Communications Network Charging and Control Version 15.1.0.0.0",
                      "product_id": "P-4623V-15.1.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_charging_and_control:15.1.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Network Charging and Control"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Integrity Version 7.3.6",
                    "product": {
                      "name": "Oracle Communications Network Integrity Version 7.3.6",
                      "product_id": "P-4491V-7.3.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Integrity Version 7.4.0",
                    "product": {
                      "name": "Oracle Communications Network Integrity Version 7.4.0",
                      "product_id": "P-4491V-7.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_integrity:7.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Integrity Version 7.5.0",
                    "product": {
                      "name": "Oracle Communications Network Integrity Version 7.5.0",
                      "product_id": "P-4491V-7.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_network_integrity:7.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Network Integrity"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Offline Mediation Controller Version 12.0.0.2-12.0.0.8",
                    "product": {
                      "name": "Oracle Communications Offline Mediation Controller Version 12.0.0.2-12.0.0.8",
                      "product_id": "P-2269V-12.0.0.2-12.0.0.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.2-12.0.0.8:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Offline Mediation Controller Version 15.0.0.0",
                    "product": {
                      "name": "Oracle Communications Offline Mediation Controller Version 15.0.0.0",
                      "product_id": "P-2269V-15.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_offline_mediation_controller:15.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Offline Mediation Controller Version 15.0.0.0-15.0.1.0",
                    "product": {
                      "name": "Oracle Communications Offline Mediation Controller Version 15.0.0.0-15.0.1.0",
                      "product_id": "P-2269V-15.0.0.0-15.0.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_offline_mediation_controller:15.0.0.0-15.0.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Offline Mediation Controller Version 15.0.1.0",
                    "product": {
                      "name": "Oracle Communications Offline Mediation Controller Version 15.0.1.0",
                      "product_id": "P-2269V-15.0.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_offline_mediation_controller:15.0.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Offline Mediation Controller"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Order and Service Management Version 7.4.0",
                    "product": {
                      "name": "Oracle Communications Order and Service Management Version 7.4.0",
                      "product_id": "P-2270V-7.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_order_and_service_management:7.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Order and Service Management Version 7.4.1",
                    "product": {
                      "name": "Oracle Communications Order and Service Management Version 7.4.1",
                      "product_id": "P-2270V-7.4.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_order_and_service_management:7.4.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Order and Service Management Version 7.5.0",
                    "product": {
                      "name": "Oracle Communications Order and Service Management Version 7.5.0",
                      "product_id": "P-2270V-7.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_order_and_service_management:7.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Order and Service Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Unified Assurance Version 6.0.5",
                    "product": {
                      "name": "Oracle Communications Unified Assurance Version 6.0.5",
                      "product_id": "P-14597V-6.0.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_unified_assurance:6.0.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Unified Assurance Version 6.0.5-6.1.0",
                    "product": {
                      "name": "Oracle Communications Unified Assurance Version 6.0.5-6.1.0",
                      "product_id": "P-14597V-6.0.5-6.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_unified_assurance:6.0.5-6.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Unified Assurance"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Unified Inventory Management Version 7.4.0-7.4.2",
                    "product": {
                      "name": "Oracle Communications Unified Inventory Management Version 7.4.0-7.4.2",
                      "product_id": "P-4516V-7.4.0-7.4.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.0-7.4.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Unified Inventory Management Version 7.5.0",
                    "product": {
                      "name": "Oracle Communications Unified Inventory Management Version 7.5.0",
                      "product_id": "P-4516V-7.5.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.5.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Unified Inventory Management Version 7.5.1",
                    "product": {
                      "name": "Oracle Communications Unified Inventory Management Version 7.5.1",
                      "product_id": "P-4516V-7.5.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.5.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Unified Inventory Management Version 7.6.0-7.8.0",
                    "product": {
                      "name": "Oracle Communications Unified Inventory Management Version 7.6.0-7.8.0",
                      "product_id": "P-4516V-7.6.0-7.8.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:communications_unified_inventory_management:7.6.0-7.8.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Unified Inventory Management"
              }
            ],
            "category": "product_family",
            "name": "Oracle Communications Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Primavera P6 Enterprise Project Portfolio Management Version 20.12.0-20.12.21",
                    "product": {
                      "name": "Primavera P6 Enterprise Project Portfolio Management Version 20.12.0-20.12.21",
                      "product_id": "P-5579V-20.12.0-20.12.21",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:20.12.0-20.12.21:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera P6 Enterprise Project Portfolio Management Version 21.12.0-21.12.21",
                    "product": {
                      "name": "Primavera P6 Enterprise Project Portfolio Management Version 21.12.0-21.12.21",
                      "product_id": "P-5579V-21.12.0-21.12.21",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:21.12.0-21.12.21:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera P6 Enterprise Project Portfolio Management Version 22.12.0-22.12.19",
                    "product": {
                      "name": "Primavera P6 Enterprise Project Portfolio Management Version 22.12.0-22.12.19",
                      "product_id": "P-5579V-22.12.0-22.12.19",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:22.12.0-22.12.19:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera P6 Enterprise Project Portfolio Management Version 23.12.0-23.12.13",
                    "product": {
                      "name": "Primavera P6 Enterprise Project Portfolio Management Version 23.12.0-23.12.13",
                      "product_id": "P-5579V-23.12.0-23.12.13",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:23.12.0-23.12.13:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera P6 Enterprise Project Portfolio Management Version 24.12.0-24.12.4",
                    "product": {
                      "name": "Primavera P6 Enterprise Project Portfolio Management Version 24.12.0-24.12.4",
                      "product_id": "P-5579V-24.12.0-24.12.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_p6_enterprise_project_portfolio_management:24.12.0-24.12.4:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Primavera P6 Enterprise Project Portfolio Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Primavera Unifier Version 20.12.0-20.12.16",
                    "product": {
                      "name": "Primavera Unifier Version 20.12.0-20.12.16",
                      "product_id": "P-10354V-20.12.0-20.12.16",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_unifier:20.12.0-20.12.16:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera Unifier Version 21.12.0-21.12.17",
                    "product": {
                      "name": "Primavera Unifier Version 21.12.0-21.12.17",
                      "product_id": "P-10354V-21.12.0-21.12.17",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_unifier:21.12.0-21.12.17:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera Unifier Version 22.12.0-22.12.15",
                    "product": {
                      "name": "Primavera Unifier Version 22.12.0-22.12.15",
                      "product_id": "P-10354V-22.12.0-22.12.15",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_unifier:22.12.0-22.12.15:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera Unifier Version 23.12.0-23.12.14",
                    "product": {
                      "name": "Primavera Unifier Version 23.12.0-23.12.14",
                      "product_id": "P-10354V-23.12.0-23.12.14",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_unifier:23.12.0-23.12.14:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Primavera Unifier Version 24.12.0-24.12.6",
                    "product": {
                      "name": "Primavera Unifier Version 24.12.0-24.12.6",
                      "product_id": "P-10354V-24.12.0-24.12.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:primavera_unifier:24.12.0-24.12.6:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Primavera Unifier"
              }
            ],
            "category": "product_family",
            "name": "Oracle Construction and Engineering"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "JDBC Version 23.4-23.8",
                    "product": {
                      "name": "JDBC Version 23.4-23.8",
                      "product_id": "P-972V-23.4-23.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:jdbc:23.4-23.8:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "JDBC"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Database Server(Oracle Database) Version 19.27",
                    "product": {
                      "name": "Oracle Database Server(Oracle Database) Version 19.27",
                      "product_id": "P-5(Oracle Database)V-19.27",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_:19.27:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Java VM) Version 19.3-19.27",
                    "product": {
                      "name": "Oracle Database Server(Java VM) Version 19.3-19.27",
                      "product_id": "P-5(Java VM)V-19.3-19.27",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_java_vm:19.3-19.27:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Oracle Database Core) Version 19.3-19.27",
                    "product": {
                      "name": "Oracle Database Server(Oracle Database Core) Version 19.3-19.27",
                      "product_id": "P-5(Oracle Database Core)V-19.3-19.27",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_core:19.3-19.27:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Oracle Database Materialized View) Version 19.3-19.27",
                    "product": {
                      "name": "Oracle Database Server(Oracle Database Materialized View) Version 19.3-19.27",
                      "product_id": "P-5(Oracle Database Materialized View)V-19.3-19.27",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_materialized_view:19.3-19.27:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Oracle Database) Version 19.3-19.27",
                    "product": {
                      "name": "Oracle Database Server(Oracle Database) Version 19.3-19.27",
                      "product_id": "P-5(Oracle Database)V-19.3-19.27",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_:19.3-19.27:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Unified Audit) Version 19.3-19.27",
                    "product": {
                      "name": "Oracle Database Server(Unified Audit) Version 19.3-19.27",
                      "product_id": "P-5(Unified Audit)V-19.3-19.27",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_unified_audit:19.3-19.27:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Oracle Spatial and Graph) Version 19.3-19.27",
                    "product": {
                      "name": "Oracle Database Server(Oracle Spatial and Graph) Version 19.3-19.27",
                      "product_id": "P-619(Oracle Spatial and Graph)V-19.3-19.27",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_e_spatial_and_graph:19.3-19.27:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(GraalVM Multilingual Engine) Version 21.3-21.18",
                    "product": {
                      "name": "Oracle Database Server(GraalVM Multilingual Engine) Version 21.3-21.18",
                      "product_id": "P-5(GraalVM Multilingual Engine)V-21.3-21.18",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_graalvm_multilingual_engine:21.3-21.18:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Java VM) Version 21.3-21.18",
                    "product": {
                      "name": "Oracle Database Server(Java VM) Version 21.3-21.18",
                      "product_id": "P-5(Java VM)V-21.3-21.18",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_java_vm:21.3-21.18:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Oracle Database Core) Version 21.3-21.18",
                    "product": {
                      "name": "Oracle Database Server(Oracle Database Core) Version 21.3-21.18",
                      "product_id": "P-5(Oracle Database Core)V-21.3-21.18",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_core:21.3-21.18:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Oracle Database Materialized View) Version 21.3-21.18",
                    "product": {
                      "name": "Oracle Database Server(Oracle Database Materialized View) Version 21.3-21.18",
                      "product_id": "P-5(Oracle Database Materialized View)V-21.3-21.18",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_materialized_view:21.3-21.18:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Oracle Database) Version 21.3-21.18",
                    "product": {
                      "name": "Oracle Database Server(Oracle Database) Version 21.3-21.18",
                      "product_id": "P-5(Oracle Database)V-21.3-21.18",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_:21.3-21.18:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Unified Audit) Version 21.3-21.18",
                    "product": {
                      "name": "Oracle Database Server(Unified Audit) Version 21.3-21.18",
                      "product_id": "P-5(Unified Audit)V-21.3-21.18",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_unified_audit:21.3-21.18:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Oracle Spatial and Graph) Version 21.3-21.18",
                    "product": {
                      "name": "Oracle Database Server(Oracle Spatial and Graph) Version 21.3-21.18",
                      "product_id": "P-619(Oracle Spatial and Graph)V-21.3-21.18",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_e_spatial_and_graph:21.3-21.18:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(OML4Py) Version 21.4-21.18",
                    "product": {
                      "name": "Oracle Database Server(OML4Py) Version 21.4-21.18",
                      "product_id": "P-5(OML4Py)V-21.4-21.18",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_oml4py:21.4-21.18:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(GraalVM Multilingual Engine) Version 23.4-23.8",
                    "product": {
                      "name": "Oracle Database Server(GraalVM Multilingual Engine) Version 23.4-23.8",
                      "product_id": "P-5(GraalVM Multilingual Engine)V-23.4-23.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_graalvm_multilingual_engine:23.4-23.8:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(OML4Py) Version 23.4-23.8",
                    "product": {
                      "name": "Oracle Database Server(OML4Py) Version 23.4-23.8",
                      "product_id": "P-5(OML4Py)V-23.4-23.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_oml4py:23.4-23.8:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Oracle Database Materialized View) Version 23.4-23.8",
                    "product": {
                      "name": "Oracle Database Server(Oracle Database Materialized View) Version 23.4-23.8",
                      "product_id": "P-5(Oracle Database Materialized View)V-23.4-23.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_materialized_view:23.4-23.8:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Oracle Database) Version 23.4-23.8",
                    "product": {
                      "name": "Oracle Database Server(Oracle Database) Version 23.4-23.8",
                      "product_id": "P-5(Oracle Database)V-23.4-23.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_:23.4-23.8:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Unified Audit) Version 23.4-23.8",
                    "product": {
                      "name": "Oracle Database Server(Unified Audit) Version 23.4-23.8",
                      "product_id": "P-5(Unified Audit)V-23.4-23.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_unified_audit:23.4-23.8:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Database Server(Oracle Spatial and Graph) Version 23.4-23.8",
                    "product": {
                      "name": "Oracle Database Server(Oracle Spatial and Graph) Version 23.4-23.8",
                      "product_id": "P-619(Oracle Spatial and Graph)V-23.4-23.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:database_-_e_spatial_and_graph:23.4-23.8:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Database Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Text Version 19.3-19.27",
                    "product": {
                      "name": "Oracle Text Version 19.3-19.27",
                      "product_id": "P-211V-19.3-19.27",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:text:19.3-19.27:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Text Version 21.3-21.18",
                    "product": {
                      "name": "Oracle Text Version 21.3-21.18",
                      "product_id": "P-211V-21.3-21.18",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:text:21.3-21.18:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Text Version 23.4-23.8",
                    "product": {
                      "name": "Oracle Text Version 23.4-23.8",
                      "product_id": "P-211V-23.4-23.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:text:23.4-23.8:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Text"
              }
            ],
            "category": "product_family",
            "name": "Oracle Database Server"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Applications Framework Version 12.2.3-12.2.14",
                    "product": {
                      "name": "Oracle Applications Framework Version 12.2.3-12.2.14",
                      "product_id": "P-1472V-12.2.3-12.2.14",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:applications_framework:12.2.3-12.2.14:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Applications Framework"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle CRM Technical Foundation Version 12.2.11-12.2.13",
                    "product": {
                      "name": "Oracle CRM Technical Foundation Version 12.2.11-12.2.13",
                      "product_id": "P-1199V-12.2.11-12.2.13",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:crm_technical_foundation:12.2.11-12.2.13:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle CRM Technical Foundation"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Lease and Finance Management Version 12.2.13",
                    "product": {
                      "name": "Oracle Lease and Finance Management Version 12.2.13",
                      "product_id": "P-1056V-12.2.13",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:lease_and_finance_management:12.2.13:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Lease and Finance Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle MES for Process Manufacturing Version 12.2.12-12.2.13",
                    "product": {
                      "name": "Oracle MES for Process Manufacturing Version 12.2.12-12.2.13",
                      "product_id": "P-1776V-12.2.12-12.2.13",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mes_for_process_manufacturing:12.2.12-12.2.13:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle MES for Process Manufacturing"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Mobile Field Service Version 12.2.3-12.2.13",
                    "product": {
                      "name": "Oracle Mobile Field Service Version 12.2.3-12.2.13",
                      "product_id": "P-753V-12.2.3-12.2.13",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mobile_field_service:12.2.3-12.2.13:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Mobile Field Service"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Universal Work Queue Version 12.2.3-12.2.14",
                    "product": {
                      "name": "Oracle Universal Work Queue Version 12.2.3-12.2.14",
                      "product_id": "P-778V-12.2.3-12.2.14",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:universal_work_queue:12.2.3-12.2.14:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Universal Work Queue Version 12.2.5-12.2.14",
                    "product": {
                      "name": "Oracle Universal Work Queue Version 12.2.5-12.2.14",
                      "product_id": "P-778V-12.2.5-12.2.14",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:universal_work_queue:12.2.5-12.2.14:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Universal Work Queue"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle iStore Version 12.2.3-12.2.14",
                    "product": {
                      "name": "Oracle iStore Version 12.2.3-12.2.14",
                      "product_id": "P-384V-12.2.3-12.2.14",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:istore:12.2.3-12.2.14:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle iStore"
              }
            ],
            "category": "product_family",
            "name": "Oracle E-Business Suite"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Application Testing Suite Version 13.3.0.1",
                    "product": {
                      "name": "Oracle Application Testing Suite Version 13.3.0.1",
                      "product_id": "P-4622V-13.3.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Application Testing Suite"
              }
            ],
            "category": "product_family",
            "name": "Oracle Enterprise Manager"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Essbase Version 21.7.2.0.0",
                    "product": {
                      "name": "Oracle Essbase Version 21.7.2.0.0",
                      "product_id": "P-4379V-21.7.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:essbase:21.7.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Essbase"
              }
            ],
            "category": "product_family",
            "name": "Oracle Essbase"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Banking Origination Version 14.4.0.0.0-14.7.0.0.0",
                    "product": {
                      "name": "Oracle Banking Origination Version 14.4.0.0.0-14.7.0.0.0",
                      "product_id": "P-14325V-14.4.0.0.0-14.7.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:banking_origination:14.4.0.0.0-14.7.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Banking Origination"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.7.8",
                    "product": {
                      "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.7.8",
                      "product_id": "P-5680V-8.0.7.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.7.8:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.8.5",
                    "product": {
                      "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.8.5",
                      "product_id": "P-5680V-8.0.8.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.8.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.8.6",
                    "product": {
                      "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.8.6",
                      "product_id": "P-5680V-8.0.8.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.8.6:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.1.4",
                    "product": {
                      "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.1.4",
                      "product_id": "P-5680V-8.1.1.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.1.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2.5",
                    "product": {
                      "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2.5",
                      "product_id": "P-5680V-8.1.2.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.2.5:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Financial Services Analytical Applications Infrastructure"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Behavior Detection Platform Version 8.0.8.1",
                    "product": {
                      "name": "Oracle Financial Services Behavior Detection Platform Version 8.0.8.1",
                      "product_id": "P-9190V-8.0.8.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.0.8.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Behavior Detection Platform Version 8.1.2.8",
                    "product": {
                      "name": "Oracle Financial Services Behavior Detection Platform Version 8.1.2.8",
                      "product_id": "P-9190V-8.1.2.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.2.8:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Behavior Detection Platform Version 8.1.2.9",
                    "product": {
                      "name": "Oracle Financial Services Behavior Detection Platform Version 8.1.2.9",
                      "product_id": "P-9190V-8.1.2.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.2.9:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Financial Services Behavior Detection Platform"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Model Management and Governance Version 8.1.2.7",
                    "product": {
                      "name": "Oracle Financial Services Model Management and Governance Version 8.1.2.7",
                      "product_id": "P-14276V-8.1.2.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_model_management_and_governance:8.1.2.7:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Financial Services Model Management and Governance"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition Version 8.0.8",
                    "product": {
                      "name": "Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition Version 8.0.8",
                      "product_id": "P-13789V-8.0.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:financial_services_trade-based_anti_money_laundering:8.0.8:*:*:*:enterprise:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition"
              }
            ],
            "category": "product_family",
            "name": "Oracle Financial Services Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Business Process Management Suite Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Business Process Management Suite Version 12.2.1.4.0",
                      "product_id": "P-5325V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Business Process Management Suite Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle Business Process Management Suite Version 14.1.2.0.0",
                      "product_id": "P-5325V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:business_process_management_suite:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Business Process Management Suite"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Coherence Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Coherence Version 12.2.1.4.0",
                      "product_id": "P-2545V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Coherence Version 14.1.1.0.0",
                    "product": {
                      "name": "Oracle Coherence Version 14.1.1.0.0",
                      "product_id": "P-2545V-14.1.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Coherence Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle Coherence Version 14.1.2.0.0",
                      "product_id": "P-2545V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Coherence"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Data Integrator Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Data Integrator Version 12.2.1.4.0",
                      "product_id": "P-2196V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Data Integrator Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle Data Integrator Version 14.1.2.0.0",
                      "product_id": "P-2196V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:data_integrator:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Data Integrator"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Data Quality Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Enterprise Data Quality Version 12.2.1.4.0",
                      "product_id": "P-9464V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_data_quality:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Data Quality Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle Enterprise Data Quality Version 14.1.2.0.0",
                      "product_id": "P-9464V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:enterprise_data_quality:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Enterprise Data Quality"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Fusion Middleware Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle Fusion Middleware Version 14.1.2.0.0",
                      "product_id": "P-1032V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:fusion_middleware:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Fusion Middleware"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle HTTP Server(Core) Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle HTTP Server(Core) Version 12.2.1.4.0",
                      "product_id": "P-1042(Core)V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle HTTP Server(Mod_Security) Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle HTTP Server(Mod_Security) Version 12.2.1.4.0",
                      "product_id": "P-1042(Mod_Security)V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle HTTP Server(Core) Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle HTTP Server(Core) Version 14.1.2.0.0",
                      "product_id": "P-1042(Core)V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle HTTP Server(Mod_Security) Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle HTTP Server(Mod_Security) Version 14.1.2.0.0",
                      "product_id": "P-1042(Mod_Security)V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:http_server:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle HTTP Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Identity Manager Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Identity Manager Version 12.2.1.4.0",
                      "product_id": "P-1980V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Identity Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle JDeveloper Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle JDeveloper Version 14.1.2.0.0",
                      "product_id": "P-807V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:jdeveloper:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle JDeveloper"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Managed File Transfer Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Managed File Transfer Version 12.2.1.4.0",
                      "product_id": "P-10198V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:managed_file_transfer:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Managed File Transfer"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Middleware Common Libraries and Tools Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Middleware Common Libraries and Tools Version 12.2.1.4.0",
                      "product_id": "P-4647V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Middleware Common Libraries and Tools Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle Middleware Common Libraries and Tools Version 14.1.2.0.0",
                      "product_id": "P-4647V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:middleware_common_libraries_and_tools:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Middleware Common Libraries and Tools"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Outside In Technology Version 8.5.7",
                    "product": {
                      "name": "Oracle Outside In Technology Version 8.5.7",
                      "product_id": "P-2276V-8.5.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:outside_in_technology:8.5.7:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Outside In Technology"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Service Bus Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Service Bus Version 12.2.1.4.0",
                      "product_id": "P-5308V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:service_bus:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Service Bus"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle WebCenter Enterprise Capture Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle WebCenter Enterprise Capture Version 12.2.1.4.0",
                      "product_id": "P-10212V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle WebCenter Enterprise Capture"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle WebCenter Portal Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle WebCenter Portal Version 12.2.1.4.0",
                      "product_id": "P-1696V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle WebCenter Portal"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle WebLogic Server Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle WebLogic Server Version 12.2.1.4.0",
                      "product_id": "P-5242V-12.2.1.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle WebLogic Server Version 14.1.1.0.0",
                    "product": {
                      "name": "Oracle WebLogic Server Version 14.1.1.0.0",
                      "product_id": "P-5242V-14.1.1.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle WebLogic Server Version 14.1.2.0.0",
                    "product": {
                      "name": "Oracle WebLogic Server Version 14.1.2.0.0",
                      "product_id": "P-5242V-14.1.2.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle WebLogic Server"
              }
            ],
            "category": "product_family",
            "name": "Oracle Fusion Middleware"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Big Data and Application Adapters Version 21.3-21.17",
                    "product": {
                      "name": "Oracle GoldenGate Big Data and Application Adapters Version 21.3-21.17",
                      "product_id": "P-5760V-21.3-21.17",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_big_data_and_application_adapters:21.3-21.17:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Big Data and Application Adapters Version 23.4-23.6",
                    "product": {
                      "name": "Oracle GoldenGate Big Data and Application Adapters Version 23.4-23.6",
                      "product_id": "P-5760V-23.4-23.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_big_data_and_application_adapters:23.4-23.6:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Big Data and Application Adapters Version 23.4-23.7",
                    "product": {
                      "name": "Oracle GoldenGate Big Data and Application Adapters Version 23.4-23.7",
                      "product_id": "P-5760V-23.4-23.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_big_data_and_application_adapters:23.4-23.7:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GoldenGate Big Data and Application Adapters"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Stream Analytics Version 19.1.0.0.0-19.1.0.0.11",
                    "product": {
                      "name": "Oracle GoldenGate Stream Analytics Version 19.1.0.0.0-19.1.0.0.11",
                      "product_id": "P-14015V-19.1.0.0.0-19.1.0.0.11",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_stream_analytics:19.1.0.0.0-19.1.0.0.11:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GoldenGate Stream Analytics"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle GoldenGate Studio Version 12.2.0.4.0",
                    "product": {
                      "name": "Oracle GoldenGate Studio Version 12.2.0.4.0",
                      "product_id": "P-10945V-12.2.0.4.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_studio:12.2.0.4.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GoldenGate Studio"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Veridata Version 12.2.1.4.0-12.2.1.4.250331",
                    "product": {
                      "name": "Oracle GoldenGate Veridata Version 12.2.1.4.0-12.2.1.4.250331",
                      "product_id": "P-5758V-12.2.1.4.0-12.2.1.4.250331",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:goldengate_veridata:12.2.1.4.0-12.2.1.4.250331:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GoldenGate Veridata"
              }
            ],
            "category": "product_family",
            "name": "Oracle GoldenGate"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Graph Server and Client Version 24.4.1",
                    "product": {
                      "name": "Graph Server and Client Version 24.4.1",
                      "product_id": "P-14069V-24.4.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graph_server_and_client:24.4.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Graph Server and Client Version 25.1.0",
                    "product": {
                      "name": "Graph Server and Client Version 25.1.0",
                      "product_id": "P-14069V-25.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graph_server_and_client:25.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Graph Server and Client"
              }
            ],
            "category": "product_family",
            "name": "Oracle Graph Server and Client"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Healthcare Master Person Index Version 5.0.0.0-5.0.9.2",
                    "product": {
                      "name": "Oracle Healthcare Master Person Index Version 5.0.0.0-5.0.9.2",
                      "product_id": "P-8575V-5.0.0.0-5.0.9.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:healthcare_master_person_index:5.0.0.0-5.0.9.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Healthcare Master Person Index"
              }
            ],
            "category": "product_family",
            "name": "Oracle HealthCare Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hospitality Cruise Shipboard Property Management System Version 23.1.4",
                    "product": {
                      "name": "Oracle Hospitality Cruise Shipboard Property Management System Version 23.1.4",
                      "product_id": "P-11607V-23.1.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hospitality_cruise_shipboard_property_management_system:23.1.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Hospitality Cruise Shipboard Property Management System Version 23.2.2",
                    "product": {
                      "name": "Oracle Hospitality Cruise Shipboard Property Management System Version 23.2.2",
                      "product_id": "P-11607V-23.2.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hospitality_cruise_shipboard_property_management_system:23.2.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hospitality Cruise Shipboard Property Management System"
              }
            ],
            "category": "product_family",
            "name": "Oracle Hospitality Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hyperion Financial Reporting Version 11.2.20.0.000",
                    "product": {
                      "name": "Oracle Hyperion Financial Reporting Version 11.2.20.0.000",
                      "product_id": "P-8776V-11.2.20.0.000",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.20.0.000:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Financial Reporting"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hyperion Infrastructure Technology Version 11.2.21.0.000",
                    "product": {
                      "name": "Oracle Hyperion Infrastructure Technology Version 11.2.21.0.000",
                      "product_id": "P-4392V-11.2.21.0.000",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.2.21.0.000:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Infrastructure Technology"
              }
            ],
            "category": "product_family",
            "name": "Oracle Hyperion"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Insurance Policy Administration J2EE Version 11.3.0-11.3.2",
                    "product": {
                      "name": "Oracle Insurance Policy Administration J2EE Version 11.3.0-11.3.2",
                      "product_id": "P-5279V-11.3.0-11.3.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.3.0-11.3.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Insurance Policy Administration J2EE Version 11.3.0-12.0.4",
                    "product": {
                      "name": "Oracle Insurance Policy Administration J2EE Version 11.3.0-12.0.4",
                      "product_id": "P-5279V-11.3.0-12.0.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.3.0-12.0.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Insurance Policy Administration J2EE Version 12.0.4",
                    "product": {
                      "name": "Oracle Insurance Policy Administration J2EE Version 12.0.4",
                      "product_id": "P-5279V-12.0.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:insurance_policy_administration_j2ee:12.0.4:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Insurance Policy Administration J2EE"
              }
            ],
            "category": "product_family",
            "name": "Oracle Insurance Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "JD Edwards EnterpriseOne Tools Version 9.2.0.0-9.2.9.3",
                    "product": {
                      "name": "JD Edwards EnterpriseOne Tools Version 9.2.0.0-9.2.9.3",
                      "product_id": "P-4781V-9.2.0.0-9.2.9.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2.0.0-9.2.9.3:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "JD Edwards EnterpriseOne Tools"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "JD Edwards World Security Version A9.4",
                    "product": {
                      "name": "JD Edwards World Security Version A9.4",
                      "product_id": "P-4839V-A9.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:jd_edwards_world_security:a9.4:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "JD Edwards World Security"
              }
            ],
            "category": "product_family",
            "name": "Oracle JD Edwards"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle GraalVM Enterprise Edition Version 21.3.14",
                    "product": {
                      "name": "Oracle GraalVM Enterprise Edition Version 21.3.14",
                      "product_id": "P-13497V-21.3.14",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graalvm:21.3.14:*:*:*:enterprise:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GraalVM Enterprise Edition"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle GraalVM for JDK Version 17.0.15",
                    "product": {
                      "name": "Oracle GraalVM for JDK Version 17.0.15",
                      "product_id": "P-13497V-17.0.15",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graalvm_for_jdk:17.0.15:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle GraalVM for JDK Version 21.0.7",
                    "product": {
                      "name": "Oracle GraalVM for JDK Version 21.0.7",
                      "product_id": "P-13497V-21.0.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graalvm_for_jdk:21.0.7:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle GraalVM for JDK Version 24.0.1",
                    "product": {
                      "name": "Oracle GraalVM for JDK Version 24.0.1",
                      "product_id": "P-13497V-24.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:graalvm_for_jdk:24.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GraalVM for JDK"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version 11.0.27",
                    "product": {
                      "name": "Oracle Java SE Version 11.0.27",
                      "product_id": "P-856V-11.0.27",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:11.0.27:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version 17.0.15",
                    "product": {
                      "name": "Oracle Java SE Version 17.0.15",
                      "product_id": "P-856V-17.0.15",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:17.0.15:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version 21.0.7",
                    "product": {
                      "name": "Oracle Java SE Version 21.0.7",
                      "product_id": "P-856V-21.0.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:21.0.7:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version 24.0.1",
                    "product": {
                      "name": "Oracle Java SE Version 24.0.1",
                      "product_id": "P-856V-24.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:24.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version 8u451",
                    "product": {
                      "name": "Oracle Java SE Version 8u451",
                      "product_id": "P-856V-8u451",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:8u451:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Java SE Version 8u451-b50",
                    "product": {
                      "name": "Oracle Java SE Version 8u451-b50",
                      "product_id": "P-856V-8u451-b50",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:8u451-b50:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version 8u451-perf",
                    "product": {
                      "name": "Oracle Java SE Version 8u451-perf",
                      "product_id": "P-856V-8u451-perf",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:java_se:8u451:*:*:*:enterprise_performance:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Java SE"
              }
            ],
            "category": "product_family",
            "name": "Oracle Java SE"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Client(Client: mysqldump) Version 8.0.0-8.0.42",
                    "product": {
                      "name": "MySQL Client(Client: mysqldump) Version 8.0.0-8.0.42",
                      "product_id": "P-8478(Client: mysqldump)V-8.0.0-8.0.42",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_client:8.0.0-8.0.42:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Client(Client: mysqldump) Version 8.4.0-8.4.5",
                    "product": {
                      "name": "MySQL Client(Client: mysqldump) Version 8.4.0-8.4.5",
                      "product_id": "P-8478(Client: mysqldump)V-8.4.0-8.4.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_client:8.4.0-8.4.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Client(Client: mysqldump) Version 9.0.0-9.3.0",
                    "product": {
                      "name": "MySQL Client(Client: mysqldump) Version 9.0.0-9.3.0",
                      "product_id": "P-8478(Client: mysqldump)V-9.0.0-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_client:9.0.0-9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Client"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 7.6.0-7.6.34",
                    "product": {
                      "name": "MySQL Cluster Version 7.6.0-7.6.34",
                      "product_id": "P-8479V-7.6.0-7.6.34",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_cluster:7.6.0-7.6.34:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 8.0.0-8.0.41",
                    "product": {
                      "name": "MySQL Cluster Version 8.0.0-8.0.41",
                      "product_id": "P-8479V-8.0.0-8.0.41",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.0-8.0.41:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 8.0.0-8.0.42",
                    "product": {
                      "name": "MySQL Cluster Version 8.0.0-8.0.42",
                      "product_id": "P-8479V-8.0.0-8.0.42",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.0.0-8.0.42:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 8.4.0-8.4.4",
                    "product": {
                      "name": "MySQL Cluster Version 8.4.0-8.4.4",
                      "product_id": "P-8479V-8.4.0-8.4.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.4.0-8.4.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 8.4.0-8.4.5",
                    "product": {
                      "name": "MySQL Cluster Version 8.4.0-8.4.5",
                      "product_id": "P-8479V-8.4.0-8.4.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_cluster:8.4.0-8.4.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 9.0.0-9.2.0",
                    "product": {
                      "name": "MySQL Cluster Version 9.0.0-9.2.0",
                      "product_id": "P-8479V-9.0.0-9.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.0.0-9.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 9.0.0-9.3.0",
                    "product": {
                      "name": "MySQL Cluster Version 9.0.0-9.3.0",
                      "product_id": "P-8479V-9.0.0-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_cluster:9.0.0-9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Cluster"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Enterprise Backup Version 8.0.0-8.0.42",
                    "product": {
                      "name": "MySQL Enterprise Backup Version 8.0.0-8.0.42",
                      "product_id": "P-4629V-8.0.0-8.0.42",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_enterprise_backup:8.0.0-8.0.42:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Enterprise Backup Version 8.4.0-8.4.5",
                    "product": {
                      "name": "MySQL Enterprise Backup Version 8.4.0-8.4.5",
                      "product_id": "P-4629V-8.4.0-8.4.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_enterprise_backup:8.4.0-8.4.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Enterprise Backup Version 9.0.0-9.3.0",
                    "product": {
                      "name": "MySQL Enterprise Backup Version 9.0.0-9.3.0",
                      "product_id": "P-4629V-9.0.0-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_enterprise_backup:9.0.0-9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Enterprise Backup"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: DML) Version 8.0.0-8.0.25",
                    "product": {
                      "name": "MySQL Server(Server: DML) Version 8.0.0-8.0.25",
                      "product_id": "P-8478(Server: DML)V-8.0.0-8.0.25",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.25:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(InnoDB) Version 8.0.0-8.0.41",
                    "product": {
                      "name": "MySQL Server(InnoDB) Version 8.0.0-8.0.41",
                      "product_id": "P-8478(InnoDB)V-8.0.0-8.0.41",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.41:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(InnoDB) Version 8.0.0-8.0.42",
                    "product": {
                      "name": "MySQL Server(InnoDB) Version 8.0.0-8.0.42",
                      "product_id": "P-8478(InnoDB)V-8.0.0-8.0.42",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.42:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Components Services) Version 8.0.0-8.0.42",
                    "product": {
                      "name": "MySQL Server(Server: Components Services) Version 8.0.0-8.0.42",
                      "product_id": "P-8478(Server: Components Services)V-8.0.0-8.0.42",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.42:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: DDL) Version 8.0.0-8.0.42",
                    "product": {
                      "name": "MySQL Server(Server: DDL) Version 8.0.0-8.0.42",
                      "product_id": "P-8478(Server: DDL)V-8.0.0-8.0.42",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.42:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: DML) Version 8.0.0-8.0.42",
                    "product": {
                      "name": "MySQL Server(Server: DML) Version 8.0.0-8.0.42",
                      "product_id": "P-8478(Server: DML)V-8.0.0-8.0.42",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.42:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Optimizer) Version 8.0.0-8.0.42",
                    "product": {
                      "name": "MySQL Server(Server: Optimizer) Version 8.0.0-8.0.42",
                      "product_id": "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.42:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Packaging) Version 8.0.0-8.0.42",
                    "product": {
                      "name": "MySQL Server(Server: Packaging) Version 8.0.0-8.0.42",
                      "product_id": "P-8478(Server: Packaging)V-8.0.0-8.0.42",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.42:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Replication) Version 8.0.0-8.0.42",
                    "product": {
                      "name": "MySQL Server(Server: Replication) Version 8.0.0-8.0.42",
                      "product_id": "P-8478(Server: Replication)V-8.0.0-8.0.42",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.42:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Security: Encryption) Version 8.0.0-8.0.42",
                    "product": {
                      "name": "MySQL Server(Server: Security: Encryption) Version 8.0.0-8.0.42",
                      "product_id": "P-8478(Server: Security: Encryption)V-8.0.0-8.0.42",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.42:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Stored Procedure) Version 8.0.0-8.0.42",
                    "product": {
                      "name": "MySQL Server(Server: Stored Procedure) Version 8.0.0-8.0.42",
                      "product_id": "P-8478(Server: Stored Procedure)V-8.0.0-8.0.42",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.42:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Thread Pooling) Version 8.0.0-8.0.42",
                    "product": {
                      "name": "MySQL Server(Server: Thread Pooling) Version 8.0.0-8.0.42",
                      "product_id": "P-8478(Server: Thread Pooling)V-8.0.0-8.0.42",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.0-8.0.42:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "MySQL Server(Server: DDL) Version 8.0.42",
                    "product": {
                      "name": "MySQL Server(Server: DDL) Version 8.0.42",
                      "product_id": "P-8478(Server: DDL)V-8.0.42",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.0.42:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(InnoDB) Version 8.4.0-8.4.4",
                    "product": {
                      "name": "MySQL Server(InnoDB) Version 8.4.0-8.4.4",
                      "product_id": "P-8478(InnoDB)V-8.4.0-8.4.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(InnoDB) Version 8.4.0-8.4.5",
                    "product": {
                      "name": "MySQL Server(InnoDB) Version 8.4.0-8.4.5",
                      "product_id": "P-8478(InnoDB)V-8.4.0-8.4.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Components Services) Version 8.4.0-8.4.5",
                    "product": {
                      "name": "MySQL Server(Server: Components Services) Version 8.4.0-8.4.5",
                      "product_id": "P-8478(Server: Components Services)V-8.4.0-8.4.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: DDL) Version 8.4.0-8.4.5",
                    "product": {
                      "name": "MySQL Server(Server: DDL) Version 8.4.0-8.4.5",
                      "product_id": "P-8478(Server: DDL)V-8.4.0-8.4.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: DML) Version 8.4.0-8.4.5",
                    "product": {
                      "name": "MySQL Server(Server: DML) Version 8.4.0-8.4.5",
                      "product_id": "P-8478(Server: DML)V-8.4.0-8.4.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Optimizer) Version 8.4.0-8.4.5",
                    "product": {
                      "name": "MySQL Server(Server: Optimizer) Version 8.4.0-8.4.5",
                      "product_id": "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Packaging) Version 8.4.0-8.4.5",
                    "product": {
                      "name": "MySQL Server(Server: Packaging) Version 8.4.0-8.4.5",
                      "product_id": "P-8478(Server: Packaging)V-8.4.0-8.4.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Security: Encryption) Version 8.4.0-8.4.5",
                    "product": {
                      "name": "MySQL Server(Server: Security: Encryption) Version 8.4.0-8.4.5",
                      "product_id": "P-8478(Server: Security: Encryption)V-8.4.0-8.4.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Stored Procedure) Version 8.4.0-8.4.5",
                    "product": {
                      "name": "MySQL Server(Server: Stored Procedure) Version 8.4.0-8.4.5",
                      "product_id": "P-8478(Server: Stored Procedure)V-8.4.0-8.4.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Thread Pooling) Version 8.4.0-8.4.5",
                    "product": {
                      "name": "MySQL Server(Server: Thread Pooling) Version 8.4.0-8.4.5",
                      "product_id": "P-8478(Server: Thread Pooling)V-8.4.0-8.4.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.0-8.4.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "MySQL Server(Server: DDL) Version 8.4.5",
                    "product": {
                      "name": "MySQL Server(Server: DDL) Version 8.4.5",
                      "product_id": "P-8478(Server: DDL)V-8.4.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:8.4.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Optimizer) Version 9.0.0-9.1.0",
                    "product": {
                      "name": "MySQL Server(Server: Optimizer) Version 9.0.0-9.1.0",
                      "product_id": "P-8478(Server: Optimizer)V-9.0.0-9.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(InnoDB) Version 9.0.0-9.2.0",
                    "product": {
                      "name": "MySQL Server(InnoDB) Version 9.0.0-9.2.0",
                      "product_id": "P-8478(InnoDB)V-9.0.0-9.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(InnoDB) Version 9.0.0-9.3.0",
                    "product": {
                      "name": "MySQL Server(InnoDB) Version 9.0.0-9.3.0",
                      "product_id": "P-8478(InnoDB)V-9.0.0-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Components Services) Version 9.0.0-9.3.0",
                    "product": {
                      "name": "MySQL Server(Server: Components Services) Version 9.0.0-9.3.0",
                      "product_id": "P-8478(Server: Components Services)V-9.0.0-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: DDL) Version 9.0.0-9.3.0",
                    "product": {
                      "name": "MySQL Server(Server: DDL) Version 9.0.0-9.3.0",
                      "product_id": "P-8478(Server: DDL)V-9.0.0-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: DML) Version 9.0.0-9.3.0",
                    "product": {
                      "name": "MySQL Server(Server: DML) Version 9.0.0-9.3.0",
                      "product_id": "P-8478(Server: DML)V-9.0.0-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Optimizer) Version 9.0.0-9.3.0",
                    "product": {
                      "name": "MySQL Server(Server: Optimizer) Version 9.0.0-9.3.0",
                      "product_id": "P-8478(Server: Optimizer)V-9.0.0-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Packaging) Version 9.0.0-9.3.0",
                    "product": {
                      "name": "MySQL Server(Server: Packaging) Version 9.0.0-9.3.0",
                      "product_id": "P-8478(Server: Packaging)V-9.0.0-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Security: Encryption) Version 9.0.0-9.3.0",
                    "product": {
                      "name": "MySQL Server(Server: Security: Encryption) Version 9.0.0-9.3.0",
                      "product_id": "P-8478(Server: Security: Encryption)V-9.0.0-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Security: LDAP Auth) Version 9.0.0-9.3.0",
                    "product": {
                      "name": "MySQL Server(Server: Security: LDAP Auth) Version 9.0.0-9.3.0",
                      "product_id": "P-8478(Server: Security: LDAP Auth)V-9.0.0-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Stored Procedure) Version 9.0.0-9.3.0",
                    "product": {
                      "name": "MySQL Server(Server: Stored Procedure) Version 9.0.0-9.3.0",
                      "product_id": "P-8478(Server: Stored Procedure)V-9.0.0-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server(Server: Thread Pooling) Version 9.0.0-9.3.0",
                    "product": {
                      "name": "MySQL Server(Server: Thread Pooling) Version 9.0.0-9.3.0",
                      "product_id": "P-8478(Server: Thread Pooling)V-9.0.0-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.0.0-9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "MySQL Server(Server: DDL) Version 9.3.0",
                    "product": {
                      "name": "MySQL Server(Server: DDL) Version 9.3.0",
                      "product_id": "P-8478(Server: DDL)V-9.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_server:9.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Workbench Version 8.0.0-8.0.42",
                    "product": {
                      "name": "MySQL Workbench Version 8.0.0-8.0.42",
                      "product_id": "P-4627V-8.0.0-8.0.42",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:mysql_workbench:8.0.0-8.0.42:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Workbench"
              }
            ],
            "category": "product_family",
            "name": "Oracle MySQL"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle NoSQL Database Version 22.3.51",
                    "product": {
                      "name": "Oracle NoSQL Database Version 22.3.51",
                      "product_id": "P-13373V-22.3.51",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:nosql_database:22.3.51:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle NoSQL Database Version 23.1.38",
                    "product": {
                      "name": "Oracle NoSQL Database Version 23.1.38",
                      "product_id": "P-13373V-23.1.38",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:nosql_database:23.1.38:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle NoSQL Database Version 24.4.9",
                    "product": {
                      "name": "Oracle NoSQL Database Version 24.4.9",
                      "product_id": "P-13373V-24.4.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:nosql_database:24.4.9:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle NoSQL Database"
              }
            ],
            "category": "product_family",
            "name": "Oracle NoSQL Database"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise HCM Global Payroll Core Version 9.2.51",
                    "product": {
                      "name": "PeopleSoft Enterprise HCM Global Payroll Core Version 9.2.51",
                      "product_id": "P-5055V-9.2.51",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_global_payroll_core:9.2.51:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise HCM Global Payroll Core Version 9.2.52",
                    "product": {
                      "name": "PeopleSoft Enterprise HCM Global Payroll Core Version 9.2.52",
                      "product_id": "P-5055V-9.2.52",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_global_payroll_core:9.2.52:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "PeopleSoft Enterprise HCM Global Payroll Core"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise HCM Human Resources Version 9.2",
                    "product": {
                      "name": "PeopleSoft Enterprise HCM Human Resources Version 9.2",
                      "product_id": "P-5071V-9.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_human_resources:9.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "PeopleSoft Enterprise HCM Human Resources"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise PeopleTools Version 8.60",
                    "product": {
                      "name": "PeopleSoft Enterprise PeopleTools Version 8.60",
                      "product_id": "P-5085V-8.60",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.60:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise PeopleTools Version 8.61",
                    "product": {
                      "name": "PeopleSoft Enterprise PeopleTools Version 8.61",
                      "product_id": "P-5085V-8.61",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.61:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise PeopleTools Version 8.62",
                    "product": {
                      "name": "PeopleSoft Enterprise PeopleTools Version 8.62",
                      "product_id": "P-5085V-8.62",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.62:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "PeopleSoft Enterprise PeopleTools"
              }
            ],
            "category": "product_family",
            "name": "Oracle PeopleSoft"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle REST Data Services Version 24.2.0",
                    "product": {
                      "name": "Oracle REST Data Services Version 24.2.0",
                      "product_id": "P-9456V-24.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:rest_data_services:24.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle REST Data Services Version 24.4",
                    "product": {
                      "name": "Oracle REST Data Services Version 24.4",
                      "product_id": "P-9456V-24.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:rest_data_services:24.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle REST Data Services Version 25.1.0",
                    "product": {
                      "name": "Oracle REST Data Services Version 25.1.0",
                      "product_id": "P-9456V-25.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:rest_data_services:25.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle REST Data Services"
              }
            ],
            "category": "product_family",
            "name": "Oracle REST Data Services"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail EFTLink Version 20.0.1",
                    "product": {
                      "name": "Oracle Retail EFTLink Version 20.0.1",
                      "product_id": "P-11516V-20.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_eftlink:20.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail EFTLink Version 21.0.0",
                    "product": {
                      "name": "Oracle Retail EFTLink Version 21.0.0",
                      "product_id": "P-11516V-21.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_eftlink:21.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail EFTLink Version 22.0.0",
                    "product": {
                      "name": "Oracle Retail EFTLink Version 22.0.0",
                      "product_id": "P-11516V-22.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_eftlink:22.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail EFTLink Version 23.0.0",
                    "product": {
                      "name": "Oracle Retail EFTLink Version 23.0.0",
                      "product_id": "P-11516V-23.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_eftlink:23.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail EFTLink"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Extract Tranform and Load Version 13.2.5",
                    "product": {
                      "name": "Oracle Retail Extract Tranform and Load Version 13.2.5",
                      "product_id": "P-1803V-13.2.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_extract_tranform_and_load:13.2.5:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Extract Tranform and Load"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Integration Bus Version 14.1.3.2",
                    "product": {
                      "name": "Oracle Retail Integration Bus Version 14.1.3.2",
                      "product_id": "P-1807V-14.1.3.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_integration_bus:14.1.3.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Integration Bus Version 15.0.3.1",
                    "product": {
                      "name": "Oracle Retail Integration Bus Version 15.0.3.1",
                      "product_id": "P-1807V-15.0.3.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_integration_bus:15.0.3.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Integration Bus Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Integration Bus Version 16.0.3",
                      "product_id": "P-1807V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_integration_bus:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Integration Bus Version 19.0.1",
                    "product": {
                      "name": "Oracle Retail Integration Bus Version 19.0.1",
                      "product_id": "P-1807V-19.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_integration_bus:19.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Integration Bus"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Predictive Application Server Version 15.0.3",
                    "product": {
                      "name": "Oracle Retail Predictive Application Server Version 15.0.3",
                      "product_id": "P-1823V-15.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_predictive_application_server:15.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Predictive Application Server Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Predictive Application Server Version 16.0.3",
                      "product_id": "P-1823V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_predictive_application_server:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Predictive Application Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Service Backbone Version 14.1.3.2",
                    "product": {
                      "name": "Oracle Retail Service Backbone Version 14.1.3.2",
                      "product_id": "P-10867V-14.1.3.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_service_backbone:14.1.3.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Service Backbone Version 15.0.3.1",
                    "product": {
                      "name": "Oracle Retail Service Backbone Version 15.0.3.1",
                      "product_id": "P-10867V-15.0.3.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_service_backbone:15.0.3.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Service Backbone Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Service Backbone Version 16.0.3",
                      "product_id": "P-10867V-16.0.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_service_backbone:16.0.3:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Service Backbone Version 19.0.1",
                    "product": {
                      "name": "Oracle Retail Service Backbone Version 19.0.1",
                      "product_id": "P-10867V-19.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_service_backbone:19.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Service Backbone"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Office Version 20.0.5",
                    "product": {
                      "name": "Oracle Retail Xstore Office Version 20.0.5",
                      "product_id": "P-11560V-20.0.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_office:20.0.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Office Version 21.0.4",
                    "product": {
                      "name": "Oracle Retail Xstore Office Version 21.0.4",
                      "product_id": "P-11560V-21.0.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_office:21.0.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Office Version 22.0.2",
                    "product": {
                      "name": "Oracle Retail Xstore Office Version 22.0.2",
                      "product_id": "P-11560V-22.0.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_office:22.0.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Office Version 23.0.2",
                    "product": {
                      "name": "Oracle Retail Xstore Office Version 23.0.2",
                      "product_id": "P-11560V-23.0.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_office:23.0.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Office Version 24.0.1",
                    "product": {
                      "name": "Oracle Retail Xstore Office Version 24.0.1",
                      "product_id": "P-11560V-24.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_office:24.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Xstore Office"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 20.0.5",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 20.0.5",
                      "product_id": "P-11513V-20.0.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:20.0.5:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 21.0.4",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 21.0.4",
                      "product_id": "P-11513V-21.0.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:21.0.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 22.0.2",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 22.0.2",
                      "product_id": "P-11513V-22.0.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:22.0.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 23.0.2",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 23.0.2",
                      "product_id": "P-11513V-23.0.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:23.0.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 24.0.1",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 24.0.1",
                      "product_id": "P-11513V-24.0.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:retail_xstore_point_of_service:24.0.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Xstore Point of Service"
              }
            ],
            "category": "product_family",
            "name": "Oracle Retail Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Siebel CRM Deployment Version 25.0-25.5",
                    "product": {
                      "name": "Siebel CRM Deployment Version 25.0-25.5",
                      "product_id": "P-9019V-25.0-25.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:siebel_crm_deployment:25.0-25.5:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Siebel CRM Deployment"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Siebel CRM End User Version 25.0-25.5",
                    "product": {
                      "name": "Siebel CRM End User Version 25.0-25.5",
                      "product_id": "P-9011V-25.0-25.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:siebel_crm_end_user:25.0-25.5:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Siebel CRM End User"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Siebel CRM Integration Version 25.0-25.5",
                    "product": {
                      "name": "Siebel CRM Integration Version 25.0-25.5",
                      "product_id": "P-9008V-25.0-25.5",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:siebel_crm_integration:25.0-25.5:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Siebel CRM Integration"
              }
            ],
            "category": "product_family",
            "name": "Oracle Siebel CRM"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Spatial Studio Version 24.1.0",
                    "product": {
                      "name": "Oracle Spatial Studio Version 24.1.0",
                      "product_id": "P-13600V-24.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:spatial_studio:24.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Spatial Studio"
              }
            ],
            "category": "product_family",
            "name": "Oracle Spatial Studio"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Agile Engineering Data Management Version 6.2.1",
                    "product": {
                      "name": "Oracle Agile Engineering Data Management Version 6.2.1",
                      "product_id": "P-4436V-6.2.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Agile Engineering Data Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Agile PLM Version 9.3.6",
                    "product": {
                      "name": "Oracle Agile PLM Version 9.3.6",
                      "product_id": "P-4461V-9.3.6",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Agile PLM"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle AutoVue Version 21.0.2",
                    "product": {
                      "name": "Oracle AutoVue Version 21.0.2",
                      "product_id": "P-4453V-21.0.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:autovue:21.0.2:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle AutoVue Version 21.1.0",
                    "product": {
                      "name": "Oracle AutoVue Version 21.1.0",
                      "product_id": "P-4453V-21.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:autovue:21.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle AutoVue"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Product Lifecycle Analytics Version 3.6.1",
                    "product": {
                      "name": "Oracle Product Lifecycle Analytics Version 3.6.1",
                      "product_id": "P-9387V-3.6.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Product Lifecycle Analytics"
              }
            ],
            "category": "product_family",
            "name": "Oracle Supply Chain"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle TimesTen In-Memory Database Version 18.1.4.52.0",
                    "product": {
                      "name": "Oracle TimesTen In-Memory Database Version 18.1.4.52.0",
                      "product_id": "P-1870V-18.1.4.52.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:timesten_in-memory_database:18.1.4.52.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle TimesTen In-Memory Database Version 22.1.1.32.0",
                    "product": {
                      "name": "Oracle TimesTen In-Memory Database Version 22.1.1.32.0",
                      "product_id": "P-1870V-22.1.1.32.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:timesten_in-memory_database:22.1.1.32.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle TimesTen In-Memory Database"
              }
            ],
            "category": "product_family",
            "name": "Oracle TimesTen In-Memory Database"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Utilities Application Framework Version 24.1.0.0.0-24.3.0.0.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 24.1.0.0.0-24.3.0.0.0",
                      "product_id": "P-2245V-24.1.0.0.0-24.3.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:24.1.0.0.0-24.3.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 25.4",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 25.4",
                      "product_id": "P-2245V-25.4",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:25.4:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.3.0.6.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.3.0.6.0",
                      "product_id": "P-2245V-4.3.0.6.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.3.0.6.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.4.0.0.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.4.0.0.0",
                      "product_id": "P-2245V-4.4.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.4.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.4.0.2.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.4.0.2.0",
                      "product_id": "P-2245V-4.4.0.2.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.4.0.2.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.4.0.3.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.4.0.3.0",
                      "product_id": "P-2245V-4.4.0.3.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.4.0.3.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.5.0.0.0",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.5.0.0.0",
                      "product_id": "P-2245V-4.5.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.5.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.5.0.1.1",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.5.0.1.1",
                      "product_id": "P-2245V-4.5.0.1.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.5.0.1.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Application Framework Version 4.5.0.1.3",
                    "product": {
                      "name": "Oracle Utilities Application Framework Version 4.5.0.1.3",
                      "product_id": "P-2245V-4.5.0.1.3",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_application_framework:4.5.0.1.3:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Utilities Application Framework"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Network Management System Version 2.4.0.1.27",
                    "product": {
                      "name": "Oracle Utilities Network Management System Version 2.4.0.1.27",
                      "product_id": "P-2241V-2.4.0.1.27",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.4.0.1.27:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Network Management System Version 2.5.0.1.15",
                    "product": {
                      "name": "Oracle Utilities Network Management System Version 2.5.0.1.15",
                      "product_id": "P-2241V-2.5.0.1.15",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.5.0.1.15:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Network Management System Version 2.5.0.2.8",
                    "product": {
                      "name": "Oracle Utilities Network Management System Version 2.5.0.2.8",
                      "product_id": "P-2241V-2.5.0.2.8",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.5.0.2.8:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Network Management System Version 2.5.0.2.9",
                    "product": {
                      "name": "Oracle Utilities Network Management System Version 2.5.0.2.9",
                      "product_id": "P-2241V-2.5.0.2.9",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.5.0.2.9:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Network Management System Version 2.6.0.1.7",
                    "product": {
                      "name": "Oracle Utilities Network Management System Version 2.6.0.1.7",
                      "product_id": "P-2241V-2.6.0.1.7",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.6.0.1.7:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Network Management System Version 2.6.0.2.1",
                    "product": {
                      "name": "Oracle Utilities Network Management System Version 2.6.0.2.1",
                      "product_id": "P-2241V-2.6.0.2.1",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.6.0.2.1:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Network Management System Version 2.6.0.2.2",
                    "product": {
                      "name": "Oracle Utilities Network Management System Version 2.6.0.2.2",
                      "product_id": "P-2241V-2.6.0.2.2",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.6.0.2.2:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Utilities Network Management System"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Testing Accelerator Version 7.0.0.0.0",
                    "product": {
                      "name": "Oracle Utilities Testing Accelerator Version 7.0.0.0.0",
                      "product_id": "P-13784V-7.0.0.0.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_testing_accelerator:7.0.0.0.0:*:*:*:*:*:*:*"
                      }
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Testing Accelerator Version 7.0.0.1.0",
                    "product": {
                      "name": "Oracle Utilities Testing Accelerator Version 7.0.0.1.0",
                      "product_id": "P-13784V-7.0.0.1.0",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:utilities_testing_accelerator:7.0.0.1.0:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Utilities Testing Accelerator"
              }
            ],
            "category": "product_family",
            "name": "Oracle Utilities Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle VM VirtualBox Version 7.1.10",
                    "product": {
                      "name": "Oracle VM VirtualBox Version 7.1.10",
                      "product_id": "P-8370V-7.1.10",
                      "product_identification_helper": {
                        "cpe": "cpe:2.3:a:oracle:vm_virtualbox:7.1.10:*:*:*:*:*:*:*"
                      }
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle VM VirtualBox"
              }
            ],
            "category": "product_family",
            "name": "Oracle Virtualization"
          }
        ],
        "category": "vendor",
        "name": "Oracle"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2020-13936",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Studio",
          "text": "33519444"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Studio product of Oracle GoldenGate (component: GoldenGate Studio (Apache Velocity Engine)).   The supported version that is affected is 12.2.0.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate Studio executes to compromise Oracle GoldenGate Studio.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate Studio. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10945V-12.2.0.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10945V-12.2.0.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10945V-12.2.0.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-33813",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Integration",
          "text": "37699953"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI (JDOM)).  Supported versions that are affected are 25.0-25.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Integration. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9008V-25.0-25.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9008V-25.0-25.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092434.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9008V-25.0-25.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-42575",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Agile PLM",
          "text": "35412017"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Web Client (Java HTML Sanitizer)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as  unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4461V-9.3.6"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4461V-9.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4461V-9.3.6"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-34169",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Retail Extract Tranform and Load",
          "text": "36230366"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Product Lifecycle Analytics",
          "text": "36230412"
        },
        {
          "system_name": "Oracle Bug ID of Oracle AutoVue",
          "text": "36230216"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle AutoVue product of Oracle Supply Chain (component: Core (Apache Xalan-Java)).  Supported versions that are affected are 21.0.2 and  21.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle AutoVue.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle AutoVue accessible data.  Note: This vulnerability applies to Oracle AutoVue Office, Oracle AutoVue 2D Professional, Oracle AutoVue 3D Professional Advanced, Oracle AutoVue EDA Professional and Oracle AutoVue Electro-Mechanical Professional. Please refer to Patch Availability Document for more details. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Extract Tranform and Load product of Oracle Retail Applications (component: Mathematical Operators (Apache Xalan-Java)).   The supported version that is affected is 13.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Extract Tranform and Load.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Extract Tranform and Load accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core (Apache Xalan-Java)).   The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4453V-21.0.2",
          "P-4453V-21.1.0",
          "P-9387V-3.6.1",
          "P-1803V-13.2.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4453V-21.0.2",
            "P-4453V-21.1.0",
            "P-9387V-3.6.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092435.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1803V-13.2.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090426.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4453V-21.0.2",
            "P-4453V-21.1.0",
            "P-9387V-3.6.1",
            "P-1803V-13.2.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-45693",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Data Integrator",
          "text": "37955793"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Security (Jettison)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Data Integrator. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2196V-14.1.2.0.0",
          "P-2196V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2196V-12.2.1.4.0",
            "P-2196V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2196V-12.2.1.4.0",
            "P-2196V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-1436",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Text (FreeType)",
          "text": "37684134"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Text (FreeType) component of Oracle Database Server.  Supported versions that are affected are 19.3-19.27, 21.3-21.18 and  23.4-23.8. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Index privilege with network access via Oracle Net to compromise Oracle Text (FreeType).  Successful attacks of this vulnerability can result in takeover of Oracle Text (FreeType). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-211V-21.3-21.18",
          "P-211V-19.3-19.27",
          "P-211V-23.4-23.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-211V-19.3-19.27",
            "P-211V-23.4-23.8",
            "P-211V-21.3-21.18"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-211V-19.3-19.27",
            "P-211V-23.4-23.8",
            "P-211V-21.3-21.18"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-27349",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications User Data Repository",
          "text": "37922847"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Platform Security (BlueZ)).   The supported version that is affected is 15.0.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Communications User Data Repository executes to compromise Oracle Communications User Data Repository.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications User Data Repository. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11108V-15.0.3"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11108V-15.0.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092974.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.0,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-11108V-15.0.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-29162",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-5(Oracle Database Core)V-19.3-19.27",
            "P-5(Oracle Database Core)V-21.3-21.18"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "37566042"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Database Core (Intel C++ Compiler Classic) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-5(Oracle Database Core)V-19.3-19.27",
          "P-5(Oracle Database Core)V-21.3-21.18"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Oracle Database Core)V-19.3-19.27",
            "P-5(Oracle Database Core)V-21.3-21.18"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Oracle Database Core)V-19.3-19.27",
            "P-5(Oracle Database Core)V-21.3-21.18"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-5(Oracle Database Core)V-19.3-19.27",
            "P-5(Oracle Database Core)V-21.3-21.18"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-39017",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-4647V-14.1.2.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
          "text": "37478441"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Quartz)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-4647V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4647V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4647V-14.1.2.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-4647V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-42917",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
          "text": "37828692"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Installer (WebKitGTK)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle WebCenter Enterprise Capture.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10212V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10212V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10212V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-44483",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise HCM Human Resources",
          "text": "35977886"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Core (Apache Santuario XML Security For Java)).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human Resources.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise HCM Human Resources accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5071V-9.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5071V-9.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092433.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5071V-9.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-49582",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Infrastructure Technology",
          "text": "37524577"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration (Apache Portable Runtime)).   The supported version that is affected is 11.2.21.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4392V-11.2.21.0.000"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4392V-11.2.21.0.000"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=2775466.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4392V-11.2.21.0.000"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-51074",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-10945V-12.2.0.4.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37397102"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Studio",
          "text": "37397702"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (JsonPath)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Studio product of Oracle GoldenGate (component: GoldenGate Studio (JsonPath)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14122V-24.2.0"
        ],
        "known_not_affected": [
          "P-10945V-12.2.0.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10945V-12.2.0.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14122V-24.2.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10945V-12.2.0.4.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-10945V-12.2.0.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-5685",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37560905"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Data Analytics Function",
          "text": "37560904"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Data Analytics Function product of Oracle Communications (component: Automated Test Suite (XNIO)).   The supported version that is affected is 22.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Data Analytics Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Data Analytics Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (XNIO)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14122V-24.2.0",
          "P-14489V-22.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14489V-22.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092976.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14122V-24.2.0",
            "P-14489V-22.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2023-7256",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37107926"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (libcap)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Exposure Function executes to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14122V-24.2.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14122V-24.2.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-1135",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
          "text": "37693432"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37693430"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
          "text": "37693440"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
          "text": "37693436"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Data Analytics Function",
          "text": "37693429"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Data Analytics Function product of Oracle Communications (component: Automated Test Suite (Gunicorn)).   The supported version that is affected is 22.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Data Analytics Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Data Analytics Function accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Network Data Analytics Function accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (Gunicorn)).  Supported versions that are affected are 5.1 and  5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Operations Monitor accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: perf-info (Gunicorn)).  Supported versions that are affected are 24.2.4 and  25.1.100. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Install/Upgrade (Gunicorn)).   The supported version that is affected is 24.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Gunicorn)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Exposure Function accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Network Exposure Function accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10761V-5.1",
          "P-14122V-24.2.0",
          "P-10761V-5.2",
          "P-14123V-25.1.100",
          "P-14118(Install/Upgrade)V-24.2.4",
          "P-14489V-22.4.0",
          "P-14123V-24.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14489V-22.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092976.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10761V-5.1",
            "P-10761V-5.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092732.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14123V-25.1.100",
            "P-14123V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092746.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118(Install/Upgrade)V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092975.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14122V-24.2.0",
            "P-14489V-22.4.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10761V-5.1",
            "P-10761V-5.2",
            "P-14123V-25.1.100",
            "P-14118(Install/Upgrade)V-24.2.4",
            "P-14123V-24.2.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-12133",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "37847497"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37847500"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
          "text": "37847501"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
          "text": "37847502"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
          "text": "37847503"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "37847504"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
          "text": "37847505"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "37847517"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
          "text": "37847506"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "37847518"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Libtasn1)).  Supported versions that are affected are 24.2.0-24.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Signaling (Libtasn1)).   The supported version that is affected is 24.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Install/Upgrade (Libtasn1)).   The supported version that is affected is 24.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Libtasn1)).   The supported version that is affected is 25.1.100. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core DBTier. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Libtasn1)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (Libtasn1)).  Supported versions that are affected are 24.2.0-24.2.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Mediation Engine (Libtasn1)).  Supported versions that are affected are 24.2.4 and  25.1.100. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: CMP (Libtasn1)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Policy Management. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Platform (Libtasn1)).  Supported versions that are affected are 24.2.0, 24.3.0 and  25.1.100. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Signaling (Libtasn1)).  Supported versions that are affected are 24.2.0 and  25.1.100. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14122V-24.2.0",
          "P-10900V-15.0.0.0",
          "P-14547V-25.1.100",
          "P-14974V-25.1.100",
          "P-14547V-24.2.0",
          "P-14123V-25.1.100",
          "P-14547V-24.3.0",
          "P-14117V-25.1.100",
          "P-14277V-24.2.0-24.2.6",
          "P-14123V-24.2.4",
          "P-14121V-24.2.0-24.2.3",
          "P-14117V-24.2.0",
          "P-14130V-24.3.1",
          "P-14118(Install/Upgrade)V-24.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.0-24.2.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092749.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-24.3.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092745.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118(Install/Upgrade)V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092975.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14974V-25.1.100"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092983.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-24.2.0-24.2.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092729.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14123V-25.1.100",
            "P-14123V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092746.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092747.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092973.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14117V-24.2.0",
            "P-14117V-25.1.100"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092730.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14122V-24.2.0",
            "P-10900V-15.0.0.0",
            "P-14547V-25.1.100",
            "P-14974V-25.1.100",
            "P-14547V-24.2.0",
            "P-14123V-25.1.100",
            "P-14547V-24.3.0",
            "P-14117V-25.1.100",
            "P-14277V-24.2.0-24.2.6",
            "P-14123V-24.2.4",
            "P-14121V-24.2.0-24.2.3",
            "P-14117V-24.2.0",
            "P-14130V-24.3.1",
            "P-14118(Install/Upgrade)V-24.2.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-12797",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "37748704"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "37748718"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Alarms, KPI, and Measurements (Cryptography)).  Supported versions that are affected are 24.2.0-24.2.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Binding Support Function accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Binding Support Function accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Cryptography)).  Supported versions that are affected are 24.2.0-24.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Policy accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14121V-24.2.0-24.2.3",
          "P-14277V-24.2.0-24.2.6"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-24.2.0-24.2.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092729.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.0-24.2.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092749.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14121V-24.2.0-24.2.3",
            "P-14277V-24.2.0-24.2.6"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-12798",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
          "text": "37417258"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (logback)).   The supported version that is affected is 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Middleware Common Libraries and Tools executes to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data as well as  unauthorized read access to a subset of Oracle Middleware Common Libraries and Tools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 5.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4647V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4647V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "P-4647V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-12801",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
          "text": "37417258"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (logback)).   The supported version that is affected is 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Middleware Common Libraries and Tools executes to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Middleware Common Libraries and Tools accessible data as well as  unauthorized read access to a subset of Oracle Middleware Common Libraries and Tools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 5.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4647V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4647V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "P-4647V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-13176",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "37630590"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Fusion Middleware",
          "text": "38104553"
        },
        {
          "system_name": "Oracle Bug ID of JD Edwards World Security",
          "text": "37727768"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37609956"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "37618883"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security, Porting, Cloud Deployment Architecture (OpenSSL)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (OpenSSL)).  Supported versions that are affected are 25.0-25.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards World Security product of Oracle JD Edwards (component: World Software Security (OpenSSL)).   The supported version that is affected is A9.4. Easily exploitable vulnerability allows physical access to compromise JD Edwards World Security.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards World Security accessible data as well as  unauthorized read access to a subset of JD Edwards World Security accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards World Security. CVSS 3.1 Base Score 4.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle Fusion Middleware (component: Oracle Database Client for Fusion Middleware (OpenSSL)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Fusion Middleware.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Fusion Middleware accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (OpenSSL)).  Supported versions that are affected are 6.0.5-6.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.0.5-6.1.0",
          "P-9019V-25.0-25.5",
          "P-1032V-14.1.2.0.0",
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-4839V-A9.4",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092433.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-25.0-25.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092434.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4839V-A9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092412.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1032V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5-6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.0.5-6.1.0",
            "P-9019V-25.0-25.5",
            "P-1032V-14.1.2.0.0",
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-4839V-A9.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-21094",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
          "text": "37828692"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Installer (WebKitGTK)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle WebCenter Enterprise Capture.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10212V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10212V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10212V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-21131",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
          "text": "37828692"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Installer (WebKitGTK)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle WebCenter Enterprise Capture.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10212V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10212V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10212V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-22201",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle AutoVue",
          "text": "36651007"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle AutoVue product of Oracle Supply Chain (component: Servlet Container (Eclipse Jetty)).  Supported versions that are affected are 21.0.2 and  21.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle AutoVue.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle AutoVue.  Note: This vulnerability applies to Oracle AutoVue Office, Oracle AutoVue 2D Professional, Oracle AutoVue 3D Professional Advanced, Oracle AutoVue EDA Professional and Oracle AutoVue Electro-Mechanical Professional. Please refer to Patch Availability Document for more details. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4453V-21.0.2",
          "P-4453V-21.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4453V-21.0.2",
            "P-4453V-21.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092435.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4453V-21.0.2",
            "P-4453V-21.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-23807",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-4453V-21.0.2",
            "P-4453V-21.1.0",
            "P-9633(Developer Studio, Forge)V-11.4.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle AutoVue",
          "text": "36754728"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
          "text": "36754733"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle AutoVue product of Oracle Supply Chain (component: Core (Apache Xerces-C++)). For supported versions that are affected see note. This vulnerability cannot be exploited in the context of this product. Note: This vulnerability applies to Oracle AutoVue Office, Oracle AutoVue 2D Professional, Oracle AutoVue 3D Professional Advanced, Oracle AutoVue EDA Professional and Oracle AutoVue Electro-Mechanical Professional. Please refer to Patch Availability Document for more details.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Commerce Guided Search product of Oracle Commerce (component: Developer Studio, Forge (Apache Xerces-C++)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-4453V-21.0.2",
          "P-4453V-21.1.0",
          "P-9633(Developer Studio, Forge)V-11.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4453V-21.0.2",
            "P-4453V-21.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092435.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633(Developer Studio, Forge)V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092429.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4453V-21.0.2",
            "P-4453V-21.1.0",
            "P-9633(Developer Studio, Forge)V-11.4.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-4453V-21.0.2",
            "P-4453V-21.1.0",
            "P-9633(Developer Studio, Forge)V-11.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-24795",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "37647990"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (Apache HTTP Server)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1042(Core)V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Core)V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-1042(Core)V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-25638",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37356005"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Data Analytics Function",
          "text": "37356004"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Data Analytics Function product of Oracle Communications (component: Automated Test Suite (dnsjava)).   The supported version that is affected is 23.4.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Data Analytics Function.  While the vulnerability is in Oracle Communications Cloud Native Core Network Data Analytics Function, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Data Analytics Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Data Analytics Function accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Data Analytics Function. CVSS 3.1 Base Score 8.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (dnsjava)).   The supported version that is affected is 24.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via DNS to compromise Oracle Communications Cloud Native Core Network Exposure Function.  While the vulnerability is in Oracle Communications Cloud Native Core Network Exposure Function, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Exposure Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Exposure Function accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 8.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14489V-23.4.3",
          "P-14122V-24.2.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14489V-23.4.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092976.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.9,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14489V-23.4.3",
            "P-14122V-24.2.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-25710",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle JDeveloper",
          "text": "37801734"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF (Apache Commons Compress)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle JDeveloper executes to compromise Oracle JDeveloper.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle JDeveloper. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-807V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-807V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-807V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-26143",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "37623842"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards (Node.js)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092433.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.6,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-26308",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle JDeveloper",
          "text": "37801734"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF (Apache Commons Compress)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle JDeveloper executes to compromise Oracle JDeveloper.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle JDeveloper. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-807V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-807V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-807V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-27309",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM Integration",
          "text": "37125123"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Event Publish and Subscribe (Apache Kafka)).  Supported versions that are affected are 25.0-25.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9008V-25.0-25.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9008V-25.0-25.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092434.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9008V-25.0-25.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-28168",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "inline_mitigations_already_exist",
          "product_ids": [
            "P-14325V-14.4.0.0.0-14.7.0.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Infrastructure Technology",
          "text": "37570653"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Origination",
          "text": "37570633"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Maintenance (Apache FOP)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration (Apache FOP)).   The supported version that is affected is 11.2.21.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4392V-11.2.21.0.000"
        ],
        "known_not_affected": [
          "P-14325V-14.4.0.0.0-14.7.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14325V-14.4.0.0.0-14.7.0.0.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4392V-11.2.21.0.000"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=2775466.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14325V-14.4.0.0.0-14.7.0.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4392V-11.2.21.0.000"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "Built-in inline controls or mitigations prevent an adversary from leveraging the vulnerability.",
          "product_ids": [
            "P-14325V-14.4.0.0.0-14.7.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-28182",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "36754852"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Nghttp2)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14122V-24.2.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14122V-24.2.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-31141",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "37953839"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Third Party (Apache Kafka)).  Supported versions that are affected are 7.5.1 and  7.6.0-7.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4516V-7.6.0-7.8.0",
          "P-4516V-7.5.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.6.0-7.8.0",
            "P-4516V-7.5.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090956.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4516V-7.6.0-7.8.0",
            "P-4516V-7.5.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-31744",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "36898853"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (JasPer)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14122V-24.2.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14122V-24.2.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-34064",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37160594"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Jinja)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Network Exposure Function accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Network Exposure Function accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14122V-24.2.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14122V-24.2.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-34517",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37900767"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Neo4j)).   The supported version that is affected is 6.0.5. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.0.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.0.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-35195",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37182036"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Requests)).   The supported version that is affected is 24.2.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Exposure Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Exposure Function accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14122V-24.2.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14122V-24.2.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-37891",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5(OML4Py)V-21.4-21.18",
            "P-10945V-12.2.0.4.0",
            "P-5(OML4Py)V-23.4-23.8"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37362108"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Studio",
          "text": "37362233"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "37362167"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Cluster",
          "text": "37362076"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDB Operator (urllib3)).  Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and  9.0.0-9.2.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Cluster accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Studio product of Oracle GoldenGate (component: GoldenGate Studio (urllib3)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (urllib3)).   The supported version that is affected is 24.2.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Exposure Function accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the OML4Py (urllib3) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8479V-9.0.0-9.2.0",
          "P-8479V-8.4.0-8.4.4",
          "P-8479V-8.0.0-8.0.41",
          "P-14122V-24.2.0"
        ],
        "known_not_affected": [
          "P-10945V-12.2.0.4.0",
          "P-5(OML4Py)V-23.4-23.8",
          "P-5(OML4Py)V-21.4-21.18"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8479V-8.4.0-8.4.4",
            "P-8479V-8.0.0-8.0.41",
            "P-8479V-9.0.0-9.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(OML4Py)V-21.4-21.18",
            "P-10945V-12.2.0.4.0",
            "P-5(OML4Py)V-23.4-23.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8479V-8.4.0-8.4.4",
            "P-8479V-8.0.0-8.0.41",
            "P-14122V-24.2.0",
            "P-8479V-9.0.0-9.2.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(OML4Py)V-21.4-21.18",
            "P-10945V-12.2.0.4.0",
            "P-5(OML4Py)V-23.4-23.8"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5(OML4Py)V-21.4-21.18",
            "P-10945V-12.2.0.4.0",
            "P-5(OML4Py)V-23.4-23.8"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-38356",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "37859743"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (TinyMCE)).  Supported versions that are affected are 8.0.7.8, 8.0.8.6, 8.1.1.4 and  8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Infrastructure accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5680V-8.1.2.5",
          "P-5680V-8.0.7.8",
          "P-5680V-8.0.8.6",
          "P-5680V-8.1.1.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.8.6",
            "P-5680V-8.0.7.8",
            "P-5680V-8.1.1.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092118.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.8.6",
            "P-5680V-8.0.7.8",
            "P-5680V-8.1.1.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-38357",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "37859743"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (TinyMCE)).  Supported versions that are affected are 8.0.7.8, 8.0.8.6, 8.1.1.4 and  8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Infrastructure accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5680V-8.1.2.5",
          "P-5680V-8.0.7.8",
          "P-5680V-8.0.8.6",
          "P-5680V-8.1.1.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.8.6",
            "P-5680V-8.0.7.8",
            "P-5680V-8.1.1.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092118.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.8.6",
            "P-5680V-8.0.7.8",
            "P-5680V-8.1.1.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-38472",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "37647990"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (Apache HTTP Server)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1042(Core)V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Core)V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-1042(Core)V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-38477",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "37647990"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (Apache HTTP Server)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1042(Core)V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Core)V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-1042(Core)V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-38819",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Healthcare Master Person Index",
          "text": "37260082"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Predictive Application Server",
          "text": "37260114"
        },
        {
          "system_name": "Oracle Bug ID of Oracle WebLogic Server",
          "text": "37260125"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37259995"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Spring Framework)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Exposure Function accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Master Person Index product of Oracle HealthCare Applications (component: Master Index Data Manager (Spring Framework)).  Supported versions that are affected are 5.0.0.0-5.0.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Master Person Index.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Healthcare Master Person Index accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Predictive Application Server product of Oracle Retail Applications (component: RPAS Fusion Client (Spring Framework)).  Supported versions that are affected are 15.0.3 and 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Predictive Application Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Predictive Application Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Spring Framework)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1823V-15.0.3",
          "P-8575V-5.0.0.0-5.0.9.2",
          "P-14122V-24.2.0",
          "P-5242V-14.1.1.0.0",
          "P-5242V-12.2.1.4.0",
          "P-1823V-16.0.3",
          "P-5242V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8575V-5.0.0.0-5.0.9.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092620.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1823V-15.0.3",
            "P-1823V-16.0.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090426.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1823V-15.0.3",
            "P-8575V-5.0.0.0-5.0.9.2",
            "P-14122V-24.2.0",
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-1823V-16.0.3",
            "P-5242V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-38820",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Healthcare Master Person Index",
          "text": "37260082"
        },
        {
          "system_name": "Oracle Bug ID of Oracle WebLogic Server",
          "text": "37260125"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Predictive Application Server",
          "text": "37260114"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37259995"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Spring Framework)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Exposure Function accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Spring Framework)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Predictive Application Server product of Oracle Retail Applications (component: RPAS Fusion Client (Spring Framework)).  Supported versions that are affected are 15.0.3 and 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Predictive Application Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Predictive Application Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Master Person Index product of Oracle HealthCare Applications (component: Master Index Data Manager (Spring Framework)).  Supported versions that are affected are 5.0.0.0-5.0.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Master Person Index.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Healthcare Master Person Index accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1823V-15.0.3",
          "P-8575V-5.0.0.0-5.0.9.2",
          "P-14122V-24.2.0",
          "P-5242V-14.1.1.0.0",
          "P-5242V-12.2.1.4.0",
          "P-5242V-14.1.2.0.0",
          "P-1823V-16.0.3"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1823V-15.0.3",
            "P-1823V-16.0.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090426.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8575V-5.0.0.0-5.0.9.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092620.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1823V-15.0.3",
            "P-8575V-5.0.0.0-5.0.9.2",
            "P-14122V-24.2.0",
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0",
            "P-1823V-16.0.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-38827",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
          "text": "37366305"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Spring Security)).   The supported version that is affected is 24.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Network Slice Selection Function accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Network Slice Selection Function accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14130V-24.3.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-24.3.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092745.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14130V-24.3.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-38828",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
          "text": "37330128"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Spring Framework)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4647V-12.2.1.4.0",
          "P-4647V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4647V-14.1.2.0.0",
            "P-4647V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-4647V-14.1.2.0.0",
            "P-4647V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-39884",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "37647990"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (Apache HTTP Server)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1042(Core)V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Core)V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-1042(Core)V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-40896",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "37718170"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (libxml2)).  Supported versions that are affected are Oracle Java SE: 8u451-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u451-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u451-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092096.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u451-b50"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-43796",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-13444V-21.4.3"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Blockchain Platform",
          "text": "37723879"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "37723883"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Express.js)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: User Interface (Express.js)).  Supported versions that are affected are 24.2.0, 24.3.0 and  25.1.100. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Network Analytics Data Director, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Network Analytics Data Director accessible data as well as  unauthorized read access to a subset of Oracle Communications Network Analytics Data Director accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-24.3.0",
          "P-14547V-25.1.100",
          "P-14547V-24.2.0"
        ],
        "known_not_affected": [
          "P-13444V-21.4.3"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13444V-21.4.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092973.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-13444V-21.4.3"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-13444V-21.4.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-45336",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-1870V-18.1.4.52.0",
            "P-1870V-22.1.1.32.0",
            "P-13444V-24.1.3"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle TimesTen In-Memory Database",
          "text": "37768409"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Blockchain Platform",
          "text": "37768400"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Golang Go)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle TimesTen In-Memory Database (component: Third-party components (Golang Go)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-1870V-22.1.1.32.0",
          "P-13444V-24.1.3",
          "P-1870V-18.1.4.52.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1870V-18.1.4.52.0",
            "P-1870V-22.1.1.32.0",
            "P-13444V-24.1.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1870V-18.1.4.52.0",
            "P-1870V-22.1.1.32.0",
            "P-13444V-24.1.3"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-1870V-18.1.4.52.0",
            "P-1870V-22.1.1.32.0",
            "P-13444V-24.1.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-45340",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-1870V-18.1.4.52.0",
            "P-1870V-22.1.1.32.0",
            "P-13444V-24.1.3"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle TimesTen In-Memory Database",
          "text": "37768409"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Blockchain Platform",
          "text": "37768400"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle TimesTen In-Memory Database (component: Third-party components (Golang Go)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Golang Go)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-1870V-22.1.1.32.0",
          "P-13444V-24.1.3",
          "P-1870V-18.1.4.52.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1870V-18.1.4.52.0",
            "P-1870V-22.1.1.32.0",
            "P-13444V-24.1.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1870V-18.1.4.52.0",
            "P-1870V-22.1.1.32.0",
            "P-13444V-24.1.3"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-1870V-18.1.4.52.0",
            "P-1870V-22.1.1.32.0",
            "P-13444V-24.1.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-45341",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-1870V-18.1.4.52.0",
            "P-1870V-22.1.1.32.0",
            "P-13444V-24.1.3"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle TimesTen In-Memory Database",
          "text": "37768409"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Blockchain Platform",
          "text": "37768400"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle TimesTen In-Memory Database (component: Third-party components (Golang Go)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Golang Go)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-1870V-22.1.1.32.0",
          "P-13444V-24.1.3",
          "P-1870V-18.1.4.52.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1870V-18.1.4.52.0",
            "P-1870V-22.1.1.32.0",
            "P-13444V-24.1.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1870V-18.1.4.52.0",
            "P-1870V-22.1.1.32.0",
            "P-13444V-24.1.3"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-1870V-18.1.4.52.0",
            "P-1870V-22.1.1.32.0",
            "P-13444V-24.1.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-46956",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications User Data Repository",
          "text": "37922865"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Platform (Ghostscript)).   The supported version that is affected is 15.0.3. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications User Data Repository executes to compromise Oracle Communications User Data Repository.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications User Data Repository. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11108V-15.0.3"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11108V-15.0.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092974.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-11108V-15.0.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-47072",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37509176"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
          "text": "37509145"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
          "text": "37509205"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (XStream)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (XStream)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Point of Sale (XStream)).  Supported versions that are affected are 20.0.5, 21.0.4, 22.0.2 and  23.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4647V-14.1.2.0.0",
          "P-14122V-24.2.0",
          "P-11513V-22.0.2",
          "P-4647V-12.2.1.4.0",
          "P-11513V-23.0.2",
          "P-11513V-21.0.4",
          "P-11513V-20.0.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4647V-14.1.2.0.0",
            "P-4647V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11513V-22.0.2",
            "P-11513V-23.0.2",
            "P-11513V-21.0.4",
            "P-11513V-20.0.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090426.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4647V-14.1.2.0.0",
            "P-14122V-24.2.0",
            "P-11513V-22.0.2",
            "P-4647V-12.2.1.4.0",
            "P-11513V-23.0.2",
            "P-11513V-21.0.4",
            "P-11513V-20.0.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-47554",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-2241V-2.5.0.1.15",
            "P-2241V-2.4.0.1.27",
            "P-2241V-2.6.0.1.7",
            "P-2241V-2.5.0.2.9",
            "P-2241V-2.6.0.2.1"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
          "text": "37139492"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Calendar Server",
          "text": "37476989"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
          "text": "37477180"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Contacts Server",
          "text": "37477005"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Agile PLM",
          "text": "37351869"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Insurance Policy Administration J2EE",
          "text": "37477136"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications IP Service Activator",
          "text": "37477015"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
          "text": "37477223"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
          "text": "37477233"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
          "text": "37477167"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Offline Mediation Controller",
          "text": "37477022"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Commons IO)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Core (Apache Commons IO)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Apache Commons IO)).  Supported versions that are affected are 7.0.0.0.0 and  7.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Utilities Testing Accelerator. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: SW-System Wide (Apache Commons IO)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: Installation (Apache Commons IO)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Service Backbone. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: Installation (Apache Commons IO)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Integration Bus. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Insurance Policy Administration J2EE product of Oracle Insurance Applications (component: Architecture (Apache Commons IO)).  Supported versions that are affected are 11.3.0-12.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration J2EE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Insurance Policy Administration J2EE. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Calendar Server product of Oracle Communications Applications (component: Third Party (Apache Commons IO)).   The supported version that is affected is 8.0.0.8.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Calendar Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Calendar Server. CVSS 3.1 Base Score 2.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Contacts Server product of Oracle Communications Applications (component: Other (Apache Commons IO)).   The supported version that is affected is 8.0.0.9.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Contacts Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Contacts Server. CVSS 3.1 Base Score 2.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications IP Service Activator product of Oracle Communications Applications (component: Network Processor (Apache Commons IO)).  Supported versions that are affected are 7.4.0 and  7.5.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications IP Service Activator.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications IP Service Activator. CVSS 3.1 Base Score 2.0 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications Applications (component: Install (Apache Commons IO)).  Supported versions that are affected are 12.0.0.2-12.0.0.8 and  15.0.0.0-15.0.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Offline Mediation Controller.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Offline Mediation Controller. CVSS 3.1 Base Score 3.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10867V-15.0.3.1",
          "P-1807V-19.0.1",
          "P-10696V-8.0.0.9.0",
          "P-4647V-14.1.2.0.0",
          "P-2261V-7.4.0",
          "P-2269V-12.0.0.2-12.0.0.8",
          "P-2261V-7.5.0",
          "P-10867V-14.1.3.2",
          "P-8494V-8.0.0.8.0",
          "P-1807V-16.0.3",
          "P-13784V-7.0.0.0.0",
          "P-13784V-7.0.0.1.0",
          "P-5279V-11.3.0-12.0.4",
          "P-10867V-16.0.3",
          "P-1807V-15.0.3.1",
          "P-4647V-12.2.1.4.0",
          "P-4461V-9.3.6",
          "P-2269V-15.0.0.0-15.0.1.0",
          "P-10867V-19.0.1",
          "P-1807V-14.1.3.2"
        ],
        "known_not_affected": [
          "P-2241V-2.5.0.1.15",
          "P-2241V-2.6.0.1.7",
          "P-2241V-2.4.0.1.27",
          "P-2241V-2.5.0.2.9",
          "P-2241V-2.6.0.2.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4647V-14.1.2.0.0",
            "P-4647V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4461V-9.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092435.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13784V-7.0.0.0.0",
            "P-2241V-2.5.0.1.15",
            "P-13784V-7.0.0.1.0",
            "P-2241V-2.4.0.1.27",
            "P-2241V-2.6.0.1.7",
            "P-2241V-2.5.0.2.9",
            "P-2241V-2.6.0.2.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093776.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10867V-15.0.3.1",
            "P-10867V-16.0.3",
            "P-1807V-19.0.1",
            "P-1807V-15.0.3.1",
            "P-10867V-14.1.3.2",
            "P-10867V-19.0.1",
            "P-1807V-14.1.3.2",
            "P-1807V-16.0.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090426.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5279V-11.3.0-12.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092287.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10696V-8.0.0.9.0",
            "P-8494V-8.0.0.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090954.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2261V-7.4.0",
            "P-2261V-7.5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090967.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2269V-12.0.0.2-12.0.0.8",
            "P-2269V-15.0.0.0-15.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090955.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-10867V-15.0.3.1",
            "P-1807V-19.0.1",
            "P-4647V-14.1.2.0.0",
            "P-10867V-14.1.3.2",
            "P-1807V-16.0.3",
            "P-13784V-7.0.0.0.0",
            "P-13784V-7.0.0.1.0",
            "P-5279V-11.3.0-12.0.4",
            "P-10867V-16.0.3",
            "P-1807V-15.0.3.1",
            "P-4647V-12.2.1.4.0",
            "P-4461V-9.3.6",
            "P-10867V-19.0.1",
            "P-1807V-14.1.3.2"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-2241V-2.5.0.1.15",
            "P-2241V-2.4.0.1.27",
            "P-2241V-2.6.0.1.7",
            "P-2241V-2.5.0.2.9",
            "P-2241V-2.6.0.2.1"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 2.4,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-10696V-8.0.0.9.0",
            "P-8494V-8.0.0.8.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 2.0,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-2261V-7.4.0",
            "P-2261V-7.5.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 3.5,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-2269V-12.0.0.2-12.0.0.8",
            "P-2269V-15.0.0.0-15.0.1.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-2241V-2.5.0.1.15",
            "P-2241V-2.4.0.1.27",
            "P-2241V-2.6.0.1.7",
            "P-2241V-2.5.0.2.9",
            "P-2241V-2.6.0.2.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-47561",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-4647V-14.1.2.0.0",
            "P-4647V-12.2.1.4.0"
          ]
        },
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-8575V-5.0.0.0-5.0.9.2"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
          "text": "37404600"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Healthcare Master Person Index",
          "text": "37379245"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Infrastructure Technology",
          "text": "37379238"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration (Apache Avro)).   The supported version that is affected is 11.2.21.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hyperion Infrastructure Technology accessible data as well as  unauthorized read access to a subset of Oracle Hyperion Infrastructure Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 3.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Avro)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Healthcare Master Person Index product of Oracle HealthCare Applications (component: Relationship Management (Apache Avro)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4392V-11.2.21.0.000"
        ],
        "known_not_affected": [
          "P-4647V-12.2.1.4.0",
          "P-8575V-5.0.0.0-5.0.9.2",
          "P-4647V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4392V-11.2.21.0.000"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=2775466.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4647V-14.1.2.0.0",
            "P-4647V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8575V-5.0.0.0-5.0.9.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092620.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.9,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-4392V-11.2.21.0.000"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8575V-5.0.0.0-5.0.9.2",
            "P-4647V-14.1.2.0.0",
            "P-4647V-12.2.1.4.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-4647V-14.1.2.0.0",
            "P-4647V-12.2.1.4.0"
          ]
        },
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-8575V-5.0.0.0-5.0.9.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-47606",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Element Manager",
          "text": "38125077"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Tools (Oracle Java SE)).  Supported versions that are affected are 9.0.0-9.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Element Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11052V-9.0.0-9.0.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11052V-9.0.0-9.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092984.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-11052V-9.0.0-9.0.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-49767",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37328095"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37455218"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Werkzeug)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Quart)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14122(Platform)V-24.2.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122(Platform)V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14122(Platform)V-24.2.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-52012",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37614130"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Solr)).  Supported versions that are affected are 6.0.5-6.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.0.5-6.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5-6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.0.5-6.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-52046",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
          "text": "37444772"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Healthcare Master Person Index",
          "text": "37444792"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Mina)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in takeover of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Master Person Index product of Oracle HealthCare Applications (component: Master Index Data Manager (Apache Mina)).  Supported versions that are affected are 5.0.0.0-5.0.9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Master Person Index.  Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Master Person Index. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4647V-12.2.1.4.0",
          "P-8575V-5.0.0.0-5.0.9.2",
          "P-4647V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4647V-14.1.2.0.0",
            "P-4647V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8575V-5.0.0.0-5.0.9.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092620.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8575V-5.0.0.0-5.0.9.2",
            "P-4647V-14.1.2.0.0",
            "P-4647V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-5535",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-4379V-21.7.2.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Essbase",
          "text": "38056628"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Essbase (component: Marketplace (OpenSSL)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-4379V-21.7.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4379V-21.7.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4379V-21.7.2.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-4379V-21.7.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-55549",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "37718198"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (libxslt)).  Supported versions that are affected are Oracle Java SE: 8u451-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u451-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u451-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092096.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u451-b50"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-56128",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Banking Origination",
          "text": "37717012"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37717111"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Convergent Charging Controller",
          "text": "37717106"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
          "text": "37717109"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Maintenance (Apache Kafka)).  Supported versions that are affected are 14.4.0.0.0-14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Banking Origination accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications Applications (component: Common Functions (Apache Kafka)).  Supported versions that are affected are 12.0.3.0.0-12.0.6.0.0, 15.0.0.0.0-15.0.1.0.0 and  15.1.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Convergent Charging Controller.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Convergent Charging Controller accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Kafka)).  Supported versions that are affected are 6.0.5-6.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications Applications (component: NGW (Apache Kafka)).  Supported versions that are affected are 12.0.3.0.0-12.0.6.0.0, 15.0.0.0.0-15.0.1.0.0 and  15.1.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Network Charging and Control accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.0.5-6.1.0",
          "P-4623V-12.0.3.0.0-12.0.6.0.0",
          "P-12985V-15.1.0.0.0",
          "P-12985V-15.0.0.0.0-15.0.1.0.0",
          "P-4623V-15.1.0.0.0",
          "P-14325V-14.4.0.0.0-14.7.0.0.0",
          "P-12985V-12.0.3.0.0-12.0.6.0.0",
          "P-4623V-15.0.0.0.0-15.0.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14325V-14.4.0.0.0-14.7.0.0.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4623V-12.0.3.0.0-12.0.6.0.0",
            "P-12985V-15.1.0.0.0",
            "P-12985V-15.0.0.0.0-15.0.1.0.0",
            "P-4623V-15.1.0.0.0",
            "P-12985V-12.0.3.0.0-12.0.6.0.0",
            "P-4623V-15.0.0.0.0-15.0.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090966.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5-6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14325V-14.4.0.0.0-14.7.0.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.0.5-6.1.0",
            "P-4623V-12.0.3.0.0-12.0.6.0.0",
            "P-12985V-15.1.0.0.0",
            "P-12985V-15.0.0.0.0-15.0.1.0.0",
            "P-4623V-15.1.0.0.0",
            "P-12985V-12.0.3.0.0-12.0.6.0.0",
            "P-4623V-15.0.0.0.0-15.0.1.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-56171",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37806205"
        },
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "37806213"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
          "text": "37847502"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "37718170"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
          "text": "37806197"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (libxml2)).  Supported versions that are affected are Oracle Java SE: 8u451-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: ATS Framework (libxml2)).   The supported version that is affected is 24.2.4. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Repository Function executes to compromise Oracle Communications Cloud Native Core Network Repository Function.  While the vulnerability is in Oracle Communications Cloud Native Core Network Repository Function, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Repository Function accessible data. CVSS 3.1 Base Score 7.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (libxml2)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server.  While the vulnerability is in Oracle HTTP Server, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data as well as  unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 7.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (libxml2)).  Supported versions that are affected are 6.0.5-6.1.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  While the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Install/Upgrade (Libtasn1)).   The supported version that is affected is 24.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u451-b50",
          "P-14118(ATS Framework)V-24.2.4",
          "P-14597V-6.0.5-6.1.0",
          "P-14118(Install/Upgrade)V-24.2.4",
          "P-1042(Core)V-12.2.1.4.0",
          "P-1042(Core)V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u451-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092096.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118(ATS Framework)V-24.2.4",
            "P-14118(Install/Upgrade)V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092975.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Core)V-12.2.1.4.0",
            "P-1042(Core)V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5-6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u451-b50"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14118(ATS Framework)V-24.2.4",
            "P-1042(Core)V-12.2.1.4.0",
            "P-1042(Core)V-14.1.2.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.0.5-6.1.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14118(Install/Upgrade)V-24.2.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-56201",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
          "text": "37476556"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Jinja)).  Supported versions that are affected are 24.3.0 and  25.1.100. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core DBTier executes to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core DBTier. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14974V-24.3.0",
          "P-14974V-25.1.100"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14974V-24.3.0",
            "P-14974V-25.1.100"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092983.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14974V-24.3.0",
            "P-14974V-25.1.100"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-56326",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
          "text": "37476556"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Jinja)).  Supported versions that are affected are 24.3.0 and  25.1.100. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core DBTier executes to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core DBTier. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14974V-24.3.0",
          "P-14974V-25.1.100"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14974V-24.3.0",
            "P-14974V-25.1.100"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092983.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14974V-24.3.0",
            "P-14974V-25.1.100"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-56406",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-23.4-23.8",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Billing and Revenue Management",
          "text": "37889057"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "37889089"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Database (Perl) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: SE_VFG_Security_Feature (Perl)).  Supported versions that are affected are 12.0.0.4.0-12.0.0.8.0, 15.0.0.0.0, 15.0.1.0.0 and  15.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Billing and Revenue Management as well as  unauthorized update, insert or delete access to some of Oracle Communications Billing and Revenue Management accessible data and  unauthorized read access to a subset of Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2136(SE_VFG_Security_Feature)V-12.0.0.4.0-12.0.0.8.0",
          "P-2136(SE_VFG_Security_Feature)V-15.0.0.0.0",
          "P-2136(SE_VFG_Security_Feature)V-15.1.0.0.0",
          "P-2136(SE_VFG_Security_Feature)V-15.0.1.0.0"
        ],
        "known_not_affected": [
          "P-5(Oracle Database)V-23.4-23.8",
          "P-5(Oracle Database)V-21.3-21.18",
          "P-5(Oracle Database)V-19.3-19.27"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-23.4-23.8",
            "P-5(Oracle Database)V-21.3-21.18"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2136(SE_VFG_Security_Feature)V-15.1.0.0.0",
            "P-2136(SE_VFG_Security_Feature)V-12.0.0.4.0-12.0.0.8.0",
            "P-2136(SE_VFG_Security_Feature)V-15.0.0.0.0",
            "P-2136(SE_VFG_Security_Feature)V-15.0.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090953.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-23.4-23.8",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 8.6,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2136(SE_VFG_Security_Feature)V-15.1.0.0.0",
            "P-2136(SE_VFG_Security_Feature)V-12.0.0.4.0-12.0.0.8.0",
            "P-2136(SE_VFG_Security_Feature)V-15.0.0.0.0",
            "P-2136(SE_VFG_Security_Feature)V-15.0.1.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-23.4-23.8",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-57699",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-4379V-21.7.2.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
          "text": "37680949"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Insurance Policy Administration J2EE",
          "text": "37692948"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Essbase",
          "text": "37692903"
        },
        {
          "system_name": "Oracle Bug ID of Oracle WebLogic Server",
          "text": "37569821"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Data Analytics Function",
          "text": "37680947"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37680948"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Origination",
          "text": "37680931"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
          "text": "37693208"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
          "text": "37680950"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37680961"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Stream Analytics",
          "text": "37693228"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Stream Analytics product of Oracle GoldenGate (component: Stream Analytics (json-smart)).  Supported versions that are affected are 19.1.0.0.0-19.1.0.0.11. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GoldenGate Stream Analytics. CVSS 3.1 Base Score 2.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Configuration (json-smart)).   The supported version that is affected is 24.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Signaling (json-smart)).   The supported version that is affected is 24.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (json-smart)).  Supported versions that are affected are 6.0.5-6.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Essbase (component: Essbase Web Platform (json-smart)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Insurance Policy Administration J2EE product of Oracle Insurance Applications (component: Architecture (json-smart)).  Supported versions that are affected are 11.3.0-11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration J2EE.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Insurance Policy Administration J2EE. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Security (json-smart)).  Supported versions that are affected are 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 24.1.0.0.0-24.3.0.0.0 and  25.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Application Framework. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Data Analytics Function product of Oracle Communications (component: Automated Test Suite (json-smart)).   The supported version that is affected is 23.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Data Analytics Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Data Analytics Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Maintenance (json-smart)).  Supported versions that are affected are 14.4.0.0.0-14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Origination. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (json-smart)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (json-smart)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.0.5-6.1.0",
          "P-14122V-24.2.0",
          "P-14325V-14.4.0.0.0-14.7.0.0.0",
          "P-2245V-4.5.0.1.1",
          "P-2245V-4.5.0.0.0",
          "P-5242V-14.1.2.0.0",
          "P-2245V-4.4.0.0.0",
          "P-14118(Configuration)V-24.2.4",
          "P-2245V-4.4.0.2.0",
          "P-2245V-4.4.0.3.0",
          "P-2245V-24.1.0.0.0-24.3.0.0.0",
          "P-5242V-14.1.1.0.0",
          "P-2245V-4.5.0.1.3",
          "P-2245V-25.4",
          "P-14015V-19.1.0.0.0-19.1.0.0.11",
          "P-14130V-24.3.1",
          "P-5242V-12.2.1.4.0",
          "P-5279V-11.3.0-11.3.2",
          "P-14489V-23.1.0"
        ],
        "known_not_affected": [
          "P-4379V-21.7.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4379V-21.7.2.0.0",
            "P-14015V-19.1.0.0.0-19.1.0.0.11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118(Configuration)V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092975.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-24.3.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092745.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5-6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5279V-11.3.0-11.3.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092287.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2245V-24.1.0.0.0-24.3.0.0.0",
            "P-2245V-4.5.0.1.3",
            "P-2245V-4.5.0.1.1",
            "P-2245V-25.4",
            "P-2245V-4.5.0.0.0",
            "P-2245V-4.4.0.0.0",
            "P-2245V-4.4.0.2.0",
            "P-2245V-4.4.0.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093776.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14489V-23.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092976.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14325V-14.4.0.0.0-14.7.0.0.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14015V-19.1.0.0.0-19.1.0.0.11"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14122V-24.2.0",
            "P-14325V-14.4.0.0.0-14.7.0.0.0",
            "P-2245V-4.5.0.1.1",
            "P-2245V-4.5.0.0.0",
            "P-5242V-14.1.2.0.0",
            "P-2245V-4.4.0.0.0",
            "P-14118(Configuration)V-24.2.4",
            "P-2245V-4.4.0.2.0",
            "P-2245V-4.4.0.3.0",
            "P-2245V-24.1.0.0.0-24.3.0.0.0",
            "P-5242V-14.1.1.0.0",
            "P-2245V-4.5.0.1.3",
            "P-2245V-25.4",
            "P-14130V-24.3.1",
            "P-5242V-12.2.1.4.0",
            "P-5279V-11.3.0-11.3.2",
            "P-14489V-23.1.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.0.5-6.1.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4379V-21.7.2.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-4379V-21.7.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-6763",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Retail EFTLink",
          "text": "37665065"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Coherence",
          "text": "37664985"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: REST API (Eclipse Jetty)).  Supported versions that are affected are 20.0.1, 21.0.0, 22.0.0 and  23.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail EFTLink.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail EFTLink accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Third Party (Eclipse Jetty)).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11516V-20.0.1",
          "P-11516V-23.0.0",
          "P-2545V-12.2.1.4.0",
          "P-11516V-21.0.0",
          "P-11516V-22.0.0",
          "P-2545V-14.1.1.0.0",
          "P-2545V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11516V-20.0.1",
            "P-11516V-23.0.0",
            "P-11516V-21.0.0",
            "P-11516V-22.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090426.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2545V-12.2.1.4.0",
            "P-2545V-14.1.1.0.0",
            "P-2545V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-11516V-20.0.1",
            "P-11516V-23.0.0",
            "P-2545V-12.2.1.4.0",
            "P-11516V-21.0.0",
            "P-11516V-22.0.0",
            "P-2545V-14.1.1.0.0",
            "P-2545V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-7254",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-10945V-12.2.0.4.0",
            "P-5758V-12.2.1.4.0-12.2.1.4.250331"
          ]
        },
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-13600V-24.1.0",
            "P-13444V-24.1.3"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Banking Origination",
          "text": "37599134"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Studio",
          "text": "37599188"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Data Analytics Function",
          "text": "37599148"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
          "text": "37599239"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Blockchain Platform",
          "text": "37599139"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Veridata",
          "text": "37599193"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "37599162"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Spatial Studio",
          "text": "37545316"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Third Party (Google Protobuf-Java)).  Supported versions that are affected are 24.2.0 and  24.3.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Studio product of Oracle GoldenGate (component: GoldenGate Studio (Google Protobuf-Java)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Veridata product of Oracle GoldenGate (component: GoldenGate Veridata (Google Protobuf-Java)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: SW-System Wide (Google Protobuf-Java)).  Supported versions that are affected are 2.5.0.2.8, 2.6.0.1.7 and  2.6.0.2.2. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Utilities Network Management System executes to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Utilities Network Management System. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Spatial Studio (component: Install (Google Protobuf-Java)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Data Analytics Function product of Oracle Communications (component: Automated Test Suite (Google Protobuf-Java)).   The supported version that is affected is 22.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Data Analytics Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Data Analytics Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Google Protobuf-Java)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Maintenance (Google Protobuf-Java)).  Supported versions that are affected are 14.4.0.0.0-14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Origination. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14547V-24.2.0",
          "P-14325V-14.4.0.0.0-14.7.0.0.0",
          "P-14547V-24.3.0",
          "P-2241V-2.6.0.1.7",
          "P-14489V-22.4.0",
          "P-2241V-2.6.0.2.2",
          "P-2241V-2.5.0.2.8"
        ],
        "known_not_affected": [
          "P-10945V-12.2.0.4.0",
          "P-13600V-24.1.0",
          "P-13444V-24.1.3",
          "P-5758V-12.2.1.4.0-12.2.1.4.250331"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092973.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10945V-12.2.0.4.0",
            "P-13600V-24.1.0",
            "P-13444V-24.1.3",
            "P-5758V-12.2.1.4.0-12.2.1.4.250331"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2241V-2.6.0.1.7",
            "P-2241V-2.6.0.2.2",
            "P-2241V-2.5.0.2.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093776.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14489V-22.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092976.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14325V-14.4.0.0.0-14.7.0.0.0"
          ],
          "url": "https://support.oracle.com"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10945V-12.2.0.4.0",
            "P-13600V-24.1.0",
            "P-13444V-24.1.3",
            "P-5758V-12.2.1.4.0-12.2.1.4.250331"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-2241V-2.6.0.1.7",
            "P-2241V-2.6.0.2.2",
            "P-2241V-2.5.0.2.8"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14325V-14.4.0.0.0-14.7.0.0.0",
            "P-14489V-22.4.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-10945V-12.2.0.4.0",
            "P-5758V-12.2.1.4.0-12.2.1.4.250331"
          ]
        },
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-13600V-24.1.0",
            "P-13444V-24.1.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-7264",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37867541"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Database (libcurl)).   The supported version that is affected is 6.0.5. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.0.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.0.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-7592",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
          "text": "37979554"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Python)).  Supported versions that are affected are 25.1.100 and  24.2.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core DBTier executes to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core DBTier. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14974V-24.2.5",
          "P-14974V-25.1.100"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14974V-25.1.100",
            "P-14974V-24.2.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092983.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14974V-25.1.100",
            "P-14974V-24.2.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-7885",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
          "text": "37289628"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37289626"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Undertow)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Install (Undertow)).   The supported version that is affected is 24.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14122V-24.2.0",
          "P-14130V-24.3.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-24.3.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092745.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14122V-24.2.0",
            "P-14130V-24.3.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-8006",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37107926"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (libcap)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Exposure Function executes to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14122V-24.2.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14122V-24.2.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-8176",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-14121V-24.2.0-24.2.3",
            "P-14277V-24.2.0-24.2.6"
          ]
        },
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "37740870"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37740871"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Outside In Technology",
          "text": "37740883"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
          "text": "38138628"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "37740862"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "37740864"
        },
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "37740876"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
          "text": "37740867"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Behavior Detection Platform",
          "text": "37740846"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition",
          "text": "37740847"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (LibExpat)).   The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (LibExpat)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (LibExpat)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (LibExpat)).  Supported versions that are affected are 8.0.8.1, 8.1.2.8 and  8.1.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (LibExpat)).  Supported versions that are affected are 24.2.0 and  25.1.100. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Configuration (LibExpat)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (LibExpat)).  Supported versions that are affected are 6.0.5-6.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Mod_Security (LibExpat)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: DC-Specific Component (LibExpat)).   The supported version that is affected is 8.5.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Signaling (LibExpat)).  Supported versions that are affected are 24.2.4 and  25.1.101. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.0.5-6.1.0",
          "P-13789V-8.0.8",
          "P-14117V-24.2.0",
          "P-9190V-8.1.2.9",
          "P-1042(Mod_Security)V-12.2.1.4.0",
          "P-9190V-8.0.8.1",
          "P-9190V-8.1.2.8",
          "P-1042(Mod_Security)V-14.1.2.0.0",
          "P-14123V-25.1.101",
          "P-2276V-8.5.7",
          "P-14117V-25.1.100",
          "P-14123V-24.2.4"
        ],
        "known_not_affected": [
          "P-14121V-24.2.0-24.2.3",
          "P-14547V-24.3.0",
          "P-14547V-25.1.100",
          "P-14277V-24.2.0-24.2.6",
          "P-14547V-24.2.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13789V-8.0.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090124.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-24.2.0-24.2.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092729.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.0-24.2.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092749.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9190V-8.1.2.9",
            "P-9190V-8.0.8.1",
            "P-9190V-8.1.2.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090123.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14117V-24.2.0",
            "P-14117V-25.1.100"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092730.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092973.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5-6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Mod_Security)V-12.2.1.4.0",
            "P-1042(Mod_Security)V-14.1.2.0.0",
            "P-2276V-8.5.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14123V-25.1.101",
            "P-14123V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092746.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13789V-8.0.8",
            "P-14117V-24.2.0",
            "P-9190V-8.1.2.9",
            "P-1042(Mod_Security)V-12.2.1.4.0",
            "P-9190V-8.0.8.1",
            "P-9190V-8.1.2.8",
            "P-1042(Mod_Security)V-14.1.2.0.0",
            "P-14123V-25.1.101",
            "P-2276V-8.5.7",
            "P-14117V-25.1.100",
            "P-14123V-24.2.4"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14121V-24.2.0-24.2.3",
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0",
            "P-14277V-24.2.0-24.2.6"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.0.5-6.1.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-14121V-24.2.0-24.2.3",
            "P-14277V-24.2.0-24.2.6"
          ]
        },
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-8184",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Data Integrator",
          "text": "37342875"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Security (Eclipse Jetty)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Data Integrator. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2196V-14.1.2.0.0",
          "P-2196V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2196V-12.2.1.4.0",
            "P-2196V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2196V-12.2.1.4.0",
            "P-2196V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-9143",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Fusion Middleware",
          "text": "38104553"
        },
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "37630590"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37609956"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "37618883"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (OpenSSL)).  Supported versions that are affected are 6.0.5-6.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle Fusion Middleware (component: Oracle Database Client for Fusion Middleware (OpenSSL)).   The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Fusion Middleware.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Fusion Middleware accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure (OpenSSL)).  Supported versions that are affected are 25.0-25.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security, Porting, Cloud Deployment Architecture (OpenSSL)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.0.5-6.1.0",
          "P-9019V-25.0-25.5",
          "P-1032V-14.1.2.0.0",
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5-6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1032V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-25.0-25.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092434.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092433.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.0.5-6.1.0",
            "P-9019V-25.0-25.5",
            "P-1032V-14.1.2.0.0",
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2024-9287",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "37979562"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "37979552"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37979563"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
          "text": "37979554"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "37979557"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "37979546"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: ATS Framework (Python)).  Supported versions that are affected are 24.2.0 and  24.3.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Network Analytics Data Director executes to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Python)).  Supported versions that are affected are 24.2.0-24.2.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Python)).  Supported versions that are affected are 25.1.100 and  24.2.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core DBTier executes to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core DBTier. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (Python)).  Supported versions that are affected are 24.2.0-24.2.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Binding Support Function executes to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Python)).  Supported versions that are affected are 6.0.5-6.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (Python)).  Supported versions that are affected are 8.0.0-8.0.42. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Workbench executes to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in takeover of MySQL Workbench. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14121V-24.2.0-24.2.3",
          "P-14597V-6.0.5-6.1.0",
          "P-4627V-8.0.0-8.0.42",
          "P-14547V-24.2.0",
          "P-14974V-25.1.100",
          "P-14547V-24.3.0",
          "P-14974V-24.2.5",
          "P-14277V-24.2.0-24.2.6"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092973.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.0-24.2.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092749.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14974V-25.1.100",
            "P-14974V-24.2.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092983.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-24.2.0-24.2.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092729.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5-6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.42"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14121V-24.2.0-24.2.3",
            "P-14597V-6.0.5-6.1.0",
            "P-4627V-8.0.0-8.0.42",
            "P-14547V-24.2.0",
            "P-14974V-25.1.100",
            "P-14547V-24.3.0",
            "P-14974V-24.2.5",
            "P-14277V-24.2.0-24.2.6"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-0395",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
          "text": "38136239"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Signaling (glibc)).  Supported versions that are affected are 24.2.4 and  25.1.101. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Security Edge Protection Proxy executes to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy as well as  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data and  unauthorized read access to a subset of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14123V-25.1.101",
          "P-14123V-24.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14123V-25.1.101",
            "P-14123V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092746.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14123V-25.1.101",
            "P-14123V-24.2.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-0624",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications User Data Repository",
          "text": "37922816"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Platform (grub2)).   The supported version that is affected is 15.0.3. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Communications User Data Repository executes to compromise Oracle Communications User Data Repository.  While the vulnerability is in Oracle Communications User Data Repository, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications User Data Repository. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11108V-15.0.3"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11108V-15.0.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092974.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.6,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-11108V-15.0.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-0725",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-619(Oracle Spatial and Graph)V-23.4-23.8",
            "P-619(Oracle Spatial and Graph)V-19.3-19.27",
            "P-619(Oracle Spatial and Graph)V-21.3-21.18"
          ]
        },
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "P-4379V-21.7.2.0.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Enterprise Backup",
          "text": "37975049"
        },
        {
          "system_name": "Oracle Bug ID of Siebel CRM Integration",
          "text": "37786608"
        },
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "37975069"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Commerce Guided Search Platform Services",
          "text": "37975057"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "37641011"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Essbase",
          "text": "37975072"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Spatial and Graph (curl) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI (curl)).  Supported versions that are affected are 25.0-25.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data as well as  unauthorized read access to a subset of Siebel CRM Integration accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Integration. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Enterprise Backup product of Oracle MySQL (component: Enterprise Backup (curl)).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Enterprise Backup.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Enterprise Backup accessible data as well as  unauthorized read access to a subset of MySQL Enterprise Backup accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Enterprise Backup. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search Platform Services product of Oracle Commerce (component: Forge (curl)).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search Platform Services.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Commerce Guided Search Platform Services accessible data as well as  unauthorized read access to a subset of Oracle Commerce Guided Search Platform Services accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search Platform Services. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Mod_Security  (curl)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle HTTP Server accessible data as well as  unauthorized read access to a subset of Oracle HTTP Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Essbase (component: Essbase Web Platform (curl)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4629V-8.4.0-8.4.5",
          "P-4629V-8.0.0-8.0.42",
          "P-9633(Forge)V-11.4.0",
          "P-9008V-25.0-25.5",
          "P-1042(Mod_Security)V-12.2.1.4.0",
          "P-1042(Mod_Security)V-14.1.2.0.0",
          "P-4629V-9.0.0-9.3.0"
        ],
        "known_not_affected": [
          "P-619(Oracle Spatial and Graph)V-19.3-19.27",
          "P-4379V-21.7.2.0.0",
          "P-619(Oracle Spatial and Graph)V-23.4-23.8",
          "P-619(Oracle Spatial and Graph)V-21.3-21.18"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4379V-21.7.2.0.0",
            "P-619(Oracle Spatial and Graph)V-23.4-23.8",
            "P-619(Oracle Spatial and Graph)V-19.3-19.27",
            "P-619(Oracle Spatial and Graph)V-21.3-21.18"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9008V-25.0-25.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092434.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4629V-8.4.0-8.4.5",
            "P-4629V-8.0.0-8.0.42",
            "P-4629V-9.0.0-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633(Forge)V-11.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092429.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Mod_Security)V-12.2.1.4.0",
            "P-1042(Mod_Security)V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-619(Oracle Spatial and Graph)V-23.4-23.8",
            "P-619(Oracle Spatial and Graph)V-19.3-19.27",
            "P-619(Oracle Spatial and Graph)V-21.3-21.18"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-4629V-8.4.0-8.4.5",
            "P-4629V-8.0.0-8.0.42",
            "P-9633(Forge)V-11.4.0",
            "P-9008V-25.0-25.5",
            "P-1042(Mod_Security)V-12.2.1.4.0",
            "P-1042(Mod_Security)V-14.1.2.0.0",
            "P-4629V-9.0.0-9.3.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4379V-21.7.2.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-619(Oracle Spatial and Graph)V-23.4-23.8",
            "P-619(Oracle Spatial and Graph)V-19.3-19.27",
            "P-619(Oracle Spatial and Graph)V-21.3-21.18"
          ]
        },
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
          "product_ids": [
            "P-4379V-21.7.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-1948",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-9456V-24.4",
            "P-9456V-25.1.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle REST Data Services",
          "text": "37931569"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle REST Data Services (component: General (Eclipse Jetty)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-9456V-24.4",
          "P-9456V-25.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9456V-24.4",
            "P-9456V-25.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9456V-24.4",
            "P-9456V-25.1.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-9456V-24.4",
            "P-9456V-25.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-1974",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37806393"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Ingress NGINX Controller)).  Supported versions that are affected are 6.0.5-6.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.0.5-6.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5-6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.0.5-6.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-22228",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "P-14250V-24.2.4"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
          "text": "38142717"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (Spring Boot)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-14250V-24.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093901.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14250V-24.2.4"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
          "product_ids": [
            "P-14250V-24.2.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-22865",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-1870V-18.1.4.52.0",
            "P-1870V-22.1.1.32.0",
            "P-13444V-24.1.3"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle TimesTen In-Memory Database",
          "text": "37768409"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Blockchain Platform",
          "text": "37768400"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Golang Go)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle TimesTen In-Memory Database (component: Third-party components (Golang Go)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-1870V-22.1.1.32.0",
          "P-13444V-24.1.3",
          "P-1870V-18.1.4.52.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1870V-18.1.4.52.0",
            "P-1870V-22.1.1.32.0",
            "P-13444V-24.1.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1870V-18.1.4.52.0",
            "P-1870V-22.1.1.32.0",
            "P-13444V-24.1.3"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-1870V-18.1.4.52.0",
            "P-1870V-22.1.1.32.0",
            "P-13444V-24.1.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-23016",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Communications Broker",
          "text": "37932485"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Session Border Controller",
          "text": "37877587"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Core Session Manager",
          "text": "37932487"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Third Party (FastCGI fcgi2)).  Supported versions that are affected are 9.2.0, 9.3.0 and  10.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Session Border Controller executes to compromise Oracle Communications Session Border Controller.  While the vulnerability is in Oracle Communications Session Border Controller, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Border Controller. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Core Session Manager product of Oracle Communications (component: Third Party (FastCGI fcgi2)).   The supported version that is affected is 9.1.5. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Core Session Manager executes to compromise Oracle Communications Core Session Manager.  While the vulnerability is in Oracle Communications Core Session Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Core Session Manager. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications (component: Third Party (FastCGI fcgi2)).  Supported versions that are affected are 4.1.0, 4.2.0 and  5.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Enterprise Communications Broker executes to compromise Oracle Enterprise Communications Broker.  While the vulnerability is in Oracle Enterprise Communications Broker, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Communications Broker. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10750V-10.0.0",
          "P-10754V-9.1.5",
          "P-10758V-4.2.0",
          "P-10758V-4.1.0",
          "P-10758V-5.0.0",
          "P-10750V-9.2.0",
          "P-10750V-9.3.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10750V-10.0.0",
            "P-10750V-9.2.0",
            "P-10750V-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091941.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10754V-9.1.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091973.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10758V-4.2.0",
            "P-10758V-4.1.0",
            "P-10758V-5.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091942.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10750V-10.0.0",
            "P-10754V-9.1.5",
            "P-10758V-4.2.0",
            "P-10758V-4.1.0",
            "P-10758V-5.0.0",
            "P-10750V-9.2.0",
            "P-10750V-9.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-23083",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.18",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.8"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "37623842"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "37756793"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards (Node.js)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the GraalVM Multilingual Engine component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ],
        "known_not_affected": [
          "P-5(GraalVM Multilingual Engine)V-21.3-21.18",
          "P-5(GraalVM Multilingual Engine)V-23.4-23.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092433.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.18",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.6,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.18",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.8"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5(GraalVM Multilingual Engine)V-21.3-21.18",
            "P-5(GraalVM Multilingual Engine)V-23.4-23.8"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-23084",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "37623842"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards (Node.js)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092433.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.6,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-23085",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "37623842"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Blockchain Platform",
          "text": "37623821"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Node.js)).   The supported version that is affected is 24.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Blockchain Platform.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Blockchain Platform accessible data as well as  unauthorized read access to a subset of Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch Dashboards (Node.js)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13444V-24.1.3",
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13444V-24.1.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092433.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-13444V-24.1.3"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 5.6,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-23165",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-14125V-25.1.100"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment",
          "text": "37989428"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GraalVM for JDK",
          "text": "37971244"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Node (Node.js)).  Supported versions that are affected are Oracle GraalVM for JDK: 17.0.15, 21.0.7 and  24.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM for JDK.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GraalVM for JDK. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (Node.js)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13497V-17.0.15",
          "P-13497V-24.0.1",
          "P-13497V-21.0.7"
        ],
        "known_not_affected": [
          "P-14125V-25.1.100"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13497V-21.0.7",
            "P-13497V-17.0.15",
            "P-13497V-24.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092096.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14125V-25.1.100"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092743.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13497V-21.0.7",
            "P-13497V-17.0.15",
            "P-13497V-24.0.1"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14125V-25.1.100"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-14125V-25.1.100"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-23166",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-14125V-25.1.100"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment",
          "text": "37989428"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GraalVM for JDK",
          "text": "37971244"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Node (Node.js)).  Supported versions that are affected are Oracle GraalVM for JDK: 17.0.15, 21.0.7 and  24.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM for JDK.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GraalVM for JDK. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (Node.js)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13497V-17.0.15",
          "P-13497V-24.0.1",
          "P-13497V-21.0.7"
        ],
        "known_not_affected": [
          "P-14125V-25.1.100"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13497V-21.0.7",
            "P-13497V-17.0.15",
            "P-13497V-24.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092096.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14125V-25.1.100"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092743.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13497V-21.0.7",
            "P-13497V-17.0.15",
            "P-13497V-24.0.1"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14125V-25.1.100"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-14125V-25.1.100"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-23167",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-14125V-25.1.100"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment",
          "text": "37989428"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (Node.js)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-14125V-25.1.100"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14125V-25.1.100"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092743.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14125V-25.1.100"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-14125V-25.1.100"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-23184",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle BI Publisher",
          "text": "37614099"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Banking Origination",
          "text": "37614111"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API (Apache CXF)).  Supported versions that are affected are 7.6.0.0.0 and  8.2.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Maintenance (Apache CXF)).  Supported versions that are affected are 14.4.0.0.0-14.7.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Origination. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1479V-8.2.0.0.0",
          "P-1479V-7.6.0.0.0",
          "P-14325V-14.4.0.0.0-14.7.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1479V-7.6.0.0.0",
            "P-1479V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093264.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14325V-14.4.0.0.0-14.7.0.0.0"
          ],
          "url": "https://support.oracle.com"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-1479V-7.6.0.0.0",
            "P-1479V-8.2.0.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14325V-14.4.0.0.0-14.7.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-24813",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Hospitality Cruise Shipboard Property Management System",
          "text": "37610322"
        },
        {
          "system_name": "Oracle Bug ID of Siebel CRM Deployment",
          "text": "37453466"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Application Interface (Apache Tomcat)).  Supported versions that are affected are 25.0-25.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hospitality Cruise Shipboard Property Management System product of Oracle Hospitality Applications (component: Next-Gen SPMS (Apache Tomcat)).  Supported versions that are affected are 23.1.4 and  23.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Cruise Shipboard Property Management System.  Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Cruise Shipboard Property Management System. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11607V-23.1.4",
          "P-11607V-23.2.2",
          "P-9019V-25.0-25.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9019V-25.0-25.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092434.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11607V-23.1.4",
            "P-11607V-23.2.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092232.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9019V-25.0-25.5"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-11607V-23.1.4",
            "P-11607V-23.2.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-24814",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37614130"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Solr)).  Supported versions that are affected are 6.0.5-6.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.0.5-6.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5-6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.0.5-6.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-24855",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "37718198"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (libxslt)).  Supported versions that are affected are Oracle Java SE: 8u451-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u451-b50"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u451-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092096.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u451-b50"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-24928",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37806205"
        },
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "37806213"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
          "text": "37847502"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "37718170"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
          "text": "37806197"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
          "text": "38138651"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (libxml2)).  Supported versions that are affected are Oracle Java SE: 8u451-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: ATS Framework (libxml2)).   The supported version that is affected is 24.2.4. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Repository Function executes to compromise Oracle Communications Cloud Native Core Network Repository Function.  While the vulnerability is in Oracle Communications Cloud Native Core Network Repository Function, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Repository Function accessible data. CVSS 3.1 Base Score 7.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (libxml2)).  Supported versions that are affected are 6.0.5-6.1.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  While the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (libxml2)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server.  While the vulnerability is in Oracle HTTP Server, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data as well as  unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 7.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Install/Upgrade (Libtasn1)).   The supported version that is affected is 24.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Signaling (libxml2)).  Supported versions that are affected are 24.2.4 and  25.1.101. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Security Edge Protection Proxy executes to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  While the vulnerability is in Oracle Communications Cloud Native Core Security Edge Protection Proxy, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 7.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u451-b50",
          "P-14118(ATS Framework)V-24.2.4",
          "P-14597V-6.0.5-6.1.0",
          "P-1042(Core)V-12.2.1.4.0",
          "P-1042(Core)V-14.1.2.0.0",
          "P-14123V-25.1.101",
          "P-14118(Install/Upgrade)V-24.2.4",
          "P-14123V-24.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u451-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092096.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118(ATS Framework)V-24.2.4",
            "P-14118(Install/Upgrade)V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092975.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5-6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Core)V-12.2.1.4.0",
            "P-1042(Core)V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14123V-25.1.101",
            "P-14123V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092746.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u451-b50"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14118(ATS Framework)V-24.2.4",
            "P-1042(Core)V-12.2.1.4.0",
            "P-1042(Core)V-14.1.2.0.0",
            "P-14123V-25.1.101",
            "P-14123V-24.2.4"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.0.5-6.1.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14118(Install/Upgrade)V-24.2.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-24970",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Banking Origination",
          "text": "37588795"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "37588895"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
          "text": "37588893"
        },
        {
          "system_name": "Oracle Bug ID of Oracle NoSQL Database",
          "text": "37588877"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
          "text": "37588888"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Stream Analytics",
          "text": "37588896"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
          "text": "37588825"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Offline Mediation Controller",
          "text": "37588837"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "37588834"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37588819"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
          "text": "37772146"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Maintenance (Netty)).  Supported versions that are affected are 14.4.0.0.0-14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Origination. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Netty)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Signaling (Netty)).   The supported version that is affected is 24.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Core (Netty)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications Applications (component: Install (Netty)).  Supported versions that are affected are 15.0.0.0 and  15.0.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Offline Mediation Controller executes to compromise Oracle Communications Offline Mediation Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Offline Mediation Controller. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle NoSQL Database (component: Administration (Netty)).  Supported versions that are affected are 22.3.51, 23.1.38 and  24.4.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle NoSQL Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle NoSQL Database. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Point of Sale (Netty)).  Supported versions that are affected are 22.0.2 and  23.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: SW-System Wide (Netty)).  Supported versions that are affected are 2.5.0.1.15, 2.5.0.2.9, 2.6.0.1.7 and  2.6.0.2.2. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Utilities Network Management System executes to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Network Management System. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Open Search, Logstash (Netty)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Stream Analytics product of Oracle GoldenGate (component: Stream Analytics (Netty)).  Supported versions that are affected are 19.1.0.0.0-19.1.0.0.11. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle GoldenGate Stream Analytics executes to compromise Oracle GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate Stream Analytics. CVSS 3.1 Base Score 4.8 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Netty)).  Supported versions that are affected are 23.4-23.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle GoldenGate Big Data and Application Adapters.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GoldenGate Big Data and Application Adapters. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5760V-23.4-23.7",
          "P-13373V-23.1.38",
          "P-14122V-24.2.0",
          "P-11513V-22.0.2",
          "P-2269V-15.0.0.0",
          "P-2269V-15.0.1.0",
          "P-13373V-22.3.51",
          "P-14325V-14.4.0.0.0-14.7.0.0.0",
          "P-2241V-2.6.0.1.7",
          "P-2241V-2.5.0.2.9",
          "P-2241V-2.6.0.2.2",
          "P-2241V-2.5.0.1.15",
          "P-11513V-23.0.2",
          "P-14130V-24.3.1",
          "P-14015V-19.1.0.0.0-19.1.0.0.11",
          "P-13373V-24.4.9",
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ],
        "known_not_affected": [
          "P-14547V-24.3.0",
          "P-14547V-25.1.100",
          "P-14547V-24.2.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14325V-14.4.0.0.0-14.7.0.0.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-24.3.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092745.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092973.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2269V-15.0.0.0",
            "P-2269V-15.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090955.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5760V-23.4-23.7",
            "P-13373V-23.1.38",
            "P-13373V-22.3.51",
            "P-14015V-19.1.0.0.0-19.1.0.0.11",
            "P-13373V-24.4.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11513V-22.0.2",
            "P-11513V-23.0.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090426.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2241V-2.5.0.1.15",
            "P-2241V-2.6.0.1.7",
            "P-2241V-2.5.0.2.9",
            "P-2241V-2.6.0.2.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093776.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092433.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14122V-24.2.0",
            "P-11513V-22.0.2",
            "P-14325V-14.4.0.0.0-14.7.0.0.0",
            "P-11513V-23.0.2",
            "P-14130V-24.3.1",
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2269V-15.0.0.0",
            "P-2269V-15.0.1.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-5760V-23.4-23.7",
            "P-13373V-23.1.38",
            "P-13373V-22.3.51",
            "P-13373V-24.4.9"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2241V-2.5.0.1.15",
            "P-2241V-2.6.0.1.7",
            "P-2241V-2.5.0.2.9",
            "P-2241V-2.6.0.2.2"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14015V-19.1.0.0.0-19.1.0.0.11"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-25193",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Banking Origination",
          "text": "37588795"
        },
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "37588895"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
          "text": "37588893"
        },
        {
          "system_name": "Oracle Bug ID of Oracle NoSQL Database",
          "text": "37588877"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
          "text": "37588888"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Stream Analytics",
          "text": "37588896"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37588819"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Netty)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Maintenance (Netty)).  Supported versions that are affected are 14.4.0.0.0-14.7.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Origination. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle NoSQL Database (component: Administration (Netty)).  Supported versions that are affected are 22.3.51, 23.1.38 and  24.4.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle NoSQL Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle NoSQL Database. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Point of Sale (Netty)).  Supported versions that are affected are 22.0.2 and  23.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: SW-System Wide (Netty)).  Supported versions that are affected are 2.5.0.1.15, 2.5.0.2.9, 2.6.0.1.7 and  2.6.0.2.2. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Utilities Network Management System executes to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Network Management System. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Open Search, Logstash (Netty)).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Stream Analytics product of Oracle GoldenGate (component: Stream Analytics (Netty)).  Supported versions that are affected are 19.1.0.0.0-19.1.0.0.11. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle GoldenGate Stream Analytics executes to compromise Oracle GoldenGate Stream Analytics.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate Stream Analytics. CVSS 3.1 Base Score 4.8 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13373V-23.1.38",
          "P-14122V-24.2.0",
          "P-11513V-22.0.2",
          "P-13373V-22.3.51",
          "P-14325V-14.4.0.0.0-14.7.0.0.0",
          "P-2241V-2.6.0.1.7",
          "P-2241V-2.5.0.2.9",
          "P-2241V-2.6.0.2.2",
          "P-2241V-2.5.0.1.15",
          "P-11513V-23.0.2",
          "P-14015V-19.1.0.0.0-19.1.0.0.11",
          "P-13373V-24.4.9",
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14325V-14.4.0.0.0-14.7.0.0.0"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13373V-23.1.38",
            "P-13373V-22.3.51",
            "P-14015V-19.1.0.0.0-19.1.0.0.11",
            "P-13373V-24.4.9"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11513V-22.0.2",
            "P-11513V-23.0.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090426.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2241V-2.5.0.1.15",
            "P-2241V-2.6.0.1.7",
            "P-2241V-2.5.0.2.9",
            "P-2241V-2.6.0.2.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093776.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092433.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14122V-24.2.0",
            "P-11513V-22.0.2",
            "P-14325V-14.4.0.0.0-14.7.0.0.0",
            "P-11513V-23.0.2",
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-13373V-23.1.38",
            "P-13373V-22.3.51",
            "P-13373V-24.4.9"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2241V-2.5.0.1.15",
            "P-2241V-2.6.0.1.7",
            "P-2241V-2.5.0.2.9",
            "P-2241V-2.6.0.2.2"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14015V-19.1.0.0.0-19.1.0.0.11"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-26791",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37932464"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
          "text": "37691511"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Insurance Policy Administration J2EE",
          "text": "37932479"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Insurance Policy Administration J2EE product of Oracle Insurance Applications (component: Architecture (DOMPurify)).   The supported version that is affected is 12.0.4. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Insurance Policy Administration J2EE executes to compromise Oracle Insurance Policy Administration J2EE.  While the vulnerability is in Oracle Insurance Policy Administration J2EE, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Insurance Policy Administration J2EE accessible data as well as  unauthorized read access to a subset of Oracle Insurance Policy Administration J2EE accessible data. CVSS 3.1 Base Score 4.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (DOMPurify)).  Supported versions that are affected are 6.0.5-6.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  While the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 4.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: Security (DOMPurify)).  Supported versions that are affected are 4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 24.1.0.0.0-24.3.0.0.0 and  25.4. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Utilities Application Framework executes to compromise Oracle Utilities Application Framework.  While the vulnerability is in Oracle Utilities Application Framework, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Utilities Application Framework accessible data as well as  unauthorized read access to a subset of Oracle Utilities Application Framework accessible data. CVSS 3.1 Base Score 4.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.0.5-6.1.0",
          "P-5279V-12.0.4",
          "P-2245V-24.1.0.0.0-24.3.0.0.0",
          "P-2245V-4.5.0.1.3",
          "P-2245V-4.5.0.1.1",
          "P-2245V-25.4",
          "P-2245V-4.3.0.6.0",
          "P-2245V-4.5.0.0.0",
          "P-2245V-4.4.0.0.0",
          "P-2245V-4.4.0.2.0",
          "P-2245V-4.4.0.3.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5279V-12.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092287.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5-6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2245V-24.1.0.0.0-24.3.0.0.0",
            "P-2245V-4.5.0.1.3",
            "P-2245V-4.5.0.1.1",
            "P-2245V-25.4",
            "P-2245V-4.3.0.6.0",
            "P-2245V-4.5.0.0.0",
            "P-2245V-4.4.0.0.0",
            "P-2245V-4.4.0.2.0",
            "P-2245V-4.4.0.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093776.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.0.5-6.1.0",
            "P-5279V-12.0.4",
            "P-2245V-24.1.0.0.0-24.3.0.0.0",
            "P-2245V-4.5.0.1.3",
            "P-2245V-4.5.0.1.1",
            "P-2245V-25.4",
            "P-2245V-4.3.0.6.0",
            "P-2245V-4.5.0.0.0",
            "P-2245V-4.4.0.0.0",
            "P-2245V-4.4.0.2.0",
            "P-2245V-4.4.0.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27113",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37806205"
        },
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "37806213"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "37718170"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
          "text": "37806197"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (libxml2)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server.  While the vulnerability is in Oracle HTTP Server, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data as well as  unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 7.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: ATS Framework (libxml2)).   The supported version that is affected is 24.2.4. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Repository Function executes to compromise Oracle Communications Cloud Native Core Network Repository Function.  While the vulnerability is in Oracle Communications Cloud Native Core Network Repository Function, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Repository Function accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Repository Function accessible data. CVSS 3.1 Base Score 7.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (libxml2)).  Supported versions that are affected are Oracle Java SE: 8u451-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (libxml2)).  Supported versions that are affected are 6.0.5-6.1.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  While the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14118(ATS Framework)V-24.2.4",
          "P-856V-8u451-b50",
          "P-14597V-6.0.5-6.1.0",
          "P-1042(Core)V-12.2.1.4.0",
          "P-1042(Core)V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Core)V-12.2.1.4.0",
            "P-1042(Core)V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118(ATS Framework)V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092975.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u451-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092096.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5-6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14118(ATS Framework)V-24.2.4",
            "P-1042(Core)V-12.2.1.4.0",
            "P-1042(Core)V-14.1.2.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u451-b50"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.0.5-6.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27363",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
          "text": "37735449"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Text (FreeType)",
          "text": "37684134"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
          "text": "37735457"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
          "text": "37735447"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37735436"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "37735458"
        },
        {
          "system_name": "Oracle Bug ID of Oracle AutoVue",
          "text": "37735426"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "37735442"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "37735455"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37735462"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (FreeType)).  Supported versions that are affected are 5.1 and  5.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Platform (FreeType)).  Supported versions that are affected are 24.2.0, 24.3.0 and  25.1.100. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Analytics Data Director.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Analytics Data Director. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: ATS Framework (FreeType)).  Supported versions that are affected are 24.2.4 and  25.1.100. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Automated Test Suite (FreeType)).  Supported versions that are affected are 24.2.0 and  25.1.100. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (FreeType)).  Supported versions that are affected are 24.2.0-24.2.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (FreeType)).   The supported version that is affected is 24.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle AutoVue product of Oracle Supply Chain (component: Core (FreeType)).  Supported versions that are affected are 21.0.2 and  21.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle AutoVue.  Successful attacks of this vulnerability can result in takeover of Oracle AutoVue.  Note: This vulnerability applies to Oracle AutoVue Office, Oracle AutoVue 2D Professional, Oracle AutoVue 3D Professional Advanced, Oracle AutoVue EDA Professional and Oracle AutoVue Electro-Mechanical Professional. Please refer to Patch Availability Document for more details. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Text (FreeType) component of Oracle Database Server.  Supported versions that are affected are 19.3-19.27, 21.3-21.18 and  23.4-23.8. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Index privilege with network access via Oracle Net to compromise Oracle Text (FreeType).  Successful attacks of this vulnerability can result in takeover of Oracle Text (FreeType). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: CMP (FreeType)).   The supported version that is affected is 15.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (FreeType)).  Supported versions that are affected are 6.0.5-6.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.0.5-6.1.0",
          "P-211V-19.3-19.27",
          "P-14547V-25.1.100",
          "P-14122V-24.2.0",
          "P-10900V-15.0.0.0",
          "P-14547V-24.2.0",
          "P-14547V-24.3.0",
          "P-14123V-25.1.100",
          "P-14117V-25.1.100",
          "P-14277V-24.2.0-24.2.6",
          "P-14123V-24.2.4",
          "P-10761V-5.1",
          "P-14117V-24.2.0",
          "P-211V-23.4-23.8",
          "P-10761V-5.2",
          "P-4453V-21.0.2",
          "P-4453V-21.1.0",
          "P-211V-21.3-21.18"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10761V-5.1",
            "P-10761V-5.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092732.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092973.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14123V-25.1.100",
            "P-14123V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092746.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14117V-24.2.0",
            "P-14117V-25.1.100"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092730.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.0-24.2.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092749.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4453V-21.0.2",
            "P-4453V-21.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092435.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-211V-19.3-19.27",
            "P-211V-23.4-23.8",
            "P-211V-21.3-21.18"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092747.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5-6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10761V-5.1",
            "P-211V-19.3-19.27",
            "P-211V-23.4-23.8",
            "P-10761V-5.2",
            "P-211V-21.3-21.18"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14117V-24.2.0",
            "P-14547V-25.1.100",
            "P-14122V-24.2.0",
            "P-10900V-15.0.0.0",
            "P-14547V-24.2.0",
            "P-4453V-21.0.2",
            "P-14547V-24.3.0",
            "P-14123V-25.1.100",
            "P-4453V-21.1.0",
            "P-14117V-25.1.100",
            "P-14277V-24.2.0-24.2.6",
            "P-14123V-24.2.4"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 6.6,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.0.5-6.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27516",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core DBTier",
          "text": "37476556"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core DBTier product of Oracle Communications (component: Configuration (Jinja)).  Supported versions that are affected are 24.3.0 and  25.1.100. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core DBTier executes to compromise Oracle Communications Cloud Native Core DBTier.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core DBTier. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14974V-24.3.0",
          "P-14974V-25.1.100"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14974V-24.3.0",
            "P-14974V-25.1.100"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092983.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14974V-24.3.0",
            "P-14974V-25.1.100"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27533",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "38086435"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "37994392"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache ActiveMQ)).  Supported versions that are affected are 8.0.7.8, 8.0.8.6, 8.1.1.4 and  8.1.2.5. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Microservices (Apache ActiveMQ)).  Supported versions that are affected are 6.0.5-6.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5680V-8.1.2.5",
          "P-14597V-6.0.5-6.1.0",
          "P-5680V-8.0.7.8",
          "P-5680V-8.0.8.6",
          "P-5680V-8.1.1.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.8.6",
            "P-5680V-8.0.7.8",
            "P-5680V-8.1.1.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092118.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5-6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5680V-8.1.2.5",
            "P-14597V-6.0.5-6.1.0",
            "P-5680V-8.0.8.6",
            "P-5680V-8.0.7.8",
            "P-5680V-8.1.1.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27553",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
          "text": "37766969"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Data Integrator",
          "text": "37952596"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Commons VFS)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Commons VFS)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4647V-12.2.1.4.0",
          "P-2196V-14.1.2.0.0",
          "P-4647V-14.1.2.0.0",
          "P-2196V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4647V-14.1.2.0.0",
            "P-2196V-12.2.1.4.0",
            "P-4647V-12.2.1.4.0",
            "P-2196V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4647V-14.1.2.0.0",
            "P-2196V-12.2.1.4.0",
            "P-4647V-12.2.1.4.0",
            "P-2196V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27636",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Banking Origination",
          "text": "37736075"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Maintenance (Apache Camel)).  Supported versions that are affected are 14.4.0.0.0-14.7.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Origination accessible data as well as  unauthorized read access to a subset of Oracle Banking Origination accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Origination. CVSS 3.1 Base Score 5.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14325V-14.4.0.0.0-14.7.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14325V-14.4.0.0.0-14.7.0.0.0"
          ],
          "url": "https://support.oracle.com"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.6,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14325V-14.4.0.0.0-14.7.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27817",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ]
        },
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-14117V-24.2.0",
            "P-14117V-25.1.100"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Data Quality",
          "text": "38128796"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "38128832"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition",
          "text": "38128853"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
          "text": "38128822"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Behavior Detection Platform",
          "text": "38128838"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38128826"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache Kafka)).  Supported versions that are affected are 8.0.7.8, 8.0.8.6, 8.1.1.4 and  8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Core (Apache Kafka)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Signaling (Apache Kafka)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: Third Party (Apache Kafka)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Data Quality.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Enterprise Data Quality accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (Apache Kafka)).  Supported versions that are affected are 8.0.8.1, 8.1.2.8 and  8.1.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Behavior Detection Platform accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (Apache Kafka)).   The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5680V-8.1.2.5",
          "P-13789V-8.0.8",
          "P-5680V-8.0.8.6",
          "P-9190V-8.1.2.9",
          "P-9190V-8.0.8.1",
          "P-9190V-8.1.2.8",
          "P-5680V-8.0.7.8",
          "P-9464V-12.2.1.4.0",
          "P-9464V-14.1.2.0.0",
          "P-5680V-8.1.1.4"
        ],
        "known_not_affected": [
          "P-14547V-24.3.0",
          "P-14117V-25.1.100",
          "P-14117V-24.2.0",
          "P-14547V-25.1.100",
          "P-14547V-24.2.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.8.6",
            "P-5680V-8.0.7.8",
            "P-5680V-8.1.1.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092118.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092973.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14117V-24.2.0",
            "P-14117V-25.1.100"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092730.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9464V-12.2.1.4.0",
            "P-9464V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9190V-8.1.2.9",
            "P-9190V-8.0.8.1",
            "P-9190V-8.1.2.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090123.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13789V-8.0.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090124.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5680V-8.1.2.5",
            "P-13789V-8.0.8",
            "P-5680V-8.0.8.6",
            "P-9190V-8.1.2.9",
            "P-9190V-8.0.8.1",
            "P-9190V-8.1.2.8",
            "P-5680V-8.0.7.8",
            "P-9464V-12.2.1.4.0",
            "P-9464V-14.1.2.0.0",
            "P-5680V-8.1.1.4"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14117V-24.2.0",
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0",
            "P-14117V-25.1.100"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
          "product_ids": [
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ]
        },
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-14117V-24.2.0",
            "P-14117V-25.1.100"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27818",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-14117V-24.2.0",
            "P-14117V-25.1.100"
          ]
        },
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Data Quality",
          "text": "38128796"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "38128832"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition",
          "text": "38128853"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
          "text": "38128822"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Behavior Detection Platform",
          "text": "38128838"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Analytics Data Director",
          "text": "38128826"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: Third Party (Apache Kafka)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Data Quality.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Enterprise Data Quality accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Signaling (Apache Kafka)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications Network Analytics Data Director product of Oracle Communications (component: Core (Apache Kafka)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache Kafka)).  Supported versions that are affected are 8.0.7.8, 8.0.8.6, 8.1.1.4 and  8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (Apache Kafka)).  Supported versions that are affected are 8.0.8.1, 8.1.2.8 and  8.1.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Behavior Detection Platform accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (Apache Kafka)).   The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5680V-8.1.2.5",
          "P-13789V-8.0.8",
          "P-5680V-8.0.8.6",
          "P-9190V-8.1.2.9",
          "P-9190V-8.0.8.1",
          "P-9190V-8.1.2.8",
          "P-9464V-12.2.1.4.0",
          "P-5680V-8.0.7.8",
          "P-9464V-14.1.2.0.0",
          "P-5680V-8.1.1.4"
        ],
        "known_not_affected": [
          "P-14547V-24.3.0",
          "P-14117V-25.1.100",
          "P-14117V-24.2.0",
          "P-14547V-25.1.100",
          "P-14547V-24.2.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9464V-12.2.1.4.0",
            "P-9464V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14117V-24.2.0",
            "P-14117V-25.1.100"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092730.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092973.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.8.6",
            "P-5680V-8.0.7.8",
            "P-5680V-8.1.1.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092118.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9190V-8.1.2.9",
            "P-9190V-8.0.8.1",
            "P-9190V-8.1.2.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090123.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13789V-8.0.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090124.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5680V-8.1.2.5",
            "P-13789V-8.0.8",
            "P-5680V-8.0.8.6",
            "P-9190V-8.1.2.9",
            "P-9190V-8.0.8.1",
            "P-9190V-8.1.2.8",
            "P-9464V-12.2.1.4.0",
            "P-5680V-8.0.7.8",
            "P-9464V-14.1.2.0.0",
            "P-5680V-8.1.1.4"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14117V-24.2.0",
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0",
            "P-14117V-25.1.100"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-14117V-24.2.0",
            "P-14117V-25.1.100"
          ]
        },
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The product is not affected because the code underlying the vulnerability is not present in the product. The component in question is present, but for whatever reason (e.g. compiler options) the specific code causing the vulnerability is not present in the component.",
          "product_ids": [
            "P-14547V-25.1.100",
            "P-14547V-24.2.0",
            "P-14547V-24.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27819",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Data Quality",
          "text": "38128796"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: Third Party (Apache Kafka)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Data Quality.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Enterprise Data Quality accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9464V-14.1.2.0.0",
          "P-9464V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9464V-12.2.1.4.0",
            "P-9464V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9464V-12.2.1.4.0",
            "P-9464V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-27820",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
          "text": "37877310"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: Java Delivery (Apache HttpClient)).  Supported versions that are affected are 23.4-23.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle GoldenGate Big Data and Application Adapters.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle GoldenGate Big Data and Application Adapters accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5760V-23.4-23.6"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5760V-23.4-23.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5760V-23.4-23.6"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-29482",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Outside In Technology",
          "text": "38037793"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: DC-Specific Component (libheif)).   The supported version that is affected is 8.5.7. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology. CVSS 3.1 Base Score 6.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2276V-8.5.7"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2276V-8.5.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.2,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2276V-8.5.7"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-29891",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Banking Origination",
          "text": "37736075"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Maintenance (Apache Camel)).  Supported versions that are affected are 14.4.0.0.0-14.7.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Origination accessible data as well as  unauthorized read access to a subset of Oracle Banking Origination accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Origination. CVSS 3.1 Base Score 5.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14325V-14.4.0.0.0-14.7.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14325V-14.4.0.0.0-14.7.0.0.0"
          ],
          "url": "https://support.oracle.com"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.6,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14325V-14.4.0.0.0-14.7.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30065",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.11"
          ]
        },
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-5760V-23.4-23.7",
            "P-5760V-21.3-21.17"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Stream Analytics",
          "text": "37810352"
        },
        {
          "system_name": "Oracle Bug ID of Oracle GoldenGate Big Data and Application Adapters",
          "text": "37810335"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "37798855"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Stream Analytics product of Oracle GoldenGate (component: Stream Analytics (Apache Parquet Java)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: GoldenGate Big Data and Application Adapters (Apache Parquet Java)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Apache Parquet Java)).  Supported versions that are affected are 7.6.0.0.0 and  8.2.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2025V-7.6.0.0.0",
          "P-2025V-8.2.0.0.0"
        ],
        "known_not_affected": [
          "P-14015V-19.1.0.0.0-19.1.0.0.11",
          "P-5760V-23.4-23.7",
          "P-5760V-21.3-21.17"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5760V-23.4-23.7",
            "P-5760V-21.3-21.17",
            "P-14015V-19.1.0.0.0-19.1.0.0.11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093264.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14015V-19.1.0.0.0-19.1.0.0.11"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5760V-23.4-23.7",
            "P-5760V-21.3-21.17"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-14015V-19.1.0.0.0-19.1.0.0.11"
          ]
        },
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-5760V-23.4-23.7",
            "P-5760V-21.3-21.17"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30474",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Data Integrator",
          "text": "37952596"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Commons VFS)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2196V-14.1.2.0.0",
          "P-2196V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2196V-12.2.1.4.0",
            "P-2196V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-2196V-12.2.1.4.0",
            "P-2196V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30739",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle CRM Technical Foundation",
          "text": "36075627"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences).  Supported versions that are affected are 12.2.11-12.2.13. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle CRM Technical Foundation.  While the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data as well as  unauthorized read access to a subset of Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1199V-12.2.11-12.2.13"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1199V-12.2.11-12.2.13"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1199V-12.2.11-12.2.13"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30743",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Lease and Finance Management",
          "text": "36097561"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations).   The supported version that is affected is 12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Lease and Finance Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Lease and Finance Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Lease and Finance Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1056V-12.2.13"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1056V-12.2.13"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1056V-12.2.13"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30744",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Mobile Field Service",
          "text": "36111923"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Mobile Field Service product of Oracle E-Business Suite (component: Multiplatform Sync Errors).  Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Mobile Field Service.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Mobile Field Service accessible data as well as  unauthorized access to critical data or complete access to all Oracle Mobile Field Service accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-753V-12.2.3-12.2.13"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-753V-12.2.3-12.2.13"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-753V-12.2.3-12.2.13"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30745",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle MES for Process Manufacturing",
          "text": "36569441"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Device Integration).  Supported versions that are affected are 12.2.12-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MES for Process Manufacturing.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle MES for Process Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle MES for Process Manufacturing accessible data as well as  unauthorized read access to a subset of Oracle MES for Process Manufacturing accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1776V-12.2.12-12.2.13"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1776V-12.2.12-12.2.13"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1776V-12.2.12-12.2.13"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30746",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle iStore",
          "text": "36589614"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart).  Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle iStore accessible data as well as  unauthorized read access to a subset of Oracle iStore accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-384V-12.2.3-12.2.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-384V-12.2.3-12.2.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-384V-12.2.3-12.2.14"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30747",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "36915808"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092433.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30748",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
          "text": "37108083"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology).  Supported versions that are affected are 8.60, 8.61 and  8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.61",
          "P-5085V-8.60",
          "P-5085V-8.62"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092433.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.61",
            "P-5085V-8.60",
            "P-5085V-8.62"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30749",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "37127529"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D).  Supported versions that are affected are Oracle Java SE: 8u451, 8u451-perf, 11.0.27, 17.0.15, 21.0.7, 24.0.1; Oracle GraalVM for JDK: 17.0.15, 21.0.7 and  24.0.1; Oracle GraalVM Enterprise Edition: 21.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-17.0.15",
          "P-856V-21.0.7",
          "P-856V-24.0.1",
          "P-856V-8u451-perf",
          "P-13497V-21.0.7",
          "P-856V-11.0.27",
          "P-13497V-21.3.14",
          "P-13497V-17.0.15",
          "P-13497V-24.0.1",
          "P-856V-8u451"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-17.0.15",
            "P-856V-21.0.7",
            "P-856V-24.0.1",
            "P-856V-8u451-perf",
            "P-13497V-21.0.7",
            "P-856V-11.0.27",
            "P-13497V-21.3.14",
            "P-13497V-17.0.15",
            "P-13497V-24.0.1",
            "P-856V-8u451"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092096.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-856V-17.0.15",
            "P-856V-21.0.7",
            "P-856V-24.0.1",
            "P-856V-8u451-perf",
            "P-13497V-21.0.7",
            "P-856V-11.0.27",
            "P-13497V-21.3.14",
            "P-13497V-17.0.15",
            "P-13497V-24.0.1",
            "P-856V-8u451"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Emad Al-Mousa"
          ]
        }
      ],
      "cve": "CVE-2025-30750",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "37160207"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Unified Audit component of Oracle Database Server.  Supported versions that are affected are 19.3-19.27, 21.3-21.18 and  23.4-23.8. Easily exploitable vulnerability allows high privileged attacker having Create User privilege with network access via Oracle Net to compromise Unified Audit.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Unified Audit accessible data. CVSS 3.1 Base Score 2.4 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(Unified Audit)V-23.4-23.8",
          "P-5(Unified Audit)V-21.3-21.18",
          "P-5(Unified Audit)V-19.3-19.27"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Unified Audit)V-21.3-21.18",
            "P-5(Unified Audit)V-23.4-23.8",
            "P-5(Unified Audit)V-19.3-19.27"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.4,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Unified Audit)V-21.3-21.18",
            "P-5(Unified Audit)V-23.4-23.8",
            "P-5(Unified Audit)V-19.3-19.27"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30751",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38080838"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Database component of Oracle Database Server.  Supported versions that are affected are 19.27 and  23.4-23.8. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Oracle Database.  Successful attacks of this vulnerability can result in takeover of Oracle Database. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(Oracle Database)V-19.27",
          "P-5(Oracle Database)V-23.4-23.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Oracle Database)V-23.4-23.8",
            "P-5(Oracle Database)V-19.27"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5(Oracle Database)V-23.4-23.8",
            "P-5(Oracle Database)V-19.27"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30752",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "37210808"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK product of Oracle Java SE (component: Compiler).   The supported version that is affected is Oracle Java SE: 24.0.1; Oracle GraalVM for JDK: 24.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-24.0.1",
          "P-13497V-24.0.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-24.0.1",
            "P-13497V-24.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092096.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-856V-24.0.1",
            "P-13497V-24.0.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30753",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebLogic Server",
          "text": "37326421"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5242V-12.2.1.4.0",
          "P-5242V-14.1.2.0.0",
          "P-5242V-14.1.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Mashroor Hasan Bhuiyan"
          ]
        }
      ],
      "cve": "CVE-2025-30754",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "37441154"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE).  Supported versions that are affected are Oracle Java SE: 8u451, 8u451-perf, 11.0.27, 17.0.15, 21.0.7, 24.0.1; Oracle GraalVM for JDK: 17.0.15, 21.0.7 and  24.0.1; Oracle GraalVM Enterprise Edition: 21.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-17.0.15",
          "P-856V-21.0.7",
          "P-856V-24.0.1",
          "P-856V-8u451-perf",
          "P-13497V-21.0.7",
          "P-856V-11.0.27",
          "P-13497V-21.3.14",
          "P-13497V-17.0.15",
          "P-13497V-24.0.1",
          "P-856V-8u451"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-17.0.15",
            "P-856V-21.0.7",
            "P-856V-24.0.1",
            "P-856V-8u451-perf",
            "P-13497V-21.0.7",
            "P-856V-11.0.27",
            "P-13497V-21.3.14",
            "P-13497V-17.0.15",
            "P-13497V-24.0.1",
            "P-856V-8u451"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092096.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-856V-17.0.15",
            "P-856V-21.0.7",
            "P-856V-24.0.1",
            "P-856V-8u451-perf",
            "P-13497V-21.0.7",
            "P-856V-11.0.27",
            "P-13497V-21.3.14",
            "P-13497V-17.0.15",
            "P-13497V-24.0.1",
            "P-856V-8u451"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Juttikhun Jirathanan"
          ]
        },
        {
          "names": [
            "Khamolwan Hnunainam"
          ],
          "organization": "IT SELECT LAB Company Ltd"
        },
        {
          "names": [
            "Pongsathon Sirithanyakul"
          ]
        },
        {
          "names": [
            "Warunyou Sunpachit"
          ],
          "organization": "IT SELECT LAB Company Ltd"
        }
      ],
      "cve": "CVE-2025-30756",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle REST Data Services",
          "text": "37511335"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle REST Data Services (component: General).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle REST Data Services.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle REST Data Services accessible data as well as  unauthorized read access to a subset of Oracle REST Data Services accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9456V-24.2.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9456V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9456V-24.2.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Javad Karimi"
          ]
        }
      ],
      "cve": "CVE-2025-30758",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Siebel CRM End User",
          "text": "37519135"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface).  Supported versions that are affected are 25.0-25.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Siebel CRM End User accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9011V-25.0-25.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9011V-25.0-25.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092434.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9011V-25.0-25.5"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Jean-Michel Huguet"
          ],
          "organization": "NATO Cyber Security Centre (NCSC)"
        }
      ],
      "cve": "CVE-2025-30759",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "37550060"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security).  Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2025V-7.6.0.0.0",
          "P-2025V-8.2.0.0.0",
          "P-2025V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-12.2.1.4.0",
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093264.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-2025V-12.2.1.4.0",
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30760",
      "ids": [
        {
          "system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
          "text": "37584057"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC).  Supported versions that are affected are 9.2.0.0-9.2.9.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4781V-9.2.0.0-9.2.9.3"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-9.2.0.0-9.2.9.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092412.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4781V-9.2.0.0-9.2.9.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-30761",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "37623700"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Scripting).  Supported versions that are affected are Oracle Java SE: 8u451, 8u451-perf and  11.0.27; Oracle GraalVM Enterprise Edition: 21.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u451-perf",
          "P-856V-11.0.27",
          "P-13497V-21.3.14",
          "P-856V-8u451"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u451-perf",
            "P-856V-11.0.27",
            "P-13497V-21.3.14",
            "P-856V-8u451"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092096.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u451-perf",
            "P-856V-11.0.27",
            "P-13497V-21.3.14",
            "P-856V-8u451"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Sinelesmeas Sleysolu"
          ]
        }
      ],
      "cve": "CVE-2025-30762",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebLogic Server",
          "text": "37623763"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5242V-12.2.1.4.0",
          "P-5242V-14.1.2.0.0",
          "P-5242V-14.1.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-31650",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        },
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Graph Server and Client",
          "text": "37725009"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Office",
          "text": "37807584"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Managed File Transfer",
          "text": "37926891"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Agile PLM",
          "text": "37724985"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38082506"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Agile Engineering Data Management",
          "text": "37926895"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Document Management (Apache Tomcat)).   The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.  Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: Runtime Server (Apache Tomcat)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Managed File Transfer.  Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security (Apache Tomcat)).  Supported versions that are affected are 20.0.5, 21.0.4, 22.0.2, 23.0.2 and  24.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Xstore Office. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Graph Server and Client product of Oracle Graph Server and Client (component: Packaging (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Document Management (Apache Tomcat)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Database (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11560V-24.0.1",
          "P-11560V-23.0.2",
          "P-10198V-12.2.1.4.0",
          "P-11560V-21.0.4",
          "P-11560V-20.0.5",
          "P-4461V-9.3.6",
          "P-4436V-6.2.1",
          "P-11560V-22.0.2"
        ],
        "known_not_affected": [
          "P-14069V-24.4.1",
          "P-14069V-25.1.0",
          "P-5(Oracle Database)V-21.3-21.18",
          "P-5(Oracle Database)V-19.3-19.27"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4461V-9.3.6",
            "P-4436V-6.2.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092435.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10198V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11560V-24.0.1",
            "P-11560V-23.0.2",
            "P-11560V-21.0.4",
            "P-11560V-20.0.5",
            "P-11560V-22.0.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090426.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0",
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-11560V-24.0.1",
            "P-11560V-23.0.2",
            "P-10198V-12.2.1.4.0",
            "P-11560V-21.0.4",
            "P-11560V-20.0.5",
            "P-4461V-9.3.6",
            "P-4436V-6.2.1",
            "P-11560V-22.0.2"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0",
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        },
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-31651",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        },
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
          "text": "38092651"
        },
        {
          "system_name": "Oracle Bug ID of Graph Server and Client",
          "text": "37725009"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Office",
          "text": "37807584"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Managed File Transfer",
          "text": "37926891"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Agile PLM",
          "text": "37724985"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38082506"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Agile Engineering Data Management",
          "text": "37926895"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Document Management (Apache Tomcat)).   The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.  Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: Runtime Server (Apache Tomcat)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Managed File Transfer.  Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security (Apache Tomcat)).  Supported versions that are affected are 20.0.5, 21.0.4, 22.0.2, 23.0.2 and  24.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Xstore Office. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Graph Server and Client product of Oracle Graph Server and Client (component: Packaging (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Document Management (Apache Tomcat)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Database (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: Web UI (Apache Tomcat)).  Supported versions that are affected are 9.0.0-9.0.4. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Session Report Manager executes to compromise Oracle Communications Session Report Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 5.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11560V-24.0.1",
          "P-11560V-23.0.2",
          "P-10198V-12.2.1.4.0",
          "P-11560V-21.0.4",
          "P-10770V-9.0.0-9.0.4",
          "P-11560V-20.0.5",
          "P-4461V-9.3.6",
          "P-4436V-6.2.1",
          "P-11560V-22.0.2"
        ],
        "known_not_affected": [
          "P-14069V-24.4.1",
          "P-14069V-25.1.0",
          "P-5(Oracle Database)V-21.3-21.18",
          "P-5(Oracle Database)V-19.3-19.27"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4461V-9.3.6",
            "P-4436V-6.2.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092435.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10198V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11560V-24.0.1",
            "P-11560V-23.0.2",
            "P-11560V-21.0.4",
            "P-11560V-20.0.5",
            "P-11560V-22.0.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090426.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0",
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10770V-9.0.0-9.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092979.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-11560V-24.0.1",
            "P-11560V-23.0.2",
            "P-10198V-12.2.1.4.0",
            "P-11560V-21.0.4",
            "P-11560V-20.0.5",
            "P-4461V-9.3.6",
            "P-4436V-6.2.1",
            "P-11560V-22.0.2"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0",
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 5.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10770V-9.0.0-9.0.4"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        },
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-31672",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
          "text": "37921603"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Oracle Business Rules (Apache POI)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Process Management Suite accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5325V-12.2.1.4.0",
          "P-5325V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5325V-14.1.2.0.0",
            "P-5325V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5325V-14.1.2.0.0",
            "P-5325V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-31720",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37788792"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "37788790"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Automated Test Suite",
          "text": "37788789"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
          "text": "37788795"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "37788796"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
          "text": "37788797"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
          "text": "37788798"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Jenkins)).  Supported versions that are affected are 24.2.0-24.2.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: ATS Framework (Jenkins)).   The supported version that is affected is 24.3.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Network Slice Selection Function accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Jenkins)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Network Exposure Function accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (Jenkins)).  Supported versions that are affected are 24.2.0-24.2.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: ATS Framework (Jenkins)).   The supported version that is affected is 24.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Automated Test Suite accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: ATS Framework (Jenkins)).  Supported versions that are affected are 24.2.4 and  25.1.100. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Jenkins)).  Supported versions that are affected are 24.2.0 and  25.1.100. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Service Communication Proxy accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14121V-24.2.0-24.2.3",
          "P-14488V-24.2.4",
          "P-14117V-24.2.0",
          "P-14122V-24.2.0",
          "P-14130V-24.3.1",
          "P-14123V-25.1.100",
          "P-14117V-25.1.100",
          "P-14277V-24.2.0-24.2.6",
          "P-14123V-24.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.0-24.2.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092749.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-24.3.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092745.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-24.2.0-24.2.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092729.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14488V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092962.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14123V-25.1.100",
            "P-14123V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092746.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14117V-24.2.0",
            "P-14117V-25.1.100"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092730.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14121V-24.2.0-24.2.3",
            "P-14488V-24.2.4",
            "P-14117V-24.2.0",
            "P-14122V-24.2.0",
            "P-14130V-24.3.1",
            "P-14123V-25.1.100",
            "P-14117V-25.1.100",
            "P-14277V-24.2.0-24.2.6",
            "P-14123V-24.2.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-31721",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "37788792"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
          "text": "37788790"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Automated Test Suite",
          "text": "37788789"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
          "text": "37788795"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
          "text": "37788796"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
          "text": "37788797"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
          "text": "37788798"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: ATS Framework (Jenkins)).   The supported version that is affected is 24.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Automated Test Suite accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (Jenkins)).  Supported versions that are affected are 24.2.0-24.2.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Jenkins)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Network Exposure Function accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: ATS Framework (Jenkins)).   The supported version that is affected is 24.3.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Network Slice Selection Function accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Alarms, KPI, and Measurements (Jenkins)).  Supported versions that are affected are 24.2.0-24.2.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: ATS Framework (Jenkins)).  Supported versions that are affected are 24.2.4 and  25.1.100. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Jenkins)).  Supported versions that are affected are 24.2.0 and  25.1.100. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Service Communication Proxy accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14488V-24.2.4",
          "P-14121V-24.2.0-24.2.3",
          "P-14117V-24.2.0",
          "P-14122V-24.2.0",
          "P-14130V-24.3.1",
          "P-14123V-25.1.100",
          "P-14117V-25.1.100",
          "P-14277V-24.2.0-24.2.6",
          "P-14123V-24.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14488V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092962.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-24.2.0-24.2.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092729.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-24.3.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092745.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-24.2.0-24.2.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092749.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14123V-25.1.100",
            "P-14123V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092746.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14117V-24.2.0",
            "P-14117V-25.1.100"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092730.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14488V-24.2.4",
            "P-14121V-24.2.0-24.2.3",
            "P-14117V-24.2.0",
            "P-14122V-24.2.0",
            "P-14130V-24.3.1",
            "P-14123V-25.1.100",
            "P-14117V-25.1.100",
            "P-14277V-24.2.0-24.2.6",
            "P-14123V-24.2.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-32414",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "37806213"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "37718170"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "37950882"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (libxml2)).  Supported versions that are affected are Oracle Java SE: 8u451-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (libxml2)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server.  While the vulnerability is in Oracle HTTP Server, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data as well as  unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 7.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libxml2)).  Supported versions that are affected are 8.0.0-8.0.42. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u451-b50",
          "P-4627V-8.0.0-8.0.42",
          "P-1042(Core)V-12.2.1.4.0",
          "P-1042(Core)V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u451-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092096.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Core)V-12.2.1.4.0",
            "P-1042(Core)V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.42"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u451-b50"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1042(Core)V-12.2.1.4.0",
            "P-1042(Core)V-14.1.2.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4627V-8.0.0-8.0.42"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-32415",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle HTTP Server",
          "text": "37806213"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "37718170"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Workbench",
          "text": "37950882"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: JavaFX (libxml2)).  Supported versions that are affected are Oracle Java SE: 8u451-b50. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (libxml2)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server.  While the vulnerability is in Oracle HTTP Server, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server accessible data as well as  unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 7.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libxml2)).  Supported versions that are affected are 8.0.0-8.0.42. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u451-b50",
          "P-4627V-8.0.0-8.0.42",
          "P-1042(Core)V-12.2.1.4.0",
          "P-1042(Core)V-14.1.2.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u451-b50"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092096.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042(Core)V-12.2.1.4.0",
            "P-1042(Core)V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4627V-8.0.0-8.0.42"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u451-b50"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1042(Core)V-12.2.1.4.0",
            "P-1042(Core)V-14.1.2.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4627V-8.0.0-8.0.42"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-4598",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
          "text": "38138734"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (systemd)).   The supported version that is affected is 24.2.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Console executes to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Console accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14250V-24.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093901.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14250V-24.2.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-46701",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        },
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Graph Server and Client",
          "text": "37725009"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38082506"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Graph Server and Client product of Oracle Graph Server and Client (component: Packaging (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Database (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-14069V-24.4.1",
          "P-14069V-25.1.0",
          "P-5(Oracle Database)V-21.3-21.18",
          "P-5(Oracle Database)V-19.3-19.27"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0",
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0",
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        },
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-47287",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-14634V-24.11.0-25.4.0"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Autonomous Health Framework",
          "text": "37967879"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Autonomous Health Framework product of Oracle Autonomous Health Framework (component: Command Line Interface and SDK (Tornado)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-14634V-24.11.0-25.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14634V-24.11.0-25.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14634V-24.11.0-25.4.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-14634V-24.11.0-25.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-4802",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
          "text": "38138787"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (glibc)).   The supported version that is affected is 24.2.4. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Console executes to compromise Oracle Communications Cloud Native Core Console.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14250V-24.2.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-24.2.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093901.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14250V-24.2.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-48734",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Convergence",
          "text": "38012249"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
          "text": "38012304"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Healthcare Master Person Index",
          "text": "38012325"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
          "text": "38012246"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Data Integrator",
          "text": "38012268"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
          "text": "38012389"
        },
        {
          "system_name": "Oracle Bug ID of Oracle WebLogic Server",
          "text": "38012229"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Slice Selection Function",
          "text": "38012241"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Element Manager",
          "text": "38012263"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Service Backbone",
          "text": "38012384"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Application Testing Suite",
          "text": "38012164"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "38012283"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
          "text": "38012266"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Behavior Detection Platform",
          "text": "38152403"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
          "text": "38012259"
        },
        {
          "system_name": "Oracle Bug ID of Primavera Unifier",
          "text": "38012439"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
          "text": "38012239"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Identity Manager",
          "text": "38012338"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
          "text": "38012197"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Service Bus",
          "text": "38012392"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Network Integrity",
          "text": "38012256"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition",
          "text": "38012311"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications BRM - Elastic Charging Engine",
          "text": "38012234"
        },
        {
          "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
          "text": "38012453"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications MetaSolv Solution",
          "text": "38012254"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Retail Integration Bus",
          "text": "38012374"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
          "text": "38012181"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Apache Commons BeanUtils)).   The supported version that is affected is 24.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: Signaling (Apache Commons BeanUtils)).   The supported version that is affected is 24.3.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: ATS Framework (Apache Commons BeanUtils)).  Supported versions that are affected are 24.2.0 and  25.1.100. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: Configuration (Apache Commons BeanUtils)).  Supported versions that are affected are 3.0.3.3.0 and  3.0.3.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Convergence.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Convergence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications MetaSolv Solution product of Oracle Communications Applications (component: Infrastructure (Apache Commons BeanUtils)).   The supported version that is affected is 6.3.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications MetaSolv Solution.  Successful attacks of this vulnerability can result in takeover of Oracle Communications MetaSolv Solution. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Integrity product of Oracle Communications Applications (component: UI and Cartridges (Apache Commons BeanUtils)).  Supported versions that are affected are 7.3.6, 7.4.0 and  7.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Network Integrity.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Integrity. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security (Apache Commons BeanUtils)).  Supported versions that are affected are 7.4.0, 7.4.1 and  7.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Order and Service Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Third Party (Apache Commons BeanUtils)).  Supported versions that are affected are 9.0.0-9.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Element Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Third Party (Apache Commons BeanUtils)).  Supported versions that are affected are 7.4.0-7.4.2, 7.5.0, 7.5.1 and  7.6.0-7.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars (Apache Commons BeanUtils)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform (Apache Commons BeanUtils)).  Supported versions that are affected are 8.0.7.8, 8.0.8.6, 8.1.1.4 and  8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Installer (Apache Commons BeanUtils)).   The supported version that is affected is 8.1.2.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Platform (Apache Commons BeanUtils)).   The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Master Person Index product of Oracle HealthCare Applications (component: Master Index Data Manager (Apache Commons BeanUtils)).  Supported versions that are affected are 5.0.0.0-5.0.9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Healthcare Master Person Index.  Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Master Person Index. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core (Apache Commons BeanUtils)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: Installation (Apache Commons BeanUtils)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and  19.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: Installation (Apache Commons BeanUtils)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and  19.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Third Party (Apache Commons BeanUtils)).  Supported versions that are affected are 12.0.0.4-12.0.0.8, 15.0.0.0, 15.0.1.0 and  15.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console (Apache Commons BeanUtils)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Core (Apache Commons BeanUtils)).  Supported versions that are affected are 7.6.0.0.0 and  8.2.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Commons BeanUtils)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in takeover of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Load Testing for Web Apps (Apache Commons BeanUtils)).   The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Testing Suite.  Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Point of Sale (Apache Commons BeanUtils)).  Supported versions that are affected are 20.0.5, 21.0.4, 22.0.2, 23.0.2 and  24.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Platform (Apache Commons BeanUtils)).  Supported versions that are affected are 8.0.8.1, 8.1.2.8 and  8.1.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (Apache Commons BeanUtils)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (Apache Commons BeanUtils)).  Supported versions that are affected are 20.12.0-20.12.16, 21.12.0-21.12.17, 22.12.0-22.12.15, 23.12.0-23.12.14 and  24.12.0-24.12.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in takeover of Primavera Unifier. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Service Bus product of Oracle Fusion Middleware (component: Core (Apache Commons BeanUtils)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Service Bus. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10867V-15.0.3.1",
          "P-13789V-8.0.8",
          "P-5680V-8.0.8.6",
          "P-1807V-19.0.1",
          "P-14122V-24.2.0",
          "P-2267V-6.3.1",
          "P-8501V-3.0.3.4.0",
          "P-2270V-7.4.0",
          "P-2270V-7.4.1",
          "P-2025V-8.2.0.0.0",
          "P-4516V-7.5.0",
          "P-4516V-7.5.1",
          "P-11513V-20.0.5",
          "P-4491V-7.5.0",
          "P-9742V-15.1.0.0",
          "P-9190V-8.0.8.1",
          "P-5308V-12.2.1.4.0",
          "P-4491V-7.3.6",
          "P-5242V-12.2.1.4.0",
          "P-9742V-15.0.0.0",
          "P-1807V-14.1.3.2",
          "P-14276V-8.1.2.7",
          "P-4622V-13.3.0.1",
          "P-8575V-5.0.0.0-5.0.9.2",
          "P-11513V-22.0.2",
          "P-9190V-8.1.2.9",
          "P-9742V-12.0.0.4-12.0.0.8",
          "P-9190V-8.1.2.8",
          "P-11052V-9.0.0-9.0.4",
          "P-10354V-24.12.0-24.12.6",
          "P-5680V-8.1.2.5",
          "P-10867V-16.0.3",
          "P-10354V-23.12.0-23.12.14",
          "P-4516V-7.6.0-7.8.0",
          "P-1807V-15.0.3.1",
          "P-5242V-14.1.1.0.0",
          "P-10354V-21.12.0-21.12.17",
          "P-14130V-24.3.1",
          "P-4516V-7.4.0-7.4.2",
          "P-11513V-21.0.4",
          "P-2025V-7.6.0.0.0",
          "P-2270V-7.5.0",
          "P-1696V-12.2.1.4.0",
          "P-4491V-7.4.0",
          "P-14117V-24.2.0",
          "P-1980V-12.2.1.4.0",
          "P-11513V-24.0.1",
          "P-8501V-3.0.3.3.0",
          "P-11513V-23.0.2",
          "P-9742V-15.0.1.0",
          "P-10867V-19.0.1",
          "P-4647V-14.1.2.0.0",
          "P-10867V-14.1.3.2",
          "P-14117V-25.1.100",
          "P-1807V-16.0.3",
          "P-10354V-20.12.0-20.12.16",
          "P-10354V-22.12.0-22.12.15",
          "P-2196V-12.2.1.4.0",
          "P-4647V-12.2.1.4.0",
          "P-5680V-8.0.7.8",
          "P-5680V-8.1.1.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-24.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092977.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-24.3.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092745.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14117V-24.2.0",
            "P-14117V-25.1.100"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092730.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8501V-3.0.3.3.0",
            "P-8501V-3.0.3.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090954.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2267V-6.3.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090959.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4491V-7.4.0",
            "P-4491V-7.5.0",
            "P-4491V-7.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090957.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2270V-7.4.0",
            "P-2270V-7.4.1",
            "P-2270V-7.5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090964.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11052V-9.0.0-9.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092984.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.6.0-7.8.0",
            "P-4516V-7.4.0-7.4.2",
            "P-4516V-7.5.0",
            "P-4516V-7.5.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090956.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1980V-12.2.1.4.0",
            "P-5242V-14.1.1.0.0",
            "P-4647V-14.1.2.0.0",
            "P-2196V-12.2.1.4.0",
            "P-5308V-12.2.1.4.0",
            "P-4647V-12.2.1.4.0",
            "P-5242V-12.2.1.4.0",
            "P-1696V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.8.6",
            "P-5680V-8.0.7.8",
            "P-5680V-8.1.1.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092118.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14276V-8.1.2.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090085.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13789V-8.0.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090124.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8575V-5.0.0.0-5.0.9.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092620.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10867V-15.0.3.1",
            "P-1807V-19.0.1",
            "P-11513V-22.0.2",
            "P-10867V-14.1.3.2",
            "P-11513V-20.0.5",
            "P-1807V-16.0.3",
            "P-10867V-16.0.3",
            "P-1807V-15.0.3.1",
            "P-11513V-24.0.1",
            "P-11513V-23.0.2",
            "P-1807V-14.1.3.2",
            "P-10867V-19.0.1",
            "P-11513V-21.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090426.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9742V-15.1.0.0",
            "P-9742V-12.0.0.4-12.0.0.8",
            "P-9742V-15.0.0.0",
            "P-9742V-15.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093969.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-7.6.0.0.0",
            "P-2025V-8.2.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093264.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4622V-13.3.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3089549.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9190V-8.1.2.9",
            "P-9190V-8.0.8.1",
            "P-9190V-8.1.2.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090123.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10354V-20.12.0-20.12.16",
            "P-10354V-22.12.0-22.12.15",
            "P-10354V-23.12.0-23.12.14",
            "P-10354V-21.12.0-21.12.17",
            "P-10354V-24.12.0-24.12.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090883.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10867V-15.0.3.1",
            "P-13789V-8.0.8",
            "P-5680V-8.0.8.6",
            "P-1807V-19.0.1",
            "P-14122V-24.2.0",
            "P-2267V-6.3.1",
            "P-8501V-3.0.3.4.0",
            "P-2270V-7.4.0",
            "P-2270V-7.4.1",
            "P-2025V-8.2.0.0.0",
            "P-4516V-7.5.0",
            "P-4516V-7.5.1",
            "P-11513V-20.0.5",
            "P-4491V-7.5.0",
            "P-9742V-15.1.0.0",
            "P-9190V-8.0.8.1",
            "P-5308V-12.2.1.4.0",
            "P-4491V-7.3.6",
            "P-5242V-12.2.1.4.0",
            "P-9742V-15.0.0.0",
            "P-1807V-14.1.3.2",
            "P-14276V-8.1.2.7",
            "P-4622V-13.3.0.1",
            "P-8575V-5.0.0.0-5.0.9.2",
            "P-11513V-22.0.2",
            "P-9190V-8.1.2.9",
            "P-9742V-12.0.0.4-12.0.0.8",
            "P-9190V-8.1.2.8",
            "P-11052V-9.0.0-9.0.4",
            "P-10354V-24.12.0-24.12.6",
            "P-5680V-8.1.2.5",
            "P-10867V-16.0.3",
            "P-10354V-23.12.0-23.12.14",
            "P-4516V-7.6.0-7.8.0",
            "P-1807V-15.0.3.1",
            "P-5242V-14.1.1.0.0",
            "P-10354V-21.12.0-21.12.17",
            "P-14130V-24.3.1",
            "P-4516V-7.4.0-7.4.2",
            "P-11513V-21.0.4",
            "P-2025V-7.6.0.0.0",
            "P-2270V-7.5.0",
            "P-1696V-12.2.1.4.0",
            "P-4491V-7.4.0",
            "P-14117V-24.2.0",
            "P-1980V-12.2.1.4.0",
            "P-11513V-24.0.1",
            "P-8501V-3.0.3.3.0",
            "P-11513V-23.0.2",
            "P-9742V-15.0.1.0",
            "P-10867V-19.0.1",
            "P-4647V-14.1.2.0.0",
            "P-10867V-14.1.3.2",
            "P-14117V-25.1.100",
            "P-1807V-16.0.3",
            "P-10354V-20.12.0-20.12.16",
            "P-10354V-22.12.0-22.12.15",
            "P-2196V-12.2.1.4.0",
            "P-4647V-12.2.1.4.0",
            "P-5680V-8.0.7.8",
            "P-5680V-8.1.1.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-48976",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        },
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Graph Server and Client",
          "text": "37725009"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38082506"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Graph Server and Client product of Oracle Graph Server and Client (component: Packaging (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Database (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-14069V-24.4.1",
          "P-14069V-25.1.0",
          "P-5(Oracle Database)V-21.3-21.18",
          "P-5(Oracle Database)V-19.3-19.27"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0",
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0",
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        },
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-48988",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        },
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
          "text": "38092651"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38092652"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
          "text": "37926927"
        },
        {
          "system_name": "Oracle Bug ID of Graph Server and Client",
          "text": "37725009"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38082506"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38092647"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Element Manager",
          "text": "38092649"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Tomcat)).  Supported versions that are affected are 6.0.5-6.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: CMP (Apache Tomcat)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Policy Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Web UI (Apache Tomcat)).  Supported versions that are affected are 9.0.0-9.0.4. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Element Manager executes to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Element Manager. CVSS 3.1 Base Score 5.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: Web UI (Apache Tomcat)).  Supported versions that are affected are 9.0.0-9.0.4. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Session Report Manager executes to compromise Oracle Communications Session Report Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 5.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Apache Tomcat)).  Supported versions that are affected are 7.0.0.0.0 and  7.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Testing Accelerator. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Graph Server and Client product of Oracle Graph Server and Client (component: Packaging (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Database (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14597V-6.0.5-6.1.0",
          "P-13784V-7.0.0.0.0",
          "P-13784V-7.0.0.1.0",
          "P-11052V-9.0.0-9.0.4",
          "P-10900V-15.0.0.0",
          "P-10770V-9.0.0-9.0.4"
        ],
        "known_not_affected": [
          "P-14069V-24.4.1",
          "P-14069V-25.1.0",
          "P-5(Oracle Database)V-21.3-21.18",
          "P-5(Oracle Database)V-19.3-19.27"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5-6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092747.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11052V-9.0.0-9.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092984.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10770V-9.0.0-9.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092979.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13784V-7.0.0.0.0",
            "P-13784V-7.0.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093776.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0",
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.0.5-6.1.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13784V-7.0.0.0.0",
            "P-13784V-7.0.0.1.0",
            "P-10900V-15.0.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 5.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10770V-9.0.0-9.0.4",
            "P-11052V-9.0.0-9.0.4"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0",
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        },
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-49124",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        },
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
          "text": "38092651"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38092652"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
          "text": "37926927"
        },
        {
          "system_name": "Oracle Bug ID of Graph Server and Client",
          "text": "37725009"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38082506"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38092647"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Element Manager",
          "text": "38092649"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Apache Tomcat)).  Supported versions that are affected are 7.0.0.0.0 and  7.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Testing Accelerator. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Graph Server and Client product of Oracle Graph Server and Client (component: Packaging (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Database (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Tomcat)).  Supported versions that are affected are 6.0.5-6.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: Web UI (Apache Tomcat)).  Supported versions that are affected are 9.0.0-9.0.4. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Session Report Manager executes to compromise Oracle Communications Session Report Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 5.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Web UI (Apache Tomcat)).  Supported versions that are affected are 9.0.0-9.0.4. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Element Manager executes to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Element Manager. CVSS 3.1 Base Score 5.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: CMP (Apache Tomcat)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Policy Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13784V-7.0.0.0.0",
          "P-14597V-6.0.5-6.1.0",
          "P-13784V-7.0.0.1.0",
          "P-11052V-9.0.0-9.0.4",
          "P-10900V-15.0.0.0",
          "P-10770V-9.0.0-9.0.4"
        ],
        "known_not_affected": [
          "P-14069V-24.4.1",
          "P-14069V-25.1.0",
          "P-5(Oracle Database)V-21.3-21.18",
          "P-5(Oracle Database)V-19.3-19.27"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13784V-7.0.0.0.0",
            "P-13784V-7.0.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093776.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0",
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5-6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10770V-9.0.0-9.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092979.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11052V-9.0.0-9.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092984.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092747.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13784V-7.0.0.0.0",
            "P-13784V-7.0.0.1.0",
            "P-10900V-15.0.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0",
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.0.5-6.1.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 5.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10770V-9.0.0-9.0.4",
            "P-11052V-9.0.0-9.0.4"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        },
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-49125",
      "flags": [
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_cannot_be_controlled_by_adversary",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        },
        {
          "date": "2025-07-15T13:00:00-07:00",
          "label": "vulnerable_code_not_in_execute_path",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
          "text": "38092651"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
          "text": "38092652"
        },
        {
          "system_name": "Oracle Bug ID of Graph Server and Client",
          "text": "37725009"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Utilities Testing Accelerator",
          "text": "37926927"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "38082506"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Policy Management",
          "text": "38092647"
        },
        {
          "system_name": "Oracle Bug ID of Oracle Communications Element Manager",
          "text": "38092649"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Graph Server and Client product of Oracle Graph Server and Client (component: Packaging (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Testing Accelerator product of Oracle Utilities Applications (component: Tools (Apache Tomcat)).  Supported versions that are affected are 7.0.0.0.0 and  7.0.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Testing Accelerator.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Testing Accelerator. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Database (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: CMP (Apache Tomcat)).   The supported version that is affected is 15.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Policy Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Web UI (Apache Tomcat)).  Supported versions that are affected are 9.0.0-9.0.4. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Element Manager executes to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Element Manager. CVSS 3.1 Base Score 5.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: Web UI (Apache Tomcat)).  Supported versions that are affected are 9.0.0-9.0.4. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Session Report Manager executes to compromise Oracle Communications Session Report Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 5.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Tomcat)).  Supported versions that are affected are 6.0.5-6.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13784V-7.0.0.0.0",
          "P-14597V-6.0.5-6.1.0",
          "P-13784V-7.0.0.1.0",
          "P-11052V-9.0.0-9.0.4",
          "P-10900V-15.0.0.0",
          "P-10770V-9.0.0-9.0.4"
        ],
        "known_not_affected": [
          "P-14069V-24.4.1",
          "P-14069V-25.1.0",
          "P-5(Oracle Database)V-21.3-21.18",
          "P-5(Oracle Database)V-19.3-19.27"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0",
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13784V-7.0.0.0.0",
            "P-13784V-7.0.0.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093776.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-15.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092747.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11052V-9.0.0-9.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092984.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10770V-9.0.0-9.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092979.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14597V-6.0.5-6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090932.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0.0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0",
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13784V-7.0.0.0.0",
            "P-13784V-7.0.0.1.0",
            "P-10900V-15.0.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 5.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10770V-9.0.0-9.0.4",
            "P-11052V-9.0.0-9.0.4"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14597V-6.0.5-6.1.0"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
          "product_ids": [
            "P-14069V-24.4.1",
            "P-14069V-25.1.0"
          ]
        },
        {
          "category": "impact",
          "date": "2025-07-15T13:00:00-07:00",
          "details": "The affected code is not reachable through the execution of the code, including non-anticipated states of the product. Components that are neither used nor executed by the product.",
          "product_ids": [
            "P-5(Oracle Database)V-19.3-19.27",
            "P-5(Oracle Database)V-21.3-21.18"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-49146",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Enterprise Data Quality",
          "text": "38084275"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: Core (PostgreSQL JDBC Driver)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Enterprise Data Quality.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Enterprise Data Quality accessible data as well as  unauthorized update, insert or delete access to some of Oracle Enterprise Data Quality accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9464V-14.1.2.0.0",
          "P-9464V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9464V-12.2.1.4.0",
            "P-9464V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9464V-12.2.1.4.0",
            "P-9464V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Martin van Wingerden"
          ]
        },
        {
          "names": [
            "Violeta Georgieva"
          ],
          "organization": "Broadcom"
        }
      ],
      "cve": "CVE-2025-50059",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "37635814"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking).  Supported versions that are affected are Oracle Java SE: 8u451-perf, 11.0.27, 17.0.15, 21.0.7, 24.0.1; Oracle GraalVM for JDK: 17.0.15, 21.0.7 and  24.0.1; Oracle GraalVM Enterprise Edition: 21.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  While the vulnerability is in Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 8.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-17.0.15",
          "P-856V-21.0.7",
          "P-856V-24.0.1",
          "P-856V-8u451-perf",
          "P-13497V-21.0.7",
          "P-856V-11.0.27",
          "P-13497V-21.3.14",
          "P-13497V-17.0.15",
          "P-13497V-24.0.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-17.0.15",
            "P-856V-21.0.7",
            "P-856V-24.0.1",
            "P-856V-8u451-perf",
            "P-13497V-21.0.7",
            "P-856V-11.0.27",
            "P-13497V-21.3.14",
            "P-13497V-17.0.15",
            "P-13497V-24.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092096.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.6,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-856V-17.0.15",
            "P-856V-21.0.7",
            "P-856V-24.0.1",
            "P-856V-8u451-perf",
            "P-13497V-21.0.7",
            "P-856V-11.0.27",
            "P-13497V-21.3.14",
            "P-13497V-17.0.15",
            "P-13497V-24.0.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50060",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle BI Publisher",
          "text": "37679636"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server).  Supported versions that are affected are 7.6.0.0.0, 8.2.0.0.0 and  12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1479V-8.2.0.0.0",
          "P-1479V-12.2.1.4.0",
          "P-1479V-7.6.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1479V-7.6.0.0.0",
            "P-1479V-8.2.0.0.0",
            "P-1479V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093264.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1479V-7.6.0.0.0",
            "P-1479V-8.2.0.0.0",
            "P-1479V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Felipe Solferini"
          ],
          "organization": "Lares Consulting"
        },
        {
          "names": [
            "Luke Turvey"
          ],
          "organization": "Lares Consulting"
        }
      ],
      "cve": "CVE-2025-50061",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Primavera P6 Enterprise Project Portfolio Management",
          "text": "37694237"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access).  Supported versions that are affected are 20.12.0-20.12.21, 21.12.0-21.12.21, 22.12.0-22.12.19, 23.12.0-23.12.13 and  24.12.0-24.12.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5579V-23.12.0-23.12.13",
          "P-5579V-24.12.0-24.12.4",
          "P-5579V-22.12.0-22.12.19",
          "P-5579V-20.12.0-20.12.21",
          "P-5579V-21.12.0-21.12.21"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5579V-22.12.0-22.12.19",
            "P-5579V-21.12.0-21.12.21",
            "P-5579V-23.12.0-23.12.13",
            "P-5579V-24.12.0-24.12.4",
            "P-5579V-20.12.0-20.12.21"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3090883.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5579V-22.12.0-22.12.19",
            "P-5579V-21.12.0-21.12.21",
            "P-5579V-23.12.0-23.12.13",
            "P-5579V-24.12.0-24.12.4",
            "P-5579V-20.12.0-20.12.21"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50062",
      "ids": [
        {
          "system_name": "Oracle Bug ID of PeopleSoft Enterprise HCM Global Payroll Core",
          "text": "37694907"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payroll for Core).  Supported versions that are affected are 9.2.51 and  9.2.52. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Global Payroll Core.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Global Payroll Core accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise HCM Global Payroll Core accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5055V-9.2.51",
          "P-5055V-9.2.52"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5055V-9.2.51",
            "P-5055V-9.2.52"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092433.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5055V-9.2.51",
            "P-5055V-9.2.52"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Dong-uk Kim"
          ]
        }
      ],
      "cve": "CVE-2025-50063",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "37730094"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Java SE (component: Install).   The supported version that is affected is Oracle Java SE: 8u451. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Java SE executes to compromise Oracle Java SE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Java SE.  Note: Applies to installation process on client deployment of Java. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-8u451"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-8u451"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092096.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-856V-8u451"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Raman Gautam"
          ]
        }
      ],
      "cve": "CVE-2025-50064",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebLogic Server",
          "text": "37768353"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5242V-12.2.1.4.0",
          "P-5242V-14.1.2.0.0",
          "P-5242V-14.1.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50065",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle GraalVM for JDK",
          "text": "37912932"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Native Image).   The supported version that is affected is Oracle GraalVM for JDK: 24.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM for JDK.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GraalVM for JDK. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13497V-24.0.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13497V-24.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092096.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-13497V-24.0.1"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Emad Al-Mousa"
          ]
        }
      ],
      "cve": "CVE-2025-50066",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "37840189"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Database Materialized View component of Oracle Database Server.  Supported versions that are affected are 19.3-19.27, 21.3-21.18 and  23.4-23.8. Easily exploitable vulnerability allows high privileged attacker having Execute on DBMS_REDEFINITION privilege with network access via Oracle Net to compromise Oracle Database Materialized View.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Database Materialized View accessible data. CVSS 3.1 Base Score 2.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(Oracle Database Materialized View)V-19.3-19.27",
          "P-5(Oracle Database Materialized View)V-23.4-23.8",
          "P-5(Oracle Database Materialized View)V-21.3-21.18"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Oracle Database Materialized View)V-19.3-19.27",
            "P-5(Oracle Database Materialized View)V-21.3-21.18",
            "P-5(Oracle Database Materialized View)V-23.4-23.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Oracle Database Materialized View)V-19.3-19.27",
            "P-5(Oracle Database Materialized View)V-21.3-21.18",
            "P-5(Oracle Database Materialized View)V-23.4-23.8"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Kanika Jalal"
          ]
        },
        {
          "names": [
            "Ved Prabhu"
          ]
        }
      ],
      "cve": "CVE-2025-50067",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Application Express",
          "text": "37898763"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Application Express product of Oracle APEX (component: Strategic Planner Starter App).  Supported versions that are affected are 24.2.4 and  24.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Express.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Application Express. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1348V-24.2.4",
          "P-1348V-24.2.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1348V-24.2.4",
            "P-1348V-24.2.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.0,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-1348V-24.2.4",
            "P-1348V-24.2.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50068",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Cluster",
          "text": "37909595"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8479V-8.4.0-8.4.5",
          "P-8479V-8.0.0-8.0.42",
          "P-8479V-9.0.0-9.3.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8479V-8.4.0-8.4.5",
            "P-8479V-8.0.0-8.0.42",
            "P-8479V-9.0.0-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8479V-8.4.0-8.4.5",
            "P-8479V-8.0.0-8.0.42",
            "P-8479V-9.0.0-9.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50069",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Database Server",
          "text": "37929314"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 19.3-19.27 and  21.3-21.18. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM.  While the vulnerability is in Java VM, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Java VM accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(Java VM)V-19.3-19.27",
          "P-5(Java VM)V-21.3-21.18"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Java VM)V-19.3-19.27",
            "P-5(Java VM)V-21.3-21.18"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Java VM)V-19.3-19.27",
            "P-5(Java VM)V-21.3-21.18"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Alexander Kornbrust"
          ],
          "organization": "Red Database Security"
        }
      ],
      "cve": "CVE-2025-50070",
      "ids": [
        {
          "system_name": "Oracle Bug ID of JDBC",
          "text": "37945281"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JDBC component of Oracle Database Server.  Supported versions that are affected are 23.4-23.8. Difficult to exploit vulnerability allows low privileged attacker having Authenticated OS User privilege with logon to the infrastructure where JDBC executes to compromise JDBC.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JDBC, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all JDBC accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-972V-23.4-23.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-972V-23.4-23.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3086459.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-972V-23.4-23.8"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50071",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Applications Framework",
          "text": "37966212"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities).  Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.  While the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data as well as  unauthorized read access to a subset of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1472V-12.2.3-12.2.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1472V-12.2.3-12.2.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1472V-12.2.3-12.2.14"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "IuHrm"
          ]
        }
      ],
      "cve": "CVE-2025-50072",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebLogic Server",
          "text": "37614926"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 4.0 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5242V-12.2.1.4.0",
          "P-5242V-14.1.2.0.0",
          "P-5242V-14.1.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.0,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50073",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle WebLogic Server",
          "text": "37670826"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5242V-12.2.1.4.0",
          "P-5242V-14.1.2.0.0",
          "P-5242V-14.1.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092885.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5242V-14.1.1.0.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.2.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50076",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "27899773"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.0-8.0.25. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: DML)V-8.0.0-8.0.25"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: DML)V-8.0.0-8.0.25"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: DML)V-8.0.0-8.0.25"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50077",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "31360522"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Cluster",
          "text": "38063122"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.6.0-7.6.34, 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8479V-8.4.0-8.4.5",
          "P-8478(InnoDB)V-9.0.0-9.3.0",
          "P-8479V-8.0.0-8.0.42",
          "P-8479V-9.0.0-9.3.0",
          "P-8479V-7.6.0-7.6.34",
          "P-8478(InnoDB)V-8.4.0-8.4.5",
          "P-8478(InnoDB)V-8.0.0-8.0.42"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8479V-8.4.0-8.4.5",
            "P-8478(InnoDB)V-9.0.0-9.3.0",
            "P-8479V-8.0.0-8.0.42",
            "P-8479V-9.0.0-9.3.0",
            "P-8479V-7.6.0-7.6.34",
            "P-8478(InnoDB)V-8.4.0-8.4.5",
            "P-8478(InnoDB)V-8.0.0-8.0.42"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8479V-8.4.0-8.4.5",
            "P-8478(InnoDB)V-9.0.0-9.3.0",
            "P-8479V-8.0.0-8.0.42",
            "P-8479V-9.0.0-9.3.0",
            "P-8479V-7.6.0-7.6.34",
            "P-8478(InnoDB)V-8.4.0-8.4.5",
            "P-8478(InnoDB)V-8.0.0-8.0.42"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50078",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "35625769"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: DML)V-8.4.0-8.4.5",
          "P-8478(Server: DML)V-9.0.0-9.3.0",
          "P-8478(Server: DML)V-8.0.0-8.0.42"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: DML)V-8.4.0-8.4.5",
            "P-8478(Server: DML)V-8.0.0-8.0.42",
            "P-8478(Server: DML)V-9.0.0-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: DML)V-8.4.0-8.4.5",
            "P-8478(Server: DML)V-8.0.0-8.0.42",
            "P-8478(Server: DML)V-9.0.0-9.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50079",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "36314993"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
          "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
          "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50080",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "36402968"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Stored Procedure)V-8.0.0-8.0.42",
          "P-8478(Server: Stored Procedure)V-9.0.0-9.3.0",
          "P-8478(Server: Stored Procedure)V-8.4.0-8.4.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Stored Procedure)V-8.0.0-8.0.42",
            "P-8478(Server: Stored Procedure)V-9.0.0-9.3.0",
            "P-8478(Server: Stored Procedure)V-8.4.0-8.4.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Stored Procedure)V-8.0.0-8.0.42",
            "P-8478(Server: Stored Procedure)V-9.0.0-9.3.0",
            "P-8478(Server: Stored Procedure)V-8.4.0-8.4.5"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Matthieu Denais"
          ]
        }
      ],
      "cve": "CVE-2025-50081",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Cluster",
          "text": "38066040"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Client",
          "text": "36416568"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Client.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Client accessible data as well as  unauthorized read access to a subset of MySQL Client accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.6.0-7.6.34, 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Cluster accessible data as well as  unauthorized read access to a subset of MySQL Cluster accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8479V-8.4.0-8.4.5",
          "P-8478(Client: mysqldump)V-8.4.0-8.4.5",
          "P-8479V-8.0.0-8.0.42",
          "P-8479V-9.0.0-9.3.0",
          "P-8478(Client: mysqldump)V-8.0.0-8.0.42",
          "P-8478(Client: mysqldump)V-9.0.0-9.3.0",
          "P-8479V-7.6.0-7.6.34"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8479V-8.4.0-8.4.5",
            "P-8478(Client: mysqldump)V-8.4.0-8.4.5",
            "P-8479V-8.0.0-8.0.42",
            "P-8479V-9.0.0-9.3.0",
            "P-8478(Client: mysqldump)V-8.0.0-8.0.42",
            "P-8478(Client: mysqldump)V-9.0.0-9.3.0",
            "P-8479V-7.6.0-7.6.34"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.1,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8479V-8.4.0-8.4.5",
            "P-8478(Client: mysqldump)V-8.4.0-8.4.5",
            "P-8479V-8.0.0-8.0.42",
            "P-8479V-9.0.0-9.3.0",
            "P-8478(Client: mysqldump)V-8.0.0-8.0.42",
            "P-8478(Client: mysqldump)V-9.0.0-9.3.0",
            "P-8479V-7.6.0-7.6.34"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Jie Liang"
          ],
          "organization": "WingTecher Lab"
        },
        {
          "names": [
            "Jingzhou Fu"
          ],
          "organization": "WingTecher Lab"
        },
        {
          "names": [
            "Zhiyong Wu"
          ],
          "organization": "WingTecher Lab"
        }
      ],
      "cve": "CVE-2025-50082",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "36421710"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
          "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
          "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Jie Liang"
          ],
          "organization": "WingTecher Lab"
        },
        {
          "names": [
            "Jingzhou Fu"
          ],
          "organization": "WingTecher Lab"
        },
        {
          "names": [
            "Zhiyong Wu"
          ],
          "organization": "WingTecher Lab"
        }
      ],
      "cve": "CVE-2025-50083",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "36421727"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
          "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
          "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50084",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "36464947"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
          "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
          "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50085",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "36682518"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(InnoDB)V-8.4.0-8.4.5",
          "P-8478(InnoDB)V-9.0.0-9.3.0",
          "P-8478(InnoDB)V-8.0.0-8.0.42"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(InnoDB)V-9.0.0-9.3.0",
            "P-8478(InnoDB)V-8.4.0-8.4.5",
            "P-8478(InnoDB)V-8.0.0-8.0.42"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(InnoDB)V-9.0.0-9.3.0",
            "P-8478(InnoDB)V-8.4.0-8.4.5",
            "P-8478(InnoDB)V-8.0.0-8.0.42"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50086",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "36835161"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Components Services)V-8.4.0-8.4.5",
          "P-8478(Server: Components Services)V-9.0.0-9.3.0",
          "P-8478(Server: Components Services)V-8.0.0-8.0.42"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Components Services)V-8.4.0-8.4.5",
            "P-8478(Server: Components Services)V-8.0.0-8.0.42",
            "P-8478(Server: Components Services)V-9.0.0-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Components Services)V-8.4.0-8.4.5",
            "P-8478(Server: Components Services)V-8.0.0-8.0.42",
            "P-8478(Server: Components Services)V-9.0.0-9.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50087",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Cluster",
          "text": "38063286"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37117875"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Server accessible data. CVSS 3.1 Base Score 4.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.6.0-7.6.34, 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Cluster accessible data. CVSS 3.1 Base Score 4.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8479V-8.4.0-8.4.5",
          "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
          "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
          "P-8479V-8.0.0-8.0.42",
          "P-8478(Server: Optimizer)V-9.0.0-9.3.0",
          "P-8479V-9.0.0-9.3.0",
          "P-8479V-7.6.0-7.6.34"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8479V-8.4.0-8.4.5",
            "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
            "P-8479V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0",
            "P-8479V-9.0.0-9.3.0",
            "P-8479V-7.6.0-7.6.34"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8479V-8.4.0-8.4.5",
            "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
            "P-8479V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0",
            "P-8479V-9.0.0-9.3.0",
            "P-8479V-7.6.0-7.6.34"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50088",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37292404"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and  9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(InnoDB)V-8.0.0-8.0.41",
          "P-8478(InnoDB)V-9.0.0-9.2.0",
          "P-8478(InnoDB)V-8.4.0-8.4.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(InnoDB)V-9.0.0-9.2.0",
            "P-8478(InnoDB)V-8.0.0-8.0.41",
            "P-8478(InnoDB)V-8.4.0-8.4.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(InnoDB)V-9.0.0-9.2.0",
            "P-8478(InnoDB)V-8.0.0-8.0.41",
            "P-8478(InnoDB)V-8.4.0-8.4.4"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "yx"
          ]
        }
      ],
      "cve": "CVE-2025-50089",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37321762"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 9.0.0-9.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-9.0.0-9.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-9.0.0-9.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-9.0.0-9.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50090",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Applications Framework",
          "text": "37330526"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization).  Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data as well as  unauthorized read access to a subset of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1472V-12.2.3-12.2.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1472V-12.2.3-12.2.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1472V-12.2.3-12.2.14"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50091",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37436220"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
          "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
          "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50092",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37478594"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(InnoDB)V-8.4.0-8.4.5",
          "P-8478(InnoDB)V-9.0.0-9.3.0",
          "P-8478(InnoDB)V-8.0.0-8.0.42"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(InnoDB)V-9.0.0-9.3.0",
            "P-8478(InnoDB)V-8.4.0-8.4.5",
            "P-8478(InnoDB)V-8.0.0-8.0.42"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(InnoDB)V-9.0.0-9.3.0",
            "P-8478(InnoDB)V-8.4.0-8.4.5",
            "P-8478(InnoDB)V-8.0.0-8.0.42"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50093",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37489167"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: DDL)V-9.0.0-9.3.0",
          "P-8478(Server: DDL)V-8.4.0-8.4.5",
          "P-8478(Server: DDL)V-8.0.0-8.0.42"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: DDL)V-9.0.0-9.3.0",
            "P-8478(Server: DDL)V-8.0.0-8.0.42",
            "P-8478(Server: DDL)V-8.4.0-8.4.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: DDL)V-9.0.0-9.3.0",
            "P-8478(Server: DDL)V-8.0.0-8.0.42",
            "P-8478(Server: DDL)V-8.4.0-8.4.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50094",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37534068"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL).  Supported versions that are affected are 8.0.42, 8.4.5 and  9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: DDL)V-9.3.0",
          "P-8478(Server: DDL)V-8.0.42",
          "P-8478(Server: DDL)V-8.4.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: DDL)V-8.0.42",
            "P-8478(Server: DDL)V-9.3.0",
            "P-8478(Server: DDL)V-8.4.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: DDL)V-8.0.42",
            "P-8478(Server: DDL)V-9.3.0",
            "P-8478(Server: DDL)V-8.4.5"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "yx"
          ]
        }
      ],
      "cve": "CVE-2025-50095",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37587388"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50096",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37621360"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(InnoDB)V-8.4.0-8.4.5",
          "P-8478(InnoDB)V-9.0.0-9.3.0",
          "P-8478(InnoDB)V-8.0.0-8.0.42"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(InnoDB)V-9.0.0-9.3.0",
            "P-8478(InnoDB)V-8.4.0-8.4.5",
            "P-8478(InnoDB)V-8.0.0-8.0.42"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(InnoDB)V-9.0.0-9.3.0",
            "P-8478(InnoDB)V-8.4.0-8.4.5",
            "P-8478(InnoDB)V-8.0.0-8.0.42"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50097",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37655299"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Security: Encryption)V-8.0.0-8.0.42",
          "P-8478(Server: Security: Encryption)V-8.4.0-8.4.5",
          "P-8478(Server: Security: Encryption)V-9.0.0-9.3.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Security: Encryption)V-8.0.0-8.0.42",
            "P-8478(Server: Security: Encryption)V-8.4.0-8.4.5",
            "P-8478(Server: Security: Encryption)V-9.0.0-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Security: Encryption)V-8.0.0-8.0.42",
            "P-8478(Server: Security: Encryption)V-8.4.0-8.4.5",
            "P-8478(Server: Security: Encryption)V-9.0.0-9.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50098",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37671751"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
          "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
          "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50099",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37726881"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(InnoDB)V-8.4.0-8.4.5",
          "P-8478(InnoDB)V-9.0.0-9.3.0",
          "P-8478(InnoDB)V-8.0.0-8.0.42"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(InnoDB)V-9.0.0-9.3.0",
            "P-8478(InnoDB)V-8.4.0-8.4.5",
            "P-8478(InnoDB)V-8.0.0-8.0.42"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(InnoDB)V-9.0.0-9.3.0",
            "P-8478(InnoDB)V-8.4.0-8.4.5",
            "P-8478(InnoDB)V-8.0.0-8.0.42"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50100",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37755594"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Thread Pooling).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Thread Pooling)V-9.0.0-9.3.0",
          "P-8478(Server: Thread Pooling)V-8.4.0-8.4.5",
          "P-8478(Server: Thread Pooling)V-8.0.0-8.0.42"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Thread Pooling)V-8.4.0-8.4.5",
            "P-8478(Server: Thread Pooling)V-9.0.0-9.3.0",
            "P-8478(Server: Thread Pooling)V-8.0.0-8.0.42"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.2,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Thread Pooling)V-8.4.0-8.4.5",
            "P-8478(Server: Thread Pooling)V-9.0.0-9.3.0",
            "P-8478(Server: Thread Pooling)V-8.0.0-8.0.42"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "yx"
          ]
        }
      ],
      "cve": "CVE-2025-50101",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37832605"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
          "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
          "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50102",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37915445"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
          "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
          "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-8.0.0-8.0.42",
            "P-8478(Server: Optimizer)V-8.4.0-8.4.5",
            "P-8478(Server: Optimizer)V-9.0.0-9.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50103",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37983282"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth).  Supported versions that are affected are 9.0.0-9.3.0. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Security: LDAP Auth)V-9.0.0-9.3.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Security: LDAP Auth)V-9.0.0-9.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Security: LDAP Auth)V-9.0.0-9.3.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50104",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37986380"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: DDL)V-9.0.0-9.3.0",
          "P-8478(Server: DDL)V-8.4.0-8.4.5",
          "P-8478(Server: DDL)V-8.0.0-8.0.42"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: DDL)V-9.0.0-9.3.0",
            "P-8478(Server: DDL)V-8.0.0-8.0.42",
            "P-8478(Server: DDL)V-8.4.0-8.4.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: DDL)V-9.0.0-9.3.0",
            "P-8478(Server: DDL)V-8.0.0-8.0.42",
            "P-8478(Server: DDL)V-8.4.0-8.4.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50105",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Universal Work Queue",
          "text": "38049705"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administration).  Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Universal Work Queue accessible data as well as  unauthorized access to critical data or complete access to all Oracle Universal Work Queue accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-778V-12.2.3-12.2.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-778V-12.2.3-12.2.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-778V-12.2.3-12.2.14"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50106",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Java SE",
          "text": "38101462"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D).  Supported versions that are affected are Oracle Java SE: 8u451, 8u451-perf, 11.0.27, 17.0.15, 21.0.7, 24.0.1; Oracle GraalVM for JDK: 17.0.15, 21.0.7 and  24.0.1; Oracle GraalVM Enterprise Edition: 21.3.14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.  Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-17.0.15",
          "P-856V-21.0.7",
          "P-856V-24.0.1",
          "P-856V-8u451-perf",
          "P-13497V-21.0.7",
          "P-856V-11.0.27",
          "P-13497V-21.3.14",
          "P-13497V-17.0.15",
          "P-13497V-24.0.1",
          "P-856V-8u451"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-17.0.15",
            "P-856V-21.0.7",
            "P-856V-24.0.1",
            "P-856V-8u451-perf",
            "P-13497V-21.0.7",
            "P-856V-11.0.27",
            "P-13497V-21.3.14",
            "P-13497V-17.0.15",
            "P-13497V-24.0.1",
            "P-856V-8u451"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092096.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-856V-17.0.15",
            "P-856V-21.0.7",
            "P-856V-24.0.1",
            "P-856V-8u451-perf",
            "P-13497V-21.0.7",
            "P-856V-11.0.27",
            "P-13497V-21.3.14",
            "P-13497V-17.0.15",
            "P-13497V-24.0.1",
            "P-856V-8u451"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-50107",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Universal Work Queue",
          "text": "36586302"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Request handling).  Supported versions that are affected are 12.2.5-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Universal Work Queue.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Universal Work Queue, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Universal Work Queue accessible data as well as  unauthorized read access to a subset of Oracle Universal Work Queue accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-778V-12.2.5-12.2.14"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-778V-12.2.5-12.2.14"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-778V-12.2.5-12.2.14"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Abdullah Alsuwailem"
          ],
          "organization": "Haboob Cyber Security Services"
        }
      ],
      "cve": "CVE-2025-50108",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Hyperion Financial Reporting",
          "text": "37821279"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Workspace).   The supported version that is affected is 11.2.20.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Reporting.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Reporting, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hyperion Financial Reporting accessible data as well as  unauthorized read access to a subset of Oracle Hyperion Financial Reporting accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8776V-11.2.20.0.000"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8776V-11.2.20.0.000"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=2775466.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8776V-11.2.20.0.000"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Weiheng Qiu"
          ],
          "organization": "Vanderbilt University"
        }
      ],
      "cve": "CVE-2025-53023",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Cluster",
          "text": "38063175"
        },
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37829550"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are 8.0.0-8.0.42. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.6.0-7.6.34 and  8.0.0-8.0.42. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Replication)V-8.0.0-8.0.42",
          "P-8479V-7.6.0-7.6.34",
          "P-8479V-8.0.0-8.0.42"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Replication)V-8.0.0-8.0.42",
            "P-8479V-8.0.0-8.0.42",
            "P-8479V-7.6.0-7.6.34"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Replication)V-8.0.0-8.0.42",
            "P-8479V-8.0.0-8.0.42",
            "P-8479V-7.6.0-7.6.34"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Prison Break (Gangmin Kim, Sangbin Kim, Hanseo Kim, Sangwon Oh, Sanghoon Lee, Wonjoon Hwang) working with Trend Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2025-53024",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "37968727"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.1.10. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.1.10"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093413.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.1.10"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Viettel Cyber Security working with Trend Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2025-53025",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "37989378"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.1.10. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.1.10"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093413.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.0,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.1.10"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Viettel Cyber Security working with Trend Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2025-53026",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "37989405"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.1.10. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.1.10"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093413.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.0,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.1.10"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Do Manh Dung and Nguyen Dang Nguyen"
          ],
          "organization": "STAR Labs SG Pte. Ltd. working with Trend Zero Day Initiative"
        }
      ],
      "cve": "CVE-2025-53027",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38024298"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.1.10. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.1.10"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093413.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.1.10"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Viettel Cyber Security working with Trend Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2025-53028",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38024369"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.1.10. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.1.10"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093413.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.1.10"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53029",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38031975"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.1.10. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 2.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.1.10"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093413.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.3,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.1.10"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53030",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
          "text": "38032327"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.1.10. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-7.1.10"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-7.1.10"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3093413.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.0,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8370V-7.1.10"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-53031",
      "ids": [
        {
          "system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
          "text": "37954017"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform).  Supported versions that are affected are 8.0.7.8, 8.0.8.5, 8.0.8.6, 8.1.1.4 and  8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5680V-8.1.2.5",
          "P-5680V-8.0.7.8",
          "P-5680V-8.0.8.6",
          "P-5680V-8.0.8.5",
          "P-5680V-8.1.1.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.8.6",
            "P-5680V-8.0.8.5",
            "P-5680V-8.0.7.8",
            "P-5680V-8.1.1.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3092118.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5680V-8.1.2.5",
            "P-5680V-8.0.8.6",
            "P-5680V-8.0.8.5",
            "P-5680V-8.0.7.8",
            "P-5680V-8.1.1.4"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "yx"
          ]
        }
      ],
      "cve": "CVE-2025-53032",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "37847161"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 9.0.0-9.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Optimizer)V-9.0.0-9.1.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Optimizer)V-9.0.0-9.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Optimizer)V-9.0.0-9.1.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2025-5399",
      "ids": [
        {
          "system_name": "Oracle Bug ID of MySQL Server",
          "text": "38042095"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging (curl)).  Supported versions that are affected are 8.0.0-8.0.42, 8.4.0-8.4.5 and  9.0.0-9.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478(Server: Packaging)V-8.4.0-8.4.5",
          "P-8478(Server: Packaging)V-9.0.0-9.3.0",
          "P-8478(Server: Packaging)V-8.0.0-8.0.42"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478(Server: Packaging)V-9.0.0-9.3.0",
            "P-8478(Server: Packaging)V-8.4.0-8.4.5",
            "P-8478(Server: Packaging)V-8.0.0-8.0.42"
          ],
          "url": "https://support.oracle.com/rs?type=doc&amp;id=3091981.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-8478(Server: Packaging)V-9.0.0-9.3.0",
            "P-8478(Server: Packaging)V-8.4.0-8.4.5",
            "P-8478(Server: Packaging)V-8.0.0-8.0.42"
          ]
        }
      ]
    }
  ]
}