cpuapr2022csaf

CRITICAL CVSS 9.8 csaf_oracle
Description

No description available.

Timeline
Published
2022-04-19 13:00 UTC
Last Modified
2024-09-20
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "document": {
    "category": "Oracle Critical Patch Update Advisory",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "name": "Oracle",
      "namespace": "https://www.oracle.com"
    },
    "references": [
      {
        "summary": "URL to html version of Advisory",
        "url": "https://www.oracle.com/security-alerts/cpuapr2022.html"
      },
      {
        "category": "self",
        "summary": "URL to CSAF version of Advisory",
        "url": "https://www.oracle.com/docs/tech/security-alerts/cpuapr2022csaf.json"
      }
    ],
    "title": "Oracle Critical Patch Update Advisory - April 2022 - Oracle CSAF",
    "tracking": {
      "current_release_date": "2024-09-20T12:00:00-07:00",
      "id": "CPUApr2022csaf",
      "initial_release_date": "2022-04-19T13:00:00-07:00",
      "revision_history": [
        {
          "date": "2022-04-19T13:00:00-07:00",
          "number": "1",
          "summary": "Initial Release"
        },
        {
          "date": "2022-04-21T12:40:00-07:00",
          "number": "2",
          "summary": "Updated the affected versions for CVE-2022-21449"
        },
        {
          "date": "2022-04-29T12:40:00-07:00",
          "number": "3",
          "summary": "Updated EM Ops Center additional CVEs for CVE-2021-40438. Removed Outside In Technology. Removed version 11.1.1.5.0 of Identity Manager Connector."
        },
        {
          "date": "2022-05-02T16:00:00-07:00",
          "number": "4",
          "summary": "Updated the affected versions HSGBU InForm and UIM. Note added for MySQL. Note Removed for CVE-2022-21449. Credit Name Updated for CVE-2022-21453"
        },
        {
          "date": "2022-05-04T15:00:00-07:00",
          "number": "5",
          "summary": "Removed affected version 11.1.1.5.0 of Oracle Identity Manager Connector for CVE-2022-23305. Added a footnote for the change."
        },
        {
          "date": "2022-05-20T13:00:00-07:00",
          "number": "6",
          "summary": "Added version 8.5.6 to Outside In Technology. Changed the Component of Middleware Common Libraries and Tools to FMW Remote Diagnostic Agent for CVE-2021-30129. Updated credit name."
        },
        {
          "date": "2022-06-16T13:00:00-07:00",
          "number": "7",
          "summary": "Added a new credit for CVE-2022-21438."
        },
        {
          "date": "2024-09-20T12:00:00-07:00",
          "number": "8",
          "summary": "Update CVE-2022-21445."
        }
      ],
      "status": "draft",
      "version": "8"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Engineered Systems Utilities Version 12.1.0.2",
                    "product": {
                      "name": "Engineered Systems Utilities Version 12.1.0.2",
                      "product_id": "P-10655V-12.1.0.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Engineered Systems Utilities Version 19c",
                    "product": {
                      "name": "Engineered Systems Utilities Version 19c",
                      "product_id": "P-10655V-19c"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Engineered Systems Utilities Version 21c",
                    "product": {
                      "name": "Engineered Systems Utilities Version 21c",
                      "product_id": "P-10655V-21c"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Engineered Systems Utilities"
              }
            ],
            "category": "product_family",
            "name": "Oracle Autonomous Health Framework"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Blockchain Platform Version 21.1.2",
                    "product": {
                      "name": "Oracle Blockchain Platform Version 21.1.2",
                      "product_id": "P-13444V-21.1.2"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Blockchain Platform Version Prior to 21.1.2",
                    "product": {
                      "name": "Oracle Blockchain Platform Version Prior to 21.1.2",
                      "product_id": "P-13444V-Prior to 21.1.2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Blockchain Platform"
              }
            ],
            "category": "product_family",
            "name": "Oracle Blockchain Platform"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Commerce Guided Search Version 11.3.2",
                    "product": {
                      "name": "Oracle Commerce Guided Search Version 11.3.2",
                      "product_id": "P-9633V-11.3.2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Commerce Guided Search"
              }
            ],
            "category": "product_family",
            "name": "Oracle Commerce"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Services Gatekeeper Version 7.0.0.0.0",
                    "product": {
                      "name": "Oracle Communications Services Gatekeeper Version 7.0.0.0.0",
                      "product_id": "P-5381V-7.0.0.0.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Services Gatekeeper"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Session Border Controller Version 8.4",
                    "product": {
                      "name": "Oracle Communications Session Border Controller Version 8.4",
                      "product_id": "P-10750V-8.4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Session Border Controller Version 9.0",
                    "product": {
                      "name": "Oracle Communications Session Border Controller Version 9.0",
                      "product_id": "P-10750V-9.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Session Border Controller"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Unified Session Manager Version 8.2.5",
                    "product": {
                      "name": "Oracle Communications Unified Session Manager Version 8.2.5",
                      "product_id": "P-10753V-8.2.5"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Unified Session Manager Version 8.4.5",
                    "product": {
                      "name": "Oracle Communications Unified Session Manager Version 8.4.5",
                      "product_id": "P-10753V-8.4.5"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Unified Session Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Session Border Controller Version 8.4",
                    "product": {
                      "name": "Oracle Enterprise Session Border Controller Version 8.4",
                      "product_id": "P-10757V-8.4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Session Border Controller Version 9.0",
                    "product": {
                      "name": "Oracle Enterprise Session Border Controller Version 9.0",
                      "product_id": "P-10757V-9.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Enterprise Session Border Controller"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Communications Broker Version 3.2",
                    "product": {
                      "name": "Oracle Enterprise Communications Broker Version 3.2",
                      "product_id": "P-10758V-3.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Communications Broker Version 3.3",
                    "product": {
                      "name": "Oracle Enterprise Communications Broker Version 3.3",
                      "product_id": "P-10758V-3.3"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Enterprise Communications Broker"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Operations Monitor Version 4.3",
                    "product": {
                      "name": "Oracle Communications Operations Monitor Version 4.3",
                      "product_id": "P-10761V-4.3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Operations Monitor Version 4.4",
                    "product": {
                      "name": "Oracle Communications Operations Monitor Version 4.4",
                      "product_id": "P-10761V-4.4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Operations Monitor Version 5.0",
                    "product": {
                      "name": "Oracle Communications Operations Monitor Version 5.0",
                      "product_id": "P-10761V-5.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Operations Monitor"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Interactive Session Recorder Version 6.4",
                    "product": {
                      "name": "Oracle Communications Interactive Session Recorder Version 6.4",
                      "product_id": "P-10765V-6.4"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Interactive Session Recorder"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications EAGLE Software Version 46.7.0",
                    "product": {
                      "name": "Oracle Communications EAGLE Software Version 46.7.0",
                      "product_id": "P-10768V-46.7.0"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications EAGLE Software Version 46.8.0-46.8.2",
                    "product": {
                      "name": "Oracle Communications EAGLE Software Version 46.8.0-46.8.2",
                      "product_id": "P-10768V-46.8.0-46.8.2"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications EAGLE Software Version 46.9.1-46.9.3",
                    "product": {
                      "name": "Oracle Communications EAGLE Software Version 46.9.1-46.9.3",
                      "product_id": "P-10768V-46.9.1-46.9.3"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications EAGLE Software"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Session Report Manager Version Prior to 9.0",
                    "product": {
                      "name": "Oracle Communications Session Report Manager Version Prior to 9.0",
                      "product_id": "P-10770V-Prior to 9.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Session Report Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Session Route Manager Version Prior to 9.0",
                    "product": {
                      "name": "Oracle Communications Session Route Manager Version Prior to 9.0",
                      "product_id": "P-10771V-Prior to 9.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Session Route Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications WebRTC Session Controller Version 7.2.1",
                    "product": {
                      "name": "Oracle Communications WebRTC Session Controller Version 7.2.1",
                      "product_id": "P-10811V-7.2.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications WebRTC Session Controller"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Diameter Signaling Router Version 8.4.0.0",
                    "product": {
                      "name": "Oracle Communications Diameter Signaling Router Version 8.4.0.0",
                      "product_id": "P-10899V-8.4.0.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Diameter Signaling Router"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Policy Management Version 12.5.0.0.0",
                    "product": {
                      "name": "Oracle Communications Policy Management Version 12.5.0.0.0",
                      "product_id": "P-10900V-12.5.0.0.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Policy Management Version 12.6.0.0.0",
                    "product": {
                      "name": "Oracle Communications Policy Management Version 12.6.0.0.0",
                      "product_id": "P-10900V-12.6.0.0.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Policy Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Evolved Communications Application Server Version 7.1",
                    "product": {
                      "name": "Oracle Communications Evolved Communications Application Server Version 7.1",
                      "product_id": "P-10994V-7.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Evolved Communications Application Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Performance Intelligence Center (PIC) Software Version 10.3.0.0.0-10.3.0.2.1",
                    "product": {
                      "name": "Oracle Communications Performance Intelligence Center (PIC) Software Version 10.3.0.0.0-10.3.0.2.1",
                      "product_id": "P-11044V-10.3.0.0.0-10.3.0.2.1"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Performance Intelligence Center (PIC) Software Version 10.4.0.1.0-10.4.0.3.1",
                    "product": {
                      "name": "Oracle Communications Performance Intelligence Center (PIC) Software Version 10.4.0.1.0-10.4.0.3.1",
                      "product_id": "P-11044V-10.4.0.1.0-10.4.0.3.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Performance Intelligence Center (PIC) Software Version 10.4.0.3",
                    "product": {
                      "name": "Oracle Communications Performance Intelligence Center (PIC) Software Version 10.4.0.3",
                      "product_id": "P-11044V-10.4.0.3"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Performance Intelligence Center (PIC) Software"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Element Manager Version Prior to 9.0",
                    "product": {
                      "name": "Oracle Communications Element Manager Version Prior to 9.0",
                      "product_id": "P-11052V-Prior to 9.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Element Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications User Data Repository Version 12.4",
                    "product": {
                      "name": "Oracle Communications User Data Repository Version 12.4",
                      "product_id": "P-11108V-12.4"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications User Data Repository"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications EAGLE FTP Table Base Retrieval Version 4.5",
                    "product": {
                      "name": "Oracle Communications EAGLE FTP Table Base Retrieval Version 4.5",
                      "product_id": "P-11116V-4.5"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications EAGLE FTP Table Base Retrieval"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications EAGLE LNP Application Processor Version 10.1",
                    "product": {
                      "name": "Oracle Communications EAGLE LNP Application Processor Version 10.1",
                      "product_id": "P-11118V-10.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications EAGLE LNP Application Processor Version 10.2",
                    "product": {
                      "name": "Oracle Communications EAGLE LNP Application Processor Version 10.2",
                      "product_id": "P-11118V-10.2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications EAGLE LNP Application Processor"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications EAGLE Application Processor Version All Supported Versions",
                    "product": {
                      "name": "Oracle Communications EAGLE Application Processor Version All Supported Versions",
                      "product_id": "P-11122V-All Supported Versions"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications EAGLE Application Processor"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications EAGLE Element Management System Version 46.6",
                    "product": {
                      "name": "Oracle Communications EAGLE Element Management System Version 46.6",
                      "product_id": "P-11125V-46.6"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications EAGLE Element Management System"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Diameter Intelligence Hub Version 8.0.0-8.1.0",
                    "product": {
                      "name": "Oracle Communications Diameter Intelligence Hub Version 8.0.0-8.1.0",
                      "product_id": "P-11126V-8.0.0-8.1.0"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Diameter Intelligence Hub Version 8.0.0-8.2.3",
                    "product": {
                      "name": "Oracle Communications Diameter Intelligence Hub Version 8.0.0-8.2.3",
                      "product_id": "P-11126V-8.0.0-8.2.3"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Diameter Intelligence Hub Version 8.2.0-8.2.3",
                    "product": {
                      "name": "Oracle Communications Diameter Intelligence Hub Version 8.2.0-8.2.3",
                      "product_id": "P-11126V-8.2.0-8.2.3"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Diameter Intelligence Hub"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle SD-WAN Edge Version 9.0",
                    "product": {
                      "name": "Oracle SD-WAN Edge Version 9.0",
                      "product_id": "P-13940V-9.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle SD-WAN Edge Version 9.1",
                    "product": {
                      "name": "Oracle SD-WAN Edge Version 9.1",
                      "product_id": "P-13940V-9.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle SD-WAN Edge"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 1.15.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 1.15.0",
                      "product_id": "P-14117V-1.15.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Service Communication Proxy"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Repository Function Version 1.15.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Repository Function Version 1.15.0",
                      "product_id": "P-14118V-1.15.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Repository Function Version 1.15.1",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Repository Function Version 1.15.1",
                      "product_id": "P-14118V-1.15.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Repository Function Version 22.1.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Repository Function Version 22.1.0",
                      "product_id": "P-14118V-22.1.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Network Repository Function"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Unified Data Repository Version 1.15.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Unified Data Repository Version 1.15.0",
                      "product_id": "P-14119V-1.15.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Unified Data Repository Version 22.1.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Unified Data Repository Version 22.1.0",
                      "product_id": "P-14119V-22.1.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Unified Data Repository"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Binding Support Function Version 1.11.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Binding Support Function Version 1.11.0",
                      "product_id": "P-14121V-1.11.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Binding Support Function"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Exposure Function Version 22.1.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Exposure Function Version 22.1.0",
                      "product_id": "P-14122V-22.1.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Network Exposure Function"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 1.7.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 1.7.0",
                      "product_id": "P-14123V-1.7.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 22.1.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 22.1.0",
                      "product_id": "P-14123V-22.1.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 1.10.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 1.10.0",
                      "product_id": "P-14125V-1.10.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Slice Selection Function Version 1.8.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Slice Selection Function Version 1.8.0",
                      "product_id": "P-14130V-1.8.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Network Slice Selection Function Version 22.1.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Network Slice Selection Function Version 22.1.0",
                      "product_id": "P-14130V-22.1.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Network Slice Selection Function"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Console Version 1.9.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Console Version 1.9.0",
                      "product_id": "P-14250V-1.9.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Console Version 22.1.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Console Version 22.1.0",
                      "product_id": "P-14250V-22.1.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Console"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Management Cloud Engine Version 1.5.0",
                    "product": {
                      "name": "Management Cloud Engine Version 1.5.0",
                      "product_id": "P-14252V-1.5.0"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Management Cloud Engine Version Prior to 1.5.0",
                    "product": {
                      "name": "Management Cloud Engine Version Prior to 1.5.0",
                      "product_id": "P-14252V-Prior to 1.5.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Management Cloud Engine"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Policy Version 1.14.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Policy Version 1.14.0",
                      "product_id": "P-14277V-1.14.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Policy Version 1.15.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Policy Version 1.15.0",
                      "product_id": "P-14277V-1.15.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Policy Version 22.1.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Policy Version 22.1.0",
                      "product_id": "P-14277V-22.1.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Policy Version All Supported Versions",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Policy Version All Supported Versions",
                      "product_id": "P-14277V-All Supported Versions"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Policy"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Automated Test Suite Version 1.8.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Automated Test Suite Version 1.8.0",
                      "product_id": "P-14488V-1.8.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Automated Test Suite Version 1.9.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Automated Test Suite Version 1.9.0",
                      "product_id": "P-14488V-1.9.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Cloud Native Core Automated Test Suite Version 22.1.0",
                    "product": {
                      "name": "Oracle Communications Cloud Native Core Automated Test Suite Version 22.1.0",
                      "product_id": "P-14488V-22.1.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Cloud Native Core Automated Test Suite"
              }
            ],
            "category": "product_family",
            "name": "Oracle Communications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Billing and Revenue Management Version 12.0.0.4",
                    "product": {
                      "name": "Oracle Communications Billing and Revenue Management Version 12.0.0.4",
                      "product_id": "P-2136V-12.0.0.4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Billing and Revenue Management Version 12.0.0.5",
                    "product": {
                      "name": "Oracle Communications Billing and Revenue Management Version 12.0.0.5",
                      "product_id": "P-2136V-12.0.0.5"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Billing and Revenue Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications ASAP Version 7.3",
                    "product": {
                      "name": "Oracle Communications ASAP Version 7.3",
                      "product_id": "P-2260V-7.3"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications ASAP"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications IP Service Activator Version 7.4.0",
                    "product": {
                      "name": "Oracle Communications IP Service Activator Version 7.4.0",
                      "product_id": "P-2261V-7.4.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications IP Service Activator"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications MetaSolv Solution Version 6.3.1",
                    "product": {
                      "name": "Oracle Communications MetaSolv Solution Version 6.3.1",
                      "product_id": "P-2267V-6.3.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications MetaSolv Solution"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Order and Service Management Version 7.3",
                    "product": {
                      "name": "Oracle Communications Order and Service Management Version 7.3",
                      "product_id": "P-2270V-7.3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Order and Service Management Version 7.4",
                    "product": {
                      "name": "Oracle Communications Order and Service Management Version 7.4",
                      "product_id": "P-2270V-7.4"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Order and Service Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Design Studio Version 7.3.5",
                    "product": {
                      "name": "Oracle Communications Design Studio Version 7.3.5",
                      "product_id": "P-2283V-7.3.5"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Design Studio Version 7.4.0-7.4.2",
                    "product": {
                      "name": "Oracle Communications Design Studio Version 7.4.0-7.4.2",
                      "product_id": "P-2283V-7.4.0-7.4.2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Design Studio"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Integrity Version 7.3.2",
                    "product": {
                      "name": "Oracle Communications Network Integrity Version 7.3.2",
                      "product_id": "P-4491V-7.3.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Integrity Version 7.3.5",
                    "product": {
                      "name": "Oracle Communications Network Integrity Version 7.3.5",
                      "product_id": "P-4491V-7.3.5"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Integrity Version 7.3.6",
                    "product": {
                      "name": "Oracle Communications Network Integrity Version 7.3.6",
                      "product_id": "P-4491V-7.3.6"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Network Integrity"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Unified Inventory Management Version 7.3.4-7.3.5",
                    "product": {
                      "name": "Oracle Communications Unified Inventory Management Version 7.3.4-7.3.5",
                      "product_id": "P-4516V-7.3.4-7.3.5"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Unified Inventory Management Version 7.3.5",
                    "product": {
                      "name": "Oracle Communications Unified Inventory Management Version 7.3.5",
                      "product_id": "P-4516V-7.3.5"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Unified Inventory Management Version 7.4.1-7.4.2",
                    "product": {
                      "name": "Oracle Communications Unified Inventory Management Version 7.4.1-7.4.2",
                      "product_id": "P-4516V-7.4.1-7.4.2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Unified Inventory Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Network Charging and Control Version 12.0.1.0.0-12.0.4.0.0",
                    "product": {
                      "name": "Oracle Communications Network Charging and Control Version 12.0.1.0.0-12.0.4.0.0",
                      "product_id": "P-4623V-12.0.1.0.0-12.0.4.0.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Network Charging and Control Version 6.0.1.0.0",
                    "product": {
                      "name": "Oracle Communications Network Charging and Control Version 6.0.1.0.0",
                      "product_id": "P-4623V-6.0.1.0.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Network Charging and Control"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Instant Messaging Server Version 10.0.1.5.0",
                    "product": {
                      "name": "Oracle Communications Instant Messaging Server Version 10.0.1.5.0",
                      "product_id": "P-8495V-10.0.1.5.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Instant Messaging Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Messaging Server Version 8.1",
                    "product": {
                      "name": "Oracle Communications Messaging Server Version 8.1",
                      "product_id": "P-8496V-8.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Messaging Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Convergence Version 3.0.2.2",
                    "product": {
                      "name": "Oracle Communications Convergence Version 3.0.2.2",
                      "product_id": "P-8501V-3.0.2.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Convergence Version 3.0.3.0",
                    "product": {
                      "name": "Oracle Communications Convergence Version 3.0.3.0",
                      "product_id": "P-8501V-3.0.3.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Convergence"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Pricing Design Center Version 12.0.0.4",
                    "product": {
                      "name": "Oracle Communications Pricing Design Center Version 12.0.0.4",
                      "product_id": "P-9437V-12.0.0.4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Pricing Design Center Version 12.0.0.5",
                    "product": {
                      "name": "Oracle Communications Pricing Design Center Version 12.0.0.5",
                      "product_id": "P-9437V-12.0.0.5"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Pricing Design Center"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Contacts Server Version 8.0.0.6.0",
                    "product": {
                      "name": "Oracle Communications Contacts Server Version 8.0.0.6.0",
                      "product_id": "P-10696V-8.0.0.6.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Contacts Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Communications Convergent Charging Controller Version 12.0.1.0.0-12.0.4.0.0",
                    "product": {
                      "name": "Oracle Communications Convergent Charging Controller Version 12.0.1.0.0-12.0.4.0.0",
                      "product_id": "P-12985V-12.0.1.0.0-12.0.4.0.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Communications Convergent Charging Controller Version 6.0.1.0.0",
                    "product": {
                      "name": "Oracle Communications Convergent Charging Controller Version 6.0.1.0.0",
                      "product_id": "P-12985V-6.0.1.0.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Communications Convergent Charging Controller"
              }
            ],
            "category": "product_family",
            "name": "Oracle Communications Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Primavera Unifier Version 17.7-17.12",
                    "product": {
                      "name": "Primavera Unifier Version 17.7-17.12",
                      "product_id": "P-10354V-17.7-17.12"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Primavera Unifier Version 18.8",
                    "product": {
                      "name": "Primavera Unifier Version 18.8",
                      "product_id": "P-10354V-18.8"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Primavera Unifier Version 19.12",
                    "product": {
                      "name": "Primavera Unifier Version 19.12",
                      "product_id": "P-10354V-19.12"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Primavera Unifier Version 20.12",
                    "product": {
                      "name": "Primavera Unifier Version 20.12",
                      "product_id": "P-10354V-20.12"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Primavera Unifier Version 21.12",
                    "product": {
                      "name": "Primavera Unifier Version 21.12",
                      "product_id": "P-10354V-21.12"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Primavera Unifier"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Instantis EnterpriseTrack Version 17.1",
                    "product": {
                      "name": "Instantis EnterpriseTrack Version 17.1",
                      "product_id": "P-10563V-17.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Instantis EnterpriseTrack Version 17.2",
                    "product": {
                      "name": "Instantis EnterpriseTrack Version 17.2",
                      "product_id": "P-10563V-17.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Instantis EnterpriseTrack Version 17.3",
                    "product": {
                      "name": "Instantis EnterpriseTrack Version 17.3",
                      "product_id": "P-10563V-17.3"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Instantis EnterpriseTrack"
              }
            ],
            "category": "product_family",
            "name": "Oracle Construction and Engineering"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Database Server(Java VM) Version 12.1.0.2",
                    "product": {
                      "name": "Oracle Database Server(Java VM) Version 12.1.0.2",
                      "product_id": "P-5(Java VM)V-12.1.0.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Database Server(RDBMS Gateway / Generic ODBC Connectivity) Version 12.1.0.2",
                    "product": {
                      "name": "Oracle Database Server(RDBMS Gateway / Generic ODBC Connectivity) Version 12.1.0.2",
                      "product_id": "P-5(RDBMS Gateway / Generic ODBC Connectivity)V-12.1.0.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Database Server(Java VM) Version 19c",
                    "product": {
                      "name": "Oracle Database Server(Java VM) Version 19c",
                      "product_id": "P-5(Java VM)V-19c"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Database Server(Oracle Database - Enterprise Edition Sharding) Version 19c",
                    "product": {
                      "name": "Oracle Database Server(Oracle Database - Enterprise Edition Sharding) Version 19c",
                      "product_id": "P-5(Oracle Database - Enterprise Edition Sharding)V-19c"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Database Server(RDBMS Gateway / Generic ODBC Connectivity) Version 19c",
                    "product": {
                      "name": "Oracle Database Server(RDBMS Gateway / Generic ODBC Connectivity) Version 19c",
                      "product_id": "P-5(RDBMS Gateway / Generic ODBC Connectivity)V-19c"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Database Server(Java VM) Version 21c",
                    "product": {
                      "name": "Oracle Database Server(Java VM) Version 21c",
                      "product_id": "P-5(Java VM)V-21c"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Database Server(RDBMS Gateway / Generic ODBC Connectivity) Version 21c",
                    "product": {
                      "name": "Oracle Database Server(RDBMS Gateway / Generic ODBC Connectivity) Version 21c",
                      "product_id": "P-5(RDBMS Gateway / Generic ODBC Connectivity)V-21c"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Database Server(Oracle Database - Enterprise Edition Portable Clusterware) Version All Supported Versions",
                    "product": {
                      "name": "Oracle Database Server(Oracle Database - Enterprise Edition Portable Clusterware) Version All Supported Versions",
                      "product_id": "P-5(Oracle Database - Enterprise Edition Portable Clusterware)V-All Supported Versions"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Database Server(Oracle Database - Enterprise Edition RDBMS) Version All Supported Versions",
                    "product": {
                      "name": "Oracle Database Server(Oracle Database - Enterprise Edition RDBMS) Version All Supported Versions",
                      "product_id": "P-5(Oracle Database - Enterprise Edition RDBMS)V-All Supported Versions"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Database Server(Oracle Database Enterprise Edition) Version All Supported Versions",
                    "product": {
                      "name": "Oracle Database Server(Oracle Database Enterprise Edition) Version All Supported Versions",
                      "product_id": "P-5(Oracle Database Enterprise Edition)V-All Supported Versions"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Database Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Database Configuration Assistant Version All Supported Versions",
                    "product": {
                      "name": "Oracle Database Configuration Assistant Version All Supported Versions",
                      "product_id": "P-383V-All Supported Versions"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Database Configuration Assistant"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Spatial and Graph MapViewer Version 19c",
                    "product": {
                      "name": "Oracle Spatial and Graph MapViewer Version 19c",
                      "product_id": "P-619V-19c"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Spatial and Graph MapViewer Version 21c",
                    "product": {
                      "name": "Oracle Spatial and Graph MapViewer Version 21c",
                      "product_id": "P-619V-21c"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Spatial and Graph MapViewer"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Application Express Version Prior to 22.1",
                    "product": {
                      "name": "Oracle Application Express Version Prior to 22.1",
                      "product_id": "P-1348V-Prior to 22.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Application Express"
              }
            ],
            "category": "product_family",
            "name": "Oracle Database Server"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Applications Framework Version 12.2.4-12.2.11",
                    "product": {
                      "name": "Oracle Applications Framework Version 12.2.4-12.2.11",
                      "product_id": "P-1472V-12.2.4-12.2.11"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Applications Framework Version 12.2.6-12.2.11",
                    "product": {
                      "name": "Oracle Applications Framework Version 12.2.6-12.2.11",
                      "product_id": "P-1472V-12.2.6-12.2.11"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Applications Framework"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle E-Business Suite Information Discovery Version Enterprise Information Discovery: 7-9",
                    "product": {
                      "name": "Oracle E-Business Suite Information Discovery Version Enterprise Information Discovery: 7-9",
                      "product_id": "P-10240V-Enterprise Information Discovery: 7-9"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle E-Business Suite Information Discovery"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle E-Business Suite Cloud Manager and Cloud Backup Module Version EBS Cloud Manager and Backup Module: Prior to 22.1.1.1",
                    "product": {
                      "name": "Oracle E-Business Suite Cloud Manager and Cloud Backup Module Version EBS Cloud Manager and Backup Module: Prior to 22.1.1.1",
                      "product_id": "P-12808V-EBS Cloud Manager and Backup Module: Prior to 22.1.1.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle E-Business Suite Cloud Manager and Cloud Backup Module"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Enterprise Command Center Framework Version Enterprise Command Center: 7.0",
                    "product": {
                      "name": "Oracle Enterprise Command Center Framework Version Enterprise Command Center: 7.0",
                      "product_id": "P-13788V-Enterprise Command Center: 7.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Enterprise Command Center Framework"
              }
            ],
            "category": "product_family",
            "name": "Oracle E-Business Suite"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Enterprise Manager Base Platform Version 13.4.0.0",
                    "product": {
                      "name": "Enterprise Manager Base Platform Version 13.4.0.0",
                      "product_id": "P-1370V-13.4.0.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Enterprise Manager Base Platform Version 13.5.0.0",
                    "product": {
                      "name": "Enterprise Manager Base Platform Version 13.5.0.0",
                      "product_id": "P-1370V-13.5.0.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Enterprise Manager Base Platform"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Enterprise Manager for Peoplesoft Version 13.4.1.1",
                    "product": {
                      "name": "Enterprise Manager for Peoplesoft Version 13.4.1.1",
                      "product_id": "P-2131V-13.4.1.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Enterprise Manager for Peoplesoft Version 13.5.1.1",
                    "product": {
                      "name": "Enterprise Manager for Peoplesoft Version 13.5.1.1",
                      "product_id": "P-2131V-13.5.1.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Enterprise Manager for Peoplesoft"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Application Testing Suite Version 13.3.0.1",
                    "product": {
                      "name": "Oracle Application Testing Suite Version 13.3.0.1",
                      "product_id": "P-4622V-13.3.0.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Application Testing Suite"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Enterprise Manager Ops Center Version 12.4.0.0",
                    "product": {
                      "name": "Enterprise Manager Ops Center Version 12.4.0.0",
                      "product_id": "P-9835V-12.4.0.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Enterprise Manager Ops Center"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Enterprise Manager for Storage Management Version 13.4.0.0",
                    "product": {
                      "name": "Enterprise Manager for Storage Management Version 13.4.0.0",
                      "product_id": "P-10303V-13.4.0.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Enterprise Manager for Storage Management"
              }
            ],
            "category": "product_family",
            "name": "Oracle Enterprise Manager"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Revenue Management and Billing Version 2.7.0.0",
                    "product": {
                      "name": "Oracle Financial Services Revenue Management and Billing Version 2.7.0.0",
                      "product_id": "P-5322V-2.7.0.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Revenue Management and Billing Version 2.7.0.1",
                    "product": {
                      "name": "Oracle Financial Services Revenue Management and Billing Version 2.7.0.1",
                      "product_id": "P-5322V-2.7.0.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Revenue Management and Billing Version 2.8.0.0",
                    "product": {
                      "name": "Oracle Financial Services Revenue Management and Billing Version 2.8.0.0",
                      "product_id": "P-5322V-2.8.0.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Financial Services Revenue Management and Billing"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.6.0-8.0.9.0",
                    "product": {
                      "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.6.0-8.0.9.0",
                      "product_id": "P-5680V-8.0.6.0-8.0.9.0"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.0.0-8.1.2.0",
                    "product": {
                      "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.0.0-8.1.2.0",
                      "product_id": "P-5680V-8.1.0.0-8.1.2.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.1.0",
                    "product": {
                      "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.1.0",
                      "product_id": "P-5680V-8.1.1.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2.0",
                    "product": {
                      "name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2.0",
                      "product_id": "P-5680V-8.1.2.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Financial Services Analytical Applications Infrastructure"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle FLEXCUBE Universal Banking Version 11.83.3",
                    "product": {
                      "name": "Oracle FLEXCUBE Universal Banking Version 11.83.3",
                      "product_id": "P-9052V-11.83.3"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle FLEXCUBE Universal Banking Version 12.1-12.4",
                    "product": {
                      "name": "Oracle FLEXCUBE Universal Banking Version 12.1-12.4",
                      "product_id": "P-9052V-12.1-12.4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle FLEXCUBE Universal Banking Version 12.4",
                    "product": {
                      "name": "Oracle FLEXCUBE Universal Banking Version 12.4",
                      "product_id": "P-9052V-12.4"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle FLEXCUBE Universal Banking Version 14.0-14.3",
                    "product": {
                      "name": "Oracle FLEXCUBE Universal Banking Version 14.0-14.3",
                      "product_id": "P-9052V-14.0-14.3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle FLEXCUBE Universal Banking Version 14.5",
                    "product": {
                      "name": "Oracle FLEXCUBE Universal Banking Version 14.5",
                      "product_id": "P-9052V-14.5"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle FLEXCUBE Universal Banking"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Platform Version 2.12.0",
                    "product": {
                      "name": "Oracle Banking Platform Version 2.12.0",
                      "product_id": "P-9178V-2.12.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Platform Version 2.6.2",
                    "product": {
                      "name": "Oracle Banking Platform Version 2.6.2",
                      "product_id": "P-9178V-2.6.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Platform Version 2.7.1",
                    "product": {
                      "name": "Oracle Banking Platform Version 2.7.1",
                      "product_id": "P-9178V-2.7.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Banking Platform"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Financial Services Behavior Detection Platform Version 8.0.6.0-8.0.8.0",
                    "product": {
                      "name": "Oracle Financial Services Behavior Detection Platform Version 8.0.6.0-8.0.8.0",
                      "product_id": "P-9190V-8.0.6.0-8.0.8.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Behavior Detection Platform Version 8.1.1.0",
                    "product": {
                      "name": "Oracle Financial Services Behavior Detection Platform Version 8.1.1.0",
                      "product_id": "P-9190V-8.1.1.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Behavior Detection Platform Version 8.1.1.1",
                    "product": {
                      "name": "Oracle Financial Services Behavior Detection Platform Version 8.1.1.1",
                      "product_id": "P-9190V-8.1.1.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Behavior Detection Platform Version 8.1.2.0",
                    "product": {
                      "name": "Oracle Financial Services Behavior Detection Platform Version 8.1.2.0",
                      "product_id": "P-9190V-8.1.2.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Financial Services Behavior Detection Platform"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Payments Version 14.5",
                    "product": {
                      "name": "Oracle Banking Payments Version 14.5",
                      "product_id": "P-13011V-14.5"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Banking Payments"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Enterprise Default Management Version 2.10.0",
                    "product": {
                      "name": "Oracle Banking Enterprise Default Management Version 2.10.0",
                      "product_id": "P-13390V-2.10.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Enterprise Default Management Version 2.12.0",
                    "product": {
                      "name": "Oracle Banking Enterprise Default Management Version 2.12.0",
                      "product_id": "P-13390V-2.12.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Enterprise Default Management Version 2.7.1",
                    "product": {
                      "name": "Oracle Banking Enterprise Default Management Version 2.7.1",
                      "product_id": "P-13390V-2.7.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Banking Enterprise Default Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Enterprise Case Management Version 8.0.7.1",
                    "product": {
                      "name": "Oracle Financial Services Enterprise Case Management Version 8.0.7.1",
                      "product_id": "P-13545V-8.0.7.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Enterprise Case Management Version 8.0.7.2",
                    "product": {
                      "name": "Oracle Financial Services Enterprise Case Management Version 8.0.7.2",
                      "product_id": "P-13545V-8.0.7.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Enterprise Case Management Version 8.0.8.0",
                    "product": {
                      "name": "Oracle Financial Services Enterprise Case Management Version 8.0.8.0",
                      "product_id": "P-13545V-8.0.8.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Enterprise Case Management Version 8.0.8.1",
                    "product": {
                      "name": "Oracle Financial Services Enterprise Case Management Version 8.0.8.1",
                      "product_id": "P-13545V-8.0.8.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Enterprise Case Management Version 8.1.1.0",
                    "product": {
                      "name": "Oracle Financial Services Enterprise Case Management Version 8.1.1.0",
                      "product_id": "P-13545V-8.1.1.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Enterprise Case Management Version 8.1.1.1",
                    "product": {
                      "name": "Oracle Financial Services Enterprise Case Management Version 8.1.1.1",
                      "product_id": "P-13545V-8.1.1.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Financial Services Enterprise Case Management Version 8.1.2.0",
                    "product": {
                      "name": "Oracle Financial Services Enterprise Case Management Version 8.1.2.0",
                      "product_id": "P-13545V-8.1.2.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Financial Services Enterprise Case Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Loans Servicing Version 2.12.0",
                    "product": {
                      "name": "Oracle Banking Loans Servicing Version 2.12.0",
                      "product_id": "P-13927V-2.12.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Banking Loans Servicing"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Deposits and Lines of Credit Servicing Version 2.12.0",
                    "product": {
                      "name": "Oracle Banking Deposits and Lines of Credit Servicing Version 2.12.0",
                      "product_id": "P-13928V-2.12.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Banking Deposits and Lines of Credit Servicing"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Party Management Version 2.7.0",
                    "product": {
                      "name": "Oracle Banking Party Management Version 2.7.0",
                      "product_id": "P-13929V-2.7.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Banking Party Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Treasury Management Version 14.5",
                    "product": {
                      "name": "Oracle Banking Treasury Management Version 14.5",
                      "product_id": "P-14133V-14.5"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Banking Treasury Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Banking Trade Finance Version 14.5",
                    "product": {
                      "name": "Oracle Banking Trade Finance Version 14.5",
                      "product_id": "P-14134V-14.5"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Banking Trade Finance"
              }
            ],
            "category": "product_family",
            "name": "Oracle Financial Services Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Internet Directory Version 12.2.1.3.0",
                    "product": {
                      "name": "Oracle Internet Directory Version 12.2.1.3.0",
                      "product_id": "P-355V-12.2.1.3.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Internet Directory Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Internet Directory Version 12.2.1.4.0",
                      "product_id": "P-355V-12.2.1.4.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Internet Directory"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle JDeveloper Version 12.2.1.3.0",
                    "product": {
                      "name": "Oracle JDeveloper Version 12.2.1.3.0",
                      "product_id": "P-807V-12.2.1.3.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle JDeveloper Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle JDeveloper Version 12.2.1.4.0",
                      "product_id": "P-807V-12.2.1.4.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle JDeveloper"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle HTTP Server Version 12.2.1.3.0",
                    "product": {
                      "name": "Oracle HTTP Server Version 12.2.1.3.0",
                      "product_id": "P-1042V-12.2.1.3.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle HTTP Server Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle HTTP Server Version 12.2.1.4.0",
                      "product_id": "P-1042V-12.2.1.4.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle HTTP Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle WebCenter Portal Version 12.2.1.3.0",
                    "product": {
                      "name": "Oracle WebCenter Portal Version 12.2.1.3.0",
                      "product_id": "P-1696V-12.2.1.3.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle WebCenter Portal Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle WebCenter Portal Version 12.2.1.4.0",
                      "product_id": "P-1696V-12.2.1.4.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle WebCenter Portal"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Web Services Manager Version 12.2.1.3.0",
                    "product": {
                      "name": "Oracle Web Services Manager Version 12.2.1.3.0",
                      "product_id": "P-1775V-12.2.1.3.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Web Services Manager Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Web Services Manager Version 12.2.1.4.0",
                      "product_id": "P-1775V-12.2.1.4.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Web Services Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Identity Management Suite Version 12.2.1.3.0",
                    "product": {
                      "name": "Oracle Identity Management Suite Version 12.2.1.3.0",
                      "product_id": "P-1980V-12.2.1.3.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Identity Management Suite Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Identity Management Suite Version 12.2.1.4.0",
                      "product_id": "P-1980V-12.2.1.4.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Identity Management Suite"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Identity Manager Connector Version -",
                    "product": {
                      "name": "Oracle Identity Manager Connector Version -",
                      "product_id": "P-1999V--"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Identity Manager Connector Version 9.1.0",
                    "product": {
                      "name": "Oracle Identity Manager Connector Version 9.1.0",
                      "product_id": "P-1999V-9.1.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Identity Manager Connector"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Business Intelligence Enterprise Edition(BI Platform Security) Version 12.2.1.3.0",
                    "product": {
                      "name": "Oracle Business Intelligence Enterprise Edition(BI Platform Security) Version 12.2.1.3.0",
                      "product_id": "P-2025(BI Platform Security)V-12.2.1.3.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Business Intelligence Enterprise Edition Version 12.2.1.3.0",
                    "product": {
                      "name": "Oracle Business Intelligence Enterprise Edition Version 12.2.1.3.0",
                      "product_id": "P-2025V-12.2.1.3.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Business Intelligence Enterprise Edition(BI Platform Security) Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Business Intelligence Enterprise Edition(BI Platform Security) Version 12.2.1.4.0",
                      "product_id": "P-2025(BI Platform Security)V-12.2.1.4.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Business Intelligence Enterprise Edition(Storage Service Integration) Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Business Intelligence Enterprise Edition(Storage Service Integration) Version 12.2.1.4.0",
                      "product_id": "P-2025(Storage Service Integration)V-12.2.1.4.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Business Intelligence Enterprise Edition Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Business Intelligence Enterprise Edition Version 12.2.1.4.0",
                      "product_id": "P-2025V-12.2.1.4.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Business Intelligence Enterprise Edition Version 5.5.0.0.0",
                    "product": {
                      "name": "Oracle Business Intelligence Enterprise Edition Version 5.5.0.0.0",
                      "product_id": "P-2025V-5.5.0.0.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Business Intelligence Enterprise Edition(Analytics Server) Version 5.9.0.0.0",
                    "product": {
                      "name": "Oracle Business Intelligence Enterprise Edition(Analytics Server) Version 5.9.0.0.0",
                      "product_id": "P-2025(Analytics Server)V-5.9.0.0.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Business Intelligence Enterprise Edition(BI Platform Security) Version 5.9.0.0.0",
                    "product": {
                      "name": "Oracle Business Intelligence Enterprise Edition(BI Platform Security) Version 5.9.0.0.0",
                      "product_id": "P-2025(BI Platform Security)V-5.9.0.0.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Business Intelligence Enterprise Edition Version 5.9.0.0.0",
                    "product": {
                      "name": "Oracle Business Intelligence Enterprise Edition Version 5.9.0.0.0",
                      "product_id": "P-2025V-5.9.0.0.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Business Intelligence Enterprise Edition"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Data Integrator Version 12.2.1.3.0",
                    "product": {
                      "name": "Oracle Data Integrator Version 12.2.1.3.0",
                      "product_id": "P-2196V-12.2.1.3.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Data Integrator Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Data Integrator Version 12.2.1.4.0",
                      "product_id": "P-2196V-12.2.1.4.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Data Integrator"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Outside In Technology Version 8.5.5",
                    "product": {
                      "name": "Oracle Outside In Technology Version 8.5.5",
                      "product_id": "P-2276V-8.5.5"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Outside In Technology Version 8.5.6",
                    "product": {
                      "name": "Oracle Outside In Technology Version 8.5.6",
                      "product_id": "P-2276V-8.5.6"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Outside In Technology"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Coherence Version 12.2.1.3.0",
                    "product": {
                      "name": "Oracle Coherence Version 12.2.1.3.0",
                      "product_id": "P-2545V-12.2.1.3.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Coherence Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Coherence Version 12.2.1.4.0",
                      "product_id": "P-2545V-12.2.1.4.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Coherence Version 14.1.1.0.0",
                    "product": {
                      "name": "Oracle Coherence Version 14.1.1.0.0",
                      "product_id": "P-2545V-14.1.1.0.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Coherence"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Middleware Common Libraries and Tools Version 12.2.1.3.0",
                    "product": {
                      "name": "Middleware Common Libraries and Tools Version 12.2.1.3.0",
                      "product_id": "P-4647V-12.2.1.3.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Middleware Common Libraries and Tools Version 12.2.1.4.0",
                    "product": {
                      "name": "Middleware Common Libraries and Tools Version 12.2.1.4.0",
                      "product_id": "P-4647V-12.2.1.4.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Middleware Common Libraries and Tools Version 14.1.1.0.0",
                    "product": {
                      "name": "Middleware Common Libraries and Tools Version 14.1.1.0.0",
                      "product_id": "P-4647V-14.1.1.0.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Middleware Common Libraries and Tools"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle WebLogic Server Version 12.2.1.3.0",
                    "product": {
                      "name": "Oracle WebLogic Server Version 12.2.1.3.0",
                      "product_id": "P-5242V-12.2.1.3.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle WebLogic Server Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle WebLogic Server Version 12.2.1.4.0",
                      "product_id": "P-5242V-12.2.1.4.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle WebLogic Server Version 14.1.1.0.0",
                    "product": {
                      "name": "Oracle WebLogic Server Version 14.1.1.0.0",
                      "product_id": "P-5242V-14.1.1.0.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle WebLogic Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Business Process Management Suite Version 12.2.1.3.0",
                    "product": {
                      "name": "Oracle Business Process Management Suite Version 12.2.1.3.0",
                      "product_id": "P-5325V-12.2.1.3.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Business Process Management Suite Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Business Process Management Suite Version 12.2.1.4.0",
                      "product_id": "P-5325V-12.2.1.4.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Business Process Management Suite"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Tuxedo Version 12.2.2.0.0",
                    "product": {
                      "name": "Oracle Tuxedo Version 12.2.2.0.0",
                      "product_id": "P-5433V-12.2.2.0.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Tuxedo"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle WebCenter Sites Version 12.2.1.3.0",
                    "product": {
                      "name": "Oracle WebCenter Sites Version 12.2.1.3.0",
                      "product_id": "P-9617V-12.2.1.3.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle WebCenter Sites Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle WebCenter Sites Version 12.2.1.4.0",
                      "product_id": "P-9617V-12.2.1.4.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle WebCenter Sites Version All Supported Versions",
                    "product": {
                      "name": "Oracle WebCenter Sites Version All Supported Versions",
                      "product_id": "P-9617V-All Supported Versions"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle WebCenter Sites"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Managed File Transfer Version 12.2.1.3.0",
                    "product": {
                      "name": "Oracle Managed File Transfer Version 12.2.1.3.0",
                      "product_id": "P-10198V-12.2.1.3.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Managed File Transfer Version 12.2.1.4.0",
                    "product": {
                      "name": "Oracle Managed File Transfer Version 12.2.1.4.0",
                      "product_id": "P-10198V-12.2.1.4.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Managed File Transfer"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Helidon Version 1.4.10",
                    "product": {
                      "name": "Helidon Version 1.4.10",
                      "product_id": "P-13972V-1.4.10"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Helidon Version 1.4.7",
                    "product": {
                      "name": "Helidon Version 1.4.7",
                      "product_id": "P-13972V-1.4.7"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Helidon Version 2.0.0-RC1",
                    "product": {
                      "name": "Helidon Version 2.0.0-RC1",
                      "product_id": "P-13972V-2.0.0-RC1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Helidon Version 2.2.0",
                    "product": {
                      "name": "Helidon Version 2.2.0",
                      "product_id": "P-13972V-2.2.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Helidon Version 2.4.0",
                    "product": {
                      "name": "Helidon Version 2.4.0",
                      "product_id": "P-13972V-2.4.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Helidon"
              }
            ],
            "category": "product_family",
            "name": "Oracle Fusion Middleware"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Global Lifecycle Management OPatch Version All Supported Versions",
                    "product": {
                      "name": "Oracle Global Lifecycle Management OPatch Version All Supported Versions",
                      "product_id": "P-12753V-All Supported Versions"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Global Lifecycle Management OPatch"
              }
            ],
            "category": "product_family",
            "name": "Oracle Global Lifecycle Management"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Version Prior to 12.3.0.1.2",
                    "product": {
                      "name": "Oracle GoldenGate Version Prior to 12.3.0.1.2",
                      "product_id": "P-5757V-Prior to 12.3.0.1.2"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Version Prior to 23.1",
                    "product": {
                      "name": "Oracle GoldenGate Version Prior to 23.1",
                      "product_id": "P-5757V-Prior to 23.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GoldenGate"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle GoldenGate Application Adapters Version All Supported Versions",
                    "product": {
                      "name": "Oracle GoldenGate Application Adapters Version All Supported Versions",
                      "product_id": "P-5760V-All Supported Versions"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle GoldenGate Application Adapters Version Prior to 23.1",
                    "product": {
                      "name": "Oracle GoldenGate Application Adapters Version Prior to 23.1",
                      "product_id": "P-5760V-Prior to 23.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle GoldenGate Application Adapters"
              }
            ],
            "category": "product_family",
            "name": "Oracle GoldenGate"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Health Sciences InForm Version 6.2.1.1",
                    "product": {
                      "name": "Oracle Health Sciences InForm Version 6.2.1.1",
                      "product_id": "P-9636V-6.2.1.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Health Sciences InForm Version 6.3.2.1",
                    "product": {
                      "name": "Oracle Health Sciences InForm Version 6.3.2.1",
                      "product_id": "P-9636V-6.3.2.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Health Sciences InForm Version 7.0.0.0",
                    "product": {
                      "name": "Oracle Health Sciences InForm Version 7.0.0.0",
                      "product_id": "P-9636V-7.0.0.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Health Sciences InForm"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Health Sciences InForm Publisher Version 6.2.1.0",
                    "product": {
                      "name": "Oracle Health Sciences InForm Publisher Version 6.2.1.0",
                      "product_id": "P-9638V-6.2.1.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Health Sciences InForm Publisher Version 6.3.1.1",
                    "product": {
                      "name": "Oracle Health Sciences InForm Publisher Version 6.3.1.1",
                      "product_id": "P-9638V-6.3.1.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Health Sciences InForm Publisher"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Health Sciences Empirica Signal Version 9.1.0.6",
                    "product": {
                      "name": "Oracle Health Sciences Empirica Signal Version 9.1.0.6",
                      "product_id": "P-9646V-9.1.0.6"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Health Sciences Empirica Signal Version 9.2.0.0",
                    "product": {
                      "name": "Oracle Health Sciences Empirica Signal Version 9.2.0.0",
                      "product_id": "P-9646V-9.2.0.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Health Sciences Empirica Signal"
              }
            ],
            "category": "product_family",
            "name": "Oracle Health Sciences Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Healthcare Master Person Index Version 5.0.1",
                    "product": {
                      "name": "Oracle Healthcare Master Person Index Version 5.0.1",
                      "product_id": "P-8575V-5.0.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Healthcare Master Person Index"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Healthcare Data Repository Version 8.1.0",
                    "product": {
                      "name": "Oracle Healthcare Data Repository Version 8.1.0",
                      "product_id": "P-9161V-8.1.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Healthcare Data Repository Version 8.1.1",
                    "product": {
                      "name": "Oracle Healthcare Data Repository Version 8.1.1",
                      "product_id": "P-9161V-8.1.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Healthcare Data Repository"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Health Sciences Information Manager Version 3.0.1-3.0.4",
                    "product": {
                      "name": "Oracle Health Sciences Information Manager Version 3.0.1-3.0.4",
                      "product_id": "P-9177V-3.0.1-3.0.4"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Health Sciences Information Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Healthcare Translational Research Version 4.1.0",
                    "product": {
                      "name": "Oracle Healthcare Translational Research Version 4.1.0",
                      "product_id": "P-9427V-4.1.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Healthcare Translational Research Version 4.1.1",
                    "product": {
                      "name": "Oracle Healthcare Translational Research Version 4.1.1",
                      "product_id": "P-9427V-4.1.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Healthcare Translational Research"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Healthcare Foundation Version 7.3.0.1-7.3.0.4",
                    "product": {
                      "name": "Oracle Healthcare Foundation Version 7.3.0.1-7.3.0.4",
                      "product_id": "P-12950V-7.3.0.1-7.3.0.4"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Healthcare Foundation"
              }
            ],
            "category": "product_family",
            "name": "Oracle HealthCare Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hospitality Suite8 Version 8.10.2",
                    "product": {
                      "name": "Oracle Hospitality Suite8 Version 8.10.2",
                      "product_id": "P-12619V-8.10.2"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Hospitality Suite8 Version 8.11.0-8.14.0",
                    "product": {
                      "name": "Oracle Hospitality Suite8 Version 8.11.0-8.14.0",
                      "product_id": "P-12619V-8.11.0-8.14.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Hospitality Suite8 Version 8.13.0",
                    "product": {
                      "name": "Oracle Hospitality Suite8 Version 8.13.0",
                      "product_id": "P-12619V-8.13.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Hospitality Suite8 Version 8.14.0",
                    "product": {
                      "name": "Oracle Hospitality Suite8 Version 8.14.0",
                      "product_id": "P-12619V-8.14.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hospitality Suite8"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Payment Interface Version 19.1",
                    "product": {
                      "name": "Oracle Payment Interface Version 19.1",
                      "product_id": "P-13173V-19.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Payment Interface Version 20.3",
                    "product": {
                      "name": "Oracle Payment Interface Version 20.3",
                      "product_id": "P-13173V-20.3"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Payment Interface"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Hospitality Token Proxy Service Version 19.2",
                    "product": {
                      "name": "Oracle Hospitality Token Proxy Service Version 19.2",
                      "product_id": "P-13387V-19.2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hospitality Token Proxy Service"
              }
            ],
            "category": "product_family",
            "name": "Oracle Hospitality Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Hyperion BI+ Version Prior to 11.2.8.0",
                    "product": {
                      "name": "Oracle Hyperion BI+ Version Prior to 11.2.8.0",
                      "product_id": "P-4361V-Prior to 11.2.8.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion BI+"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Hyperion Data Relationship Management Version Prior to 11.2.8.0",
                    "product": {
                      "name": "Oracle Hyperion Data Relationship Management Version Prior to 11.2.8.0",
                      "product_id": "P-4375V-Prior to 11.2.8.0"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Hyperion Data Relationship Management Version Prior to 11.2.9.0",
                    "product": {
                      "name": "Oracle Hyperion Data Relationship Management Version Prior to 11.2.9.0",
                      "product_id": "P-4375V-Prior to 11.2.9.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Data Relationship Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Hyperion Financial Management Version Prior to 11.2.8.0",
                    "product": {
                      "name": "Oracle Hyperion Financial Management Version Prior to 11.2.8.0",
                      "product_id": "P-4390V-Prior to 11.2.8.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Financial Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Hyperion Infrastructure Technology Version Prior to 11.2.8.0",
                    "product": {
                      "name": "Oracle Hyperion Infrastructure Technology Version Prior to 11.2.8.0",
                      "product_id": "P-4392V-Prior to 11.2.8.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Infrastructure Technology"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Hyperion Planning Version Prior to 11.2.8.0",
                    "product": {
                      "name": "Oracle Hyperion Planning Version Prior to 11.2.8.0",
                      "product_id": "P-4402V-Prior to 11.2.8.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Planning"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Hyperion Profitability and Cost Management Version Prior to 11.2.8.0",
                    "product": {
                      "name": "Oracle Hyperion Profitability and Cost Management Version Prior to 11.2.8.0",
                      "product_id": "P-4403V-Prior to 11.2.8.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Profitability and Cost Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Hyperion Calculation Manager Version Prior to 11.2.8.0",
                    "product": {
                      "name": "Oracle Hyperion Calculation Manager Version Prior to 11.2.8.0",
                      "product_id": "P-5685V-Prior to 11.2.8.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Calculation Manager"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Hyperion Tax Provision Version Prior to 11.2.8.0",
                    "product": {
                      "name": "Oracle Hyperion Tax Provision Version Prior to 11.2.8.0",
                      "product_id": "P-10505V-Prior to 11.2.8.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Hyperion Tax Provision"
              }
            ],
            "category": "product_family",
            "name": "Oracle Hyperion"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Insurance Policy Administration Version 11.0.2",
                    "product": {
                      "name": "Oracle Insurance Policy Administration Version 11.0.2",
                      "product_id": "P-5279V-11.0.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Insurance Policy Administration Version 11.1.0",
                    "product": {
                      "name": "Oracle Insurance Policy Administration Version 11.1.0",
                      "product_id": "P-5279V-11.1.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Insurance Policy Administration Version 11.2.8",
                    "product": {
                      "name": "Oracle Insurance Policy Administration Version 11.2.8",
                      "product_id": "P-5279V-11.2.8"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Insurance Policy Administration Version 11.3.0",
                    "product": {
                      "name": "Oracle Insurance Policy Administration Version 11.3.0",
                      "product_id": "P-5279V-11.3.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Insurance Policy Administration Version 11.3.1",
                    "product": {
                      "name": "Oracle Insurance Policy Administration Version 11.3.1",
                      "product_id": "P-5279V-11.3.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Insurance Policy Administration"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Insurance Rules Palette Version 11.0.2",
                    "product": {
                      "name": "Oracle Insurance Rules Palette Version 11.0.2",
                      "product_id": "P-5288V-11.0.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Insurance Rules Palette Version 11.1.0",
                    "product": {
                      "name": "Oracle Insurance Rules Palette Version 11.1.0",
                      "product_id": "P-5288V-11.1.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Insurance Rules Palette Version 11.2.8",
                    "product": {
                      "name": "Oracle Insurance Rules Palette Version 11.2.8",
                      "product_id": "P-5288V-11.2.8"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Insurance Rules Palette Version 11.3.0",
                    "product": {
                      "name": "Oracle Insurance Rules Palette Version 11.3.0",
                      "product_id": "P-5288V-11.3.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Insurance Rules Palette Version 11.3.1",
                    "product": {
                      "name": "Oracle Insurance Rules Palette Version 11.3.1",
                      "product_id": "P-5288V-11.3.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Insurance Rules Palette"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Documaker Version 12.6.0",
                    "product": {
                      "name": "Oracle Documaker Version 12.6.0",
                      "product_id": "P-5477V-12.6.0"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Documaker Version 12.6.2-12.6.4",
                    "product": {
                      "name": "Oracle Documaker Version 12.6.2-12.6.4",
                      "product_id": "P-5477V-12.6.2-12.6.4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Documaker Version 12.7.0",
                    "product": {
                      "name": "Oracle Documaker Version 12.7.0",
                      "product_id": "P-5477V-12.7.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Documaker"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Insurance Insbridge Rating and Underwriting Version 5.2.0",
                    "product": {
                      "name": "Oracle Insurance Insbridge Rating and Underwriting Version 5.2.0",
                      "product_id": "P-5484V-5.2.0"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Insurance Insbridge Rating and Underwriting Version 5.4.0-5.6.0",
                    "product": {
                      "name": "Oracle Insurance Insbridge Rating and Underwriting Version 5.4.0-5.6.0",
                      "product_id": "P-5484V-5.4.0-5.6.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Insurance Insbridge Rating and Underwriting Version 5.6.1",
                    "product": {
                      "name": "Oracle Insurance Insbridge Rating and Underwriting Version 5.6.1",
                      "product_id": "P-5484V-5.6.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Insurance Insbridge Rating and Underwriting"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Insurance Data Gateway Version 1.0.1",
                    "product": {
                      "name": "Oracle Insurance Data Gateway Version 1.0.1",
                      "product_id": "P-13628V-1.0.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Insurance Data Gateway"
              }
            ],
            "category": "product_family",
            "name": "Oracle Insurance Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "JD Edwards EnterpriseOne Tools Version Prior to 9.2.6.0",
                    "product": {
                      "name": "JD Edwards EnterpriseOne Tools Version Prior to 9.2.6.0",
                      "product_id": "P-4781V-Prior to 9.2.6.0"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "JD Edwards EnterpriseOne Tools Version Prior to 9.2.6.1",
                    "product": {
                      "name": "JD Edwards EnterpriseOne Tools Version Prior to 9.2.6.1",
                      "product_id": "P-4781V-Prior to 9.2.6.1"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "JD Edwards EnterpriseOne Tools(Database and Comm SEC) Version Prior to 9.2.6.3",
                    "product": {
                      "name": "JD Edwards EnterpriseOne Tools(Database and Comm SEC) Version Prior to 9.2.6.3",
                      "product_id": "P-4781(Database and Comm SEC)V-Prior to 9.2.6.3"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "JD Edwards EnterpriseOne Tools(Monitoring and Diagnostics SEC) Version Prior to 9.2.6.3",
                    "product": {
                      "name": "JD Edwards EnterpriseOne Tools(Monitoring and Diagnostics SEC) Version Prior to 9.2.6.3",
                      "product_id": "P-4781(Monitoring and Diagnostics SEC)V-Prior to 9.2.6.3"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "JD Edwards EnterpriseOne Tools(Web Runtime) Version Prior to 9.2.6.3",
                    "product": {
                      "name": "JD Edwards EnterpriseOne Tools(Web Runtime) Version Prior to 9.2.6.3",
                      "product_id": "P-4781(Web Runtime)V-Prior to 9.2.6.3"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "JD Edwards EnterpriseOne Tools Version Prior to 9.2.6.3",
                    "product": {
                      "name": "JD Edwards EnterpriseOne Tools Version Prior to 9.2.6.3",
                      "product_id": "P-4781V-Prior to 9.2.6.3"
                    }
                  }
                ],
                "category": "product_name",
                "name": "JD Edwards EnterpriseOne Tools"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "JD Edwards World Security Version A9.4",
                    "product": {
                      "name": "JD Edwards World Security Version A9.4",
                      "product_id": "P-4839V-A9.4"
                    }
                  }
                ],
                "category": "product_name",
                "name": "JD Edwards World Security"
              }
            ],
            "category": "product_family",
            "name": "Oracle JD Edwards"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:20.3.5",
                    "product": {
                      "name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:20.3.5",
                      "product_id": "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:21.3.1",
                    "product": {
                      "name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:21.3.1",
                      "product_id": "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:22.0.0.2",
                    "product": {
                      "name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:22.0.0.2",
                      "product_id": "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version Oracle Java SE:11.0.14",
                    "product": {
                      "name": "Oracle Java SE Version Oracle Java SE:11.0.14",
                      "product_id": "P-856V-Oracle Java SE:11.0.14"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version Oracle Java SE:17.0.2",
                    "product": {
                      "name": "Oracle Java SE Version Oracle Java SE:17.0.2",
                      "product_id": "P-856V-Oracle Java SE:17.0.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version Oracle Java SE:18",
                    "product": {
                      "name": "Oracle Java SE Version Oracle Java SE:18",
                      "product_id": "P-856V-Oracle Java SE:18"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version Oracle Java SE:7u331",
                    "product": {
                      "name": "Oracle Java SE Version Oracle Java SE:7u331",
                      "product_id": "P-856V-Oracle Java SE:7u331"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Java SE Version Oracle Java SE:8u321",
                    "product": {
                      "name": "Oracle Java SE Version Oracle Java SE:8u321",
                      "product_id": "P-856V-Oracle Java SE:8u321"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Java SE"
              }
            ],
            "category": "product_family",
            "name": "Oracle Java SE"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Workbench Version 8.0.28 and prior",
                    "product": {
                      "name": "MySQL Workbench Version 8.0.28 and prior",
                      "product_id": "P-4627V-8.0.28 and prior"
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Workbench"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server Version 5.7.37 and prior",
                    "product": {
                      "name": "MySQL Server Version 5.7.37 and prior",
                      "product_id": "P-8478V-5.7.37 and prior"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Server Version 8.0.28 and prior",
                    "product": {
                      "name": "MySQL Server Version 8.0.28 and prior",
                      "product_id": "P-8478V-8.0.28 and prior"
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Server"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 7.4.35 and prior",
                    "product": {
                      "name": "MySQL Cluster Version 7.4.35 and prior",
                      "product_id": "P-8479V-7.4.35 and prior"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 7.5.25 and prior",
                    "product": {
                      "name": "MySQL Cluster Version 7.5.25 and prior",
                      "product_id": "P-8479V-7.5.25 and prior"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 7.6.21 and prior",
                    "product": {
                      "name": "MySQL Cluster Version 7.6.21 and prior",
                      "product_id": "P-8479V-7.6.21 and prior"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Cluster Version 8.0.28 and prior",
                    "product": {
                      "name": "MySQL Cluster Version 8.0.28 and prior",
                      "product_id": "P-8479V-8.0.28 and prior"
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Cluster"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Enterprise Monitor Version 8.0.29 and prior",
                    "product": {
                      "name": "MySQL Enterprise Monitor Version 8.0.29 and prior",
                      "product_id": "P-8480V-8.0.29 and prior"
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Enterprise Monitor"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "MySQL Connectors(Connector/C++) Version 8.0.28 and prior",
                    "product": {
                      "name": "MySQL Connectors(Connector/C++) Version 8.0.28 and prior",
                      "product_id": "P-8576(Connector/C++)V-8.0.28 and prior"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "MySQL Connectors(Connector/ODBC) Version 8.0.28 and prior",
                    "product": {
                      "name": "MySQL Connectors(Connector/ODBC) Version 8.0.28 and prior",
                      "product_id": "P-8576(Connector/ODBC)V-8.0.28 and prior"
                    }
                  }
                ],
                "category": "product_name",
                "name": "MySQL Connectors"
              }
            ],
            "category": "product_family",
            "name": "Oracle MySQL"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle NoSQL Database Version All Supported Versions",
                    "product": {
                      "name": "Oracle NoSQL Database Version All Supported Versions",
                      "product_id": "P-13373V-All Supported Versions"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle NoSQL Database"
              }
            ],
            "category": "product_family",
            "name": "Oracle NoSQL Database"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise FIN Cash Management Version 9.2",
                    "product": {
                      "name": "PeopleSoft Enterprise FIN Cash Management Version 9.2",
                      "product_id": "P-4979V-9.2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "PeopleSoft Enterprise FIN Cash Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise PeopleTools Version 8.58",
                    "product": {
                      "name": "PeopleSoft Enterprise PeopleTools Version 8.58",
                      "product_id": "P-5085V-8.58"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise PeopleTools Version 8.59",
                    "product": {
                      "name": "PeopleSoft Enterprise PeopleTools Version 8.59",
                      "product_id": "P-5085V-8.59"
                    }
                  }
                ],
                "category": "product_name",
                "name": "PeopleSoft Enterprise PeopleTools"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise PRTL Interaction Hub Version 9.1",
                    "product": {
                      "name": "PeopleSoft Enterprise PRTL Interaction Hub Version 9.1",
                      "product_id": "P-5090V-9.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "PeopleSoft Enterprise PRTL Interaction Hub"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "PeopleSoft Enterprise CS Academic Advisement Version 9.2",
                    "product": {
                      "name": "PeopleSoft Enterprise CS Academic Advisement Version 9.2",
                      "product_id": "P-5181V-9.2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "PeopleSoft Enterprise CS Academic Advisement"
              }
            ],
            "category": "product_family",
            "name": "Oracle PeopleSoft"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle REST Data Services Version Prior to 21.2",
                    "product": {
                      "name": "Oracle REST Data Services Version Prior to 21.2",
                      "product_id": "P-9456V-Prior to 21.2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle REST Data Services"
              }
            ],
            "category": "product_family",
            "name": "Oracle REST Data Services"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Extract Transform and Load Version 13.2.8",
                    "product": {
                      "name": "Oracle Retail Extract Transform and Load Version 13.2.8",
                      "product_id": "P-1803V-13.2.8"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Extract Transform and Load"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Integration Bus Version 14.1.3.2",
                    "product": {
                      "name": "Oracle Retail Integration Bus Version 14.1.3.2",
                      "product_id": "P-1807V-14.1.3.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Integration Bus Version 15.0.3.1",
                    "product": {
                      "name": "Oracle Retail Integration Bus Version 15.0.3.1",
                      "product_id": "P-1807V-15.0.3.1"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Retail Integration Bus Version 16.0.1-16.0.3",
                    "product": {
                      "name": "Oracle Retail Integration Bus Version 16.0.1-16.0.3",
                      "product_id": "P-1807V-16.0.1-16.0.3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Integration Bus Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Integration Bus Version 16.0.3",
                      "product_id": "P-1807V-16.0.3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Integration Bus Version 19.0.0",
                    "product": {
                      "name": "Oracle Retail Integration Bus Version 19.0.0",
                      "product_id": "P-1807V-19.0.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Integration Bus Version 19.0.1",
                    "product": {
                      "name": "Oracle Retail Integration Bus Version 19.0.1",
                      "product_id": "P-1807V-19.0.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Integration Bus"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Invoice Matching Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Invoice Matching Version 16.0.3",
                      "product_id": "P-1810V-16.0.3"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Invoice Matching"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Merchandising System Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Merchandising System Version 16.0.3",
                      "product_id": "P-1816V-16.0.3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Merchandising System Version 19.0.1",
                    "product": {
                      "name": "Oracle Retail Merchandising System Version 19.0.1",
                      "product_id": "P-1816V-19.0.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Merchandising System"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Store Inventory Management Version 14.0.4.13",
                    "product": {
                      "name": "Oracle Retail Store Inventory Management Version 14.0.4.13",
                      "product_id": "P-1838V-14.0.4.13"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Store Inventory Management Version 14.1.3.14",
                    "product": {
                      "name": "Oracle Retail Store Inventory Management Version 14.1.3.14",
                      "product_id": "P-1838V-14.1.3.14"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Store Inventory Management Version 14.1.3.5",
                    "product": {
                      "name": "Oracle Retail Store Inventory Management Version 14.1.3.5",
                      "product_id": "P-1838V-14.1.3.5"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Store Inventory Management Version 15.0.3.3",
                    "product": {
                      "name": "Oracle Retail Store Inventory Management Version 15.0.3.3",
                      "product_id": "P-1838V-15.0.3.3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Store Inventory Management Version 15.0.3.8",
                    "product": {
                      "name": "Oracle Retail Store Inventory Management Version 15.0.3.8",
                      "product_id": "P-1838V-15.0.3.8"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Store Inventory Management Version 16.0.3.7",
                    "product": {
                      "name": "Oracle Retail Store Inventory Management Version 16.0.3.7",
                      "product_id": "P-1838V-16.0.3.7"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Store Inventory Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Customer Insights Version 15.0.2",
                    "product": {
                      "name": "Oracle Retail Customer Insights Version 15.0.2",
                      "product_id": "P-10263V-15.0.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Customer Insights Version 16.0.2",
                    "product": {
                      "name": "Oracle Retail Customer Insights Version 16.0.2",
                      "product_id": "P-10263V-16.0.2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Customer Insights"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Financial Integration Version 14.1.3.2",
                    "product": {
                      "name": "Oracle Retail Financial Integration Version 14.1.3.2",
                      "product_id": "P-10722V-14.1.3.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Financial Integration Version 15.0.3.1",
                    "product": {
                      "name": "Oracle Retail Financial Integration Version 15.0.3.1",
                      "product_id": "P-10722V-15.0.3.1"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Retail Financial Integration Version 16.0.1-16.0.3",
                    "product": {
                      "name": "Oracle Retail Financial Integration Version 16.0.1-16.0.3",
                      "product_id": "P-10722V-16.0.1-16.0.3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Financial Integration Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Financial Integration Version 16.0.3",
                      "product_id": "P-10722V-16.0.3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Financial Integration Version 19.0.0",
                    "product": {
                      "name": "Oracle Retail Financial Integration Version 19.0.0",
                      "product_id": "P-10722V-19.0.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Financial Integration Version 19.0.1",
                    "product": {
                      "name": "Oracle Retail Financial Integration Version 19.0.1",
                      "product_id": "P-10722V-19.0.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Financial Integration"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Service Backbone Version 14.1.3.2",
                    "product": {
                      "name": "Oracle Retail Service Backbone Version 14.1.3.2",
                      "product_id": "P-10867V-14.1.3.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Service Backbone Version 15.0.3.1",
                    "product": {
                      "name": "Oracle Retail Service Backbone Version 15.0.3.1",
                      "product_id": "P-10867V-15.0.3.1"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle Retail Service Backbone Version 16.0.1-16.0.3",
                    "product": {
                      "name": "Oracle Retail Service Backbone Version 16.0.1-16.0.3",
                      "product_id": "P-10867V-16.0.1-16.0.3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Service Backbone Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Service Backbone Version 16.0.3",
                      "product_id": "P-10867V-16.0.3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Service Backbone Version 19.0.0",
                    "product": {
                      "name": "Oracle Retail Service Backbone Version 19.0.0",
                      "product_id": "P-10867V-19.0.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Service Backbone Version 19.0.1",
                    "product": {
                      "name": "Oracle Retail Service Backbone Version 19.0.1",
                      "product_id": "P-10867V-19.0.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Service Backbone"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 16.0.6",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 16.0.6",
                      "product_id": "P-11513V-16.0.6"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 17.0.4",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 17.0.4",
                      "product_id": "P-11513V-17.0.4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 18.0.3",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 18.0.3",
                      "product_id": "P-11513V-18.0.3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 19.0.2",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 19.0.2",
                      "product_id": "P-11513V-19.0.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 20.0.1",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 20.0.1",
                      "product_id": "P-11513V-20.0.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Point of Service Version 21.0.0",
                    "product": {
                      "name": "Oracle Retail Xstore Point of Service Version 21.0.0",
                      "product_id": "P-11513V-21.0.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Xstore Point of Service"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail EFTLink Version 17.0.2",
                    "product": {
                      "name": "Oracle Retail EFTLink Version 17.0.2",
                      "product_id": "P-11516V-17.0.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail EFTLink Version 18.0.1",
                    "product": {
                      "name": "Oracle Retail EFTLink Version 18.0.1",
                      "product_id": "P-11516V-18.0.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail EFTLink Version 19.0.1",
                    "product": {
                      "name": "Oracle Retail EFTLink Version 19.0.1",
                      "product_id": "P-11516V-19.0.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail EFTLink Version 20.0.1",
                    "product": {
                      "name": "Oracle Retail EFTLink Version 20.0.1",
                      "product_id": "P-11516V-20.0.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail EFTLink Version 21.0.0",
                    "product": {
                      "name": "Oracle Retail EFTLink Version 21.0.0",
                      "product_id": "P-11516V-21.0.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail EFTLink"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Data Extractor for Merchandising Version 15.0.2",
                    "product": {
                      "name": "Oracle Retail Data Extractor for Merchandising Version 15.0.2",
                      "product_id": "P-12936V-15.0.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Data Extractor for Merchandising Version 16.0.2",
                    "product": {
                      "name": "Oracle Retail Data Extractor for Merchandising Version 16.0.2",
                      "product_id": "P-12936V-16.0.2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Data Extractor for Merchandising"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Bulk Data Integration Version 16.0.3",
                    "product": {
                      "name": "Oracle Retail Bulk Data Integration Version 16.0.3",
                      "product_id": "P-12968V-16.0.3"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Bulk Data Integration"
              },
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Retail Customer Management and Segmentation Foundation Version 17.0-19.0",
                    "product": {
                      "name": "Oracle Retail Customer Management and Segmentation Foundation Version 17.0-19.0",
                      "product_id": "P-13388V-17.0-19.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Customer Management and Segmentation Foundation Version 18.0",
                    "product": {
                      "name": "Oracle Retail Customer Management and Segmentation Foundation Version 18.0",
                      "product_id": "P-13388V-18.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Customer Management and Segmentation Foundation Version 19.0",
                    "product": {
                      "name": "Oracle Retail Customer Management and Segmentation Foundation Version 19.0",
                      "product_id": "P-13388V-19.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Customer Management and Segmentation Foundation"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Office Cloud Service Version 16.0.6",
                    "product": {
                      "name": "Oracle Retail Xstore Office Cloud Service Version 16.0.6",
                      "product_id": "P-13551V-16.0.6"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Office Cloud Service Version 17.0.4",
                    "product": {
                      "name": "Oracle Retail Xstore Office Cloud Service Version 17.0.4",
                      "product_id": "P-13551V-17.0.4"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Office Cloud Service Version 18.0.3",
                    "product": {
                      "name": "Oracle Retail Xstore Office Cloud Service Version 18.0.3",
                      "product_id": "P-13551V-18.0.3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Office Cloud Service Version 19.0.2",
                    "product": {
                      "name": "Oracle Retail Xstore Office Cloud Service Version 19.0.2",
                      "product_id": "P-13551V-19.0.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Retail Xstore Office Cloud Service Version 20.0.1",
                    "product": {
                      "name": "Oracle Retail Xstore Office Cloud Service Version 20.0.1",
                      "product_id": "P-13551V-20.0.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Retail Xstore Office Cloud Service"
              }
            ],
            "category": "product_family",
            "name": "Oracle Retail Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle SQL Developer Version 21c",
                    "product": {
                      "name": "Oracle SQL Developer Version 21c",
                      "product_id": "P-1875V-21c"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle SQL Developer Version Database: 19c",
                    "product": {
                      "name": "Oracle SQL Developer Version Database: 19c",
                      "product_id": "P-1875V-Database: 19c"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle SQL Developer Version Prior to 21.4.2",
                    "product": {
                      "name": "Oracle SQL Developer Version Prior to 21.4.2",
                      "product_id": "P-1875V-Prior to 21.4.2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle SQL Developer"
              }
            ],
            "category": "product_family",
            "name": "Oracle SQL Developer"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Secure Backup Version All Supported Versions",
                    "product": {
                      "name": "Oracle Secure Backup Version All Supported Versions",
                      "product_id": "P-1522V-All Supported Versions"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Secure Backup"
              }
            ],
            "category": "product_family",
            "name": "Oracle Secure Backup"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Advanced Supply Chain Planning Version 12.1",
                    "product": {
                      "name": "Oracle Advanced Supply Chain Planning Version 12.1",
                      "product_id": "P-719V-12.1"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Advanced Supply Chain Planning Version 12.2",
                    "product": {
                      "name": "Oracle Advanced Supply Chain Planning Version 12.2",
                      "product_id": "P-719V-12.2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Advanced Supply Chain Planning"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Transportation Management Version 6.4.3",
                    "product": {
                      "name": "Oracle Transportation Management Version 6.4.3",
                      "product_id": "P-1991V-6.4.3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Transportation Management Version 6.5.1",
                    "product": {
                      "name": "Oracle Transportation Management Version 6.5.1",
                      "product_id": "P-1991V-6.5.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Transportation Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Autovue for Agile Product Lifecycle Management Version 21.0.2",
                    "product": {
                      "name": "Oracle Autovue for Agile Product Lifecycle Management Version 21.0.2",
                      "product_id": "P-4434V-21.0.2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Autovue for Agile Product Lifecycle Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Agile Engineering Data Management Version 6.2.1.0",
                    "product": {
                      "name": "Oracle Agile Engineering Data Management Version 6.2.1.0",
                      "product_id": "P-4436V-6.2.1.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Agile Engineering Data Management"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Agile PLM MCAD Connector Version 3.6",
                    "product": {
                      "name": "Oracle Agile PLM MCAD Connector Version 3.6",
                      "product_id": "P-4440V-3.6"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Agile PLM MCAD Connector"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Agile PLM Version 9.3.6",
                    "product": {
                      "name": "Oracle Agile PLM Version 9.3.6",
                      "product_id": "P-4461V-9.3.6"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Agile PLM"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Product Lifecycle Analytics Version 3.6.1.0",
                    "product": {
                      "name": "Oracle Product Lifecycle Analytics Version 3.6.1.0",
                      "product_id": "P-9387V-3.6.1.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Product Lifecycle Analytics"
              }
            ],
            "category": "product_family",
            "name": "Oracle Supply Chain"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "OSS Support Tools Version 18.3",
                    "product": {
                      "name": "OSS Support Tools Version 18.3",
                      "product_id": "P-1330V-18.3"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "OSS Support Tools Version 2.12.42",
                    "product": {
                      "name": "OSS Support Tools Version 2.12.42",
                      "product_id": "P-1330V-2.12.42"
                    }
                  }
                ],
                "category": "product_name",
                "name": "OSS Support Tools"
              }
            ],
            "category": "product_family",
            "name": "Oracle Support Tools"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Ethernet Switch TOR-72 Version 1.2.2",
                    "product": {
                      "name": "Oracle Ethernet Switch TOR-72 Version 1.2.2",
                      "product_id": "P-9889V-1.2.2"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Ethernet Switch TOR-72"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Solaris Cluster Version 4",
                    "product": {
                      "name": "Oracle Solaris Cluster Version 4",
                      "product_id": "P-10005V-4"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Solaris Cluster"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Solaris Version 11",
                    "product": {
                      "name": "Oracle Solaris Version 11",
                      "product_id": "P-10006V-11"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Solaris"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle ZFS Storage Appliance Kit Version 8.8",
                    "product": {
                      "name": "Oracle ZFS Storage Appliance Kit Version 8.8",
                      "product_id": "P-10026V-8.8"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle ZFS Storage Appliance Kit"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle StorageTek Tape Analytics (STA) Version 2.4",
                    "product": {
                      "name": "Oracle StorageTek Tape Analytics (STA) Version 2.4",
                      "product_id": "P-10085V-2.4"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle StorageTek Tape Analytics (STA)"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle StorageTek ACSLS Version 8.5.1",
                    "product": {
                      "name": "Oracle StorageTek ACSLS Version 8.5.1",
                      "product_id": "P-10088V-8.5.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle StorageTek ACSLS"
              }
            ],
            "category": "product_family",
            "name": "Oracle Systems"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Taleo Platform Version Prior to 22.1",
                    "product": {
                      "name": "Oracle Taleo Platform Version Prior to 22.1",
                      "product_id": "P-9830V-Prior to 22.1"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Taleo Platform"
              }
            ],
            "category": "product_family",
            "name": "Oracle Taleo"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle Utilities Framework Version 4.3.0.1.0-4.3.0.6.0",
                    "product": {
                      "name": "Oracle Utilities Framework Version 4.3.0.1.0-4.3.0.6.0",
                      "product_id": "P-2245V-4.3.0.1.0-4.3.0.6.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Framework Version 4.4.0.0.0",
                    "product": {
                      "name": "Oracle Utilities Framework Version 4.4.0.0.0",
                      "product_id": "P-2245V-4.4.0.0.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Framework Version 4.4.0.2.0",
                    "product": {
                      "name": "Oracle Utilities Framework Version 4.4.0.2.0",
                      "product_id": "P-2245V-4.4.0.2.0"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle Utilities Framework Version 4.4.0.3.0",
                    "product": {
                      "name": "Oracle Utilities Framework Version 4.4.0.3.0",
                      "product_id": "P-2245V-4.4.0.3.0"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Utilities Framework"
              }
            ],
            "category": "product_family",
            "name": "Oracle Utilities Applications"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version_range",
                    "name": "Oracle VM VirtualBox(Core) Version Prior to 6.1.34",
                    "product": {
                      "name": "Oracle VM VirtualBox(Core) Version Prior to 6.1.34",
                      "product_id": "P-8370(Core)V-Prior to 6.1.34"
                    }
                  },
                  {
                    "category": "product_version_range",
                    "name": "Oracle VM VirtualBox Version Prior to 6.1.34",
                    "product": {
                      "name": "Oracle VM VirtualBox Version Prior to 6.1.34",
                      "product_id": "P-8370V-Prior to 6.1.34"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle VM VirtualBox"
              },
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle Secure Global Desktop Version 5.6",
                    "product": {
                      "name": "Oracle Secure Global Desktop Version 5.6",
                      "product_id": "P-8539V-5.6"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle Secure Global Desktop"
              }
            ],
            "category": "product_family",
            "name": "Oracle Virtualization"
          },
          {
            "branches": [
              {
                "branches": [
                  {
                    "category": "product_version",
                    "name": "Oracle iLearning Version 6.2",
                    "product": {
                      "name": "Oracle iLearning Version 6.2",
                      "product_id": "P-902V-6.2"
                    }
                  },
                  {
                    "category": "product_version",
                    "name": "Oracle iLearning Version 6.3",
                    "product": {
                      "name": "Oracle iLearning Version 6.3",
                      "product_id": "P-902V-6.3"
                    }
                  }
                ],
                "category": "product_name",
                "name": "Oracle iLearning"
              }
            ],
            "category": "product_family",
            "name": "Oracle iLearning"
          }
        ],
        "category": "vendor",
        "name": "Oracle"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2017-1000353",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Automated Test Suite (Jenkins)).   The supported version that is affected is 1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14488V-1.9.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14488V-1.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859046.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14488V-1.9.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2018-11212",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: Oracle Directory Services Manager (libjpeg)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Internet Directory.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Internet Directory. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-355V-12.2.1.3.0",
          "P-355V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-355V-12.2.1.3.0",
            "P-355V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-355V-12.2.1.3.0",
            "P-355V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2018-1285",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Load Testing for Web Apps (Apache log4net)).   The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite.  Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4622V-13.3.0.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4622V-13.3.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844807.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4622V-13.3.0.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2019-0227",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: Oracle Directory Services Mngr (Apache Axis)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Internet Directory executes to compromise Oracle Internet Directory.  Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory.  Note: The patch for CVE-2019-0227 also addresses CVE-2018-2601 for Oracle Internet Directory 12.2.1.4.0. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-355V-12.2.1.3.0",
          "P-355V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-355V-12.2.1.3.0",
            "P-355V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-355V-12.2.1.3.0",
            "P-355V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2019-10086",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Apache Commons BeanUtils)).   The supported version that is affected is Prior to 21.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Blockchain Platform.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Blockchain Platform accessible data as well as  unauthorized read access to a subset of Oracle Blockchain Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Blockchain Platform. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Integrity product of Oracle Communications Applications (component: User Interface (Apache Commons BeanUtils)).   The supported version that is affected is 7.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Integrity.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Network Integrity accessible data as well as  unauthorized read access to a subset of Oracle Communications Network Integrity accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Network Integrity. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Invoice Matching product of Oracle Retail Applications (component: Security (Apache Commons BeanUtils)).   The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Invoice Matching.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail Invoice Matching accessible data as well as  unauthorized read access to a subset of Oracle Retail Invoice Matching accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Invoice Matching. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13444V-Prior to 21.1.2",
          "P-4491V-7.3.6",
          "P-1810V-16.0.3"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13444V-Prior to 21.1.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4491V-7.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856673.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1810V-16.0.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855697.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-13444V-Prior to 21.1.2",
            "P-4491V-7.3.6",
            "P-1810V-16.0.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2019-12086",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle GoldenGate (component: Internal Framework (jackson-databind)).   The supported version that is affected is Prior to 12.3.0.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GoldenGate.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle GoldenGate accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5757V-Prior to 12.3.0.1.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5757V-Prior to 12.3.0.1.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5757V-Prior to 12.3.0.1.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2019-12399",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Apache Kafka)).   The supported version that is affected is Prior to 21.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Blockchain Platform.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13444V-Prior to 21.1.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13444V-Prior to 21.1.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-13444V-Prior to 21.1.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2019-12402",
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Database Configuration Assistant (Apache Commons Compress) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-383V-All Supported Versions"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-383V-All Supported Versions"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-383V-All Supported Versions"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2019-13565",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Blockchain Platform (component: Backend (OpenLDAP)).   The supported version that is affected is Prior to 21.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Blockchain Platform.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13444V-Prior to 21.1.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13444V-Prior to 21.1.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-13444V-Prior to 21.1.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2019-14862",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle GoldenGate (component: Internal Framework (Knockout)).   The supported version that is affected is Prior to 12.3.0.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GoldenGate.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle GoldenGate, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle GoldenGate accessible data as well as  unauthorized read access to a subset of Oracle GoldenGate accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5757V-Prior to 12.3.0.1.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5757V-Prior to 12.3.0.1.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5757V-Prior to 12.3.0.1.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2019-16789",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: OC-CNE (ceph)).   The supported version that is affected is 1.10.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Function Cloud Native Environment accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Network Function Cloud Native Environment accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14125V-1.10.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14125V-1.10.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14125V-1.10.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2019-17195",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris Cluster product of Oracle Systems (component: Tools (Nimbus JOSE+JWT)).   The supported version that is affected is 4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Solaris Cluster.  Successful attacks of this vulnerability can result in takeover of Oracle Solaris Cluster. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10005V-4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10005V-4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857179.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10005V-4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2019-18276",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (GNU Bash)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.14.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.14.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.14.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2019-3740",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Integrity product of Oracle Communications Applications (component: Installer (RSA BSAFE Crypto-J)).  Supported versions that are affected are 7.3.2, 7.3.5 and  7.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Network Integrity.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Network Integrity accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle StorageTek ACSLS product of Oracle Systems (component: Software (RSA BSAFE Crypto-J)).   The supported version that is affected is 8.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle StorageTek ACSLS.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle StorageTek ACSLS accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4491V-7.3.2",
          "P-4491V-7.3.5",
          "P-4491V-7.3.6",
          "P-10088V-8.5.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4491V-7.3.2",
            "P-4491V-7.3.5",
            "P-4491V-7.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856673.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10088V-8.5.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857179.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4491V-7.3.2",
            "P-4491V-7.3.5",
            "P-4491V-7.3.6",
            "P-10088V-8.5.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2019-3799",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Spring Cloud Config)).   The supported version that is affected is 1.15.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.15.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.15.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-10878",
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications EAGLE Application Processor product of Oracle Communications (component: Platform (Perl)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications EAGLE LNP Application Processor product of Oracle Communications (component: Platform (Perl)).  Supported versions that are affected are 10.1 and  10.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE LNP Application Processor.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications EAGLE LNP Application Processor as well as  unauthorized update, insert or delete access to some of Oracle Communications EAGLE LNP Application Processor accessible data and  unauthorized read access to a subset of Oracle Communications EAGLE LNP Application Processor accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Performance Intelligence Center (PIC) Software product of Oracle Communications (component: Platform (Perl)).  Supported versions that are affected are 10.3.0.0.0-10.3.0.2.1 and  10.4.0.1.0-10.4.0.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Performance Intelligence Center (PIC) Software.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Performance Intelligence Center (PIC) Software as well as  unauthorized update, insert or delete access to some of Oracle Communications Performance Intelligence Center (PIC) Software accessible data and  unauthorized read access to a subset of Oracle Communications Performance Intelligence Center (PIC) Software accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11118V-10.1",
          "P-11118V-10.2",
          "P-11044V-10.3.0.0.0-10.3.0.2.1",
          "P-11044V-10.4.0.1.0-10.4.0.3.1"
        ],
        "known_not_affected": [
          "P-11122V-All Supported Versions"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11122V-All Supported Versions"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861811.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11118V-10.1",
            "P-11118V-10.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861828.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11044V-10.3.0.0.0-10.3.0.2.1",
            "P-11044V-10.4.0.1.0-10.4.0.3.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859060.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-11122V-All Supported Versions"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 8.6,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "P-11118V-10.1",
            "P-11118V-10.2",
            "P-11044V-10.3.0.0.0-10.3.0.2.1",
            "P-11044V-10.4.0.1.0-10.4.0.3.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-11022",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Blockchain Platform (component: Backend (jQuery)).   The supported version that is affected is Prior to 21.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Blockchain Platform.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Blockchain Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Blockchain Platform accessible data as well as  unauthorized read access to a subset of Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle StorageTek ACSLS product of Oracle Systems (component: Software (jQuery)).   The supported version that is affected is 8.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle StorageTek ACSLS.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle StorageTek ACSLS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle StorageTek ACSLS accessible data as well as  unauthorized read access to a subset of Oracle StorageTek ACSLS accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13444V-Prior to 21.1.2",
          "P-10088V-8.5.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13444V-Prior to 21.1.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10088V-8.5.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857179.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-13444V-Prior to 21.1.2",
            "P-10088V-8.5.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-11612",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Netty)).   The supported version that is affected is Prior to 21.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Blockchain Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Blockchain Platform. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13444V-Prior to 21.1.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13444V-Prior to 21.1.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13444V-Prior to 21.1.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-11971",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Intelligence Hub product of Oracle Communications (component: Mediation (Apache Camel)).  Supported versions that are affected are 8.0.0-8.1.0 and  8.2.0-8.2.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Intelligence Hub.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Diameter Intelligence Hub accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11126V-8.0.0-8.1.0",
          "P-11126V-8.2.0-8.2.3"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11126V-8.0.0-8.1.0",
            "P-11126V-8.2.0-8.2.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859054.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-11126V-8.0.0-8.1.0",
            "P-11126V-8.2.0-8.2.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-11979",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle StorageTek Tape Analytics (STA) product of Oracle Systems (component: Core (Apache Ant)).   The supported version that is affected is 2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle StorageTek Tape Analytics (STA).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle StorageTek Tape Analytics (STA) accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle StorageTek ACSLS product of Oracle Systems (component: Software (Apache Ant)).   The supported version that is affected is 8.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle StorageTek ACSLS.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle StorageTek ACSLS accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10085V-2.4",
          "P-10088V-8.5.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10085V-2.4",
            "P-10088V-8.5.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857179.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10085V-2.4",
            "P-10088V-8.5.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-13434",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy   (SQLite)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.14.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.14.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.14.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-13936",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Integrity product of Oracle Communications Applications (component: TL1 Cartridge (Apache Velocity Engine)).   The supported version that is affected is 7.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Network Integrity.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Integrity. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hospitality Token Proxy Service product of Oracle Hospitality Applications (component: TPS Service (Apache Velocity Engine)).   The supported version that is affected is 19.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Token Proxy Service.  Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Token Proxy Service. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Office Cloud Service product of Oracle Retail Applications (component: Configurator (Apache Velocity Engine)).  Supported versions that are affected are 16.0.6, 17.0.4, 18.0.3, 19.0.2 and  20.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Office Cloud Service.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Xstore Office Cloud Service. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4491V-7.3.6",
          "P-13387V-19.2",
          "P-13551V-16.0.6",
          "P-13551V-17.0.4",
          "P-13551V-18.0.3",
          "P-13551V-19.0.2",
          "P-13551V-20.0.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4491V-7.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856673.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13387V-19.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859245.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13551V-16.0.6",
            "P-13551V-17.0.4",
            "P-13551V-18.0.3",
            "P-13551V-19.0.2",
            "P-13551V-20.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855697.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4491V-7.3.6",
            "P-13387V-19.2",
            "P-13551V-16.0.6",
            "P-13551V-17.0.4",
            "P-13551V-18.0.3",
            "P-13551V-19.0.2",
            "P-13551V-20.0.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-13956",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Workbench (HTTPClient)).   The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Commerce Guided Search accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle SQL Developer (component: Thirdparty Database support (Apache HTTPClient)).  Supported versions that are affected are Database: 19c and  21c. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SQL Developer.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle SQL Developer accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9633V-11.3.2",
          "P-1875V-Database: 19c",
          "P-1875V-21c"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633V-11.3.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859309.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1875V-Database: 19c",
            "P-1875V-21c"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9633V-11.3.2",
            "P-1875V-Database: 19c",
            "P-1875V-21c"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-14155",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy   (PCRE)).   The supported version that is affected is 1.15.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.15.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.15.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-14340",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: CNC Console (XNIO)).   The supported version that is affected is 1.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (XNIO)).   The supported version that is affected is 1.14.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14250V-1.9.0",
          "P-14277V-1.14.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-1.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859048.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.14.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14250V-1.9.0",
            "P-14277V-1.14.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-14343",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: OC-CNE (PyYAML)).   The supported version that is affected is 1.10.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14125V-1.10.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14125V-1.10.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14125V-1.10.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-15250",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy  (JUnit)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.14.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.14.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.14.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-16135",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (libssh)).   The supported version that is affected is 1.15.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.15.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.15.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-17521",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: BPM Studio (Apache Groovy)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Process Management Suite executes to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Process Management Suite accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: API Gateway (Apache Groovy)).   The supported version that is affected is 8.4.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Diameter Signaling Router executes to compromise Oracle Communications Diameter Signaling Router.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5325V-12.2.1.3.0",
          "P-5325V-12.2.1.4.0",
          "P-10899V-8.4.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5325V-12.2.1.3.0",
            "P-5325V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10899V-8.4.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859055.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5325V-12.2.1.3.0",
            "P-5325V-12.2.1.4.0",
            "P-10899V-8.4.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-17527",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Apache Tomcat)).   The supported version that is affected is Prior to 21.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Blockchain Platform.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13444V-Prior to 21.1.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13444V-Prior to 21.1.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-13444V-Prior to 21.1.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-17530",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Intelligence Hub product of Oracle Communications (component: Visualization (Apache Struts)).  Supported versions that are affected are 8.0.0-8.1.0 and  8.2.0-8.2.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Intelligence Hub.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Intelligence Hub. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11126V-8.0.0-8.1.0",
          "P-11126V-8.2.0-8.2.3"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11126V-8.0.0-8.1.0",
            "P-11126V-8.2.0-8.2.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859054.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-11126V-8.0.0-8.1.0",
            "P-11126V-8.2.0-8.2.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-1968",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Ethernet Switch TOR-72 product of Oracle Systems (component: Firmware (OpenSSL)).   The supported version that is affected is 1.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Ethernet Switch TOR-72.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Ethernet Switch TOR-72 accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9889V-1.2.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9889V-1.2.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857179.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9889V-1.2.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-1971",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: OC-CNE (OpenSSL)).   The supported version that is affected is 1.10.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14125V-1.10.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14125V-1.10.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14125V-1.10.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-24750",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (jackson-databind)).   The supported version that is affected is Prior to 21.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Blockchain Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Blockchain Platform. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13444V-Prior to 21.1.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13444V-Prior to 21.1.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13444V-Prior to 21.1.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-24977",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module   (libxml2)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle HTTP Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 6.5 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1042V-12.2.1.3.0",
          "P-1042V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042V-12.2.1.3.0",
            "P-1042V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-1042V-12.2.1.3.0",
            "P-1042V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-25638",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: CNC Console (hibernate-core)).   The supported version that is affected is 1.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Console accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Console accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14250V-1.9.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-1.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859048.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14250V-1.9.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-25649",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (jackson-databind)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1696V-12.2.1.3.0",
          "P-1696V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1696V-12.2.1.3.0",
            "P-1696V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1696V-12.2.1.3.0",
            "P-1696V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-27218",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Eclipse Jetty)).   The supported version that is affected is Prior to 21.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Blockchain Platform.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Blockchain Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Blockchain Platform. CVSS 3.1 Base Score 4.8 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13444V-Prior to 21.1.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13444V-Prior to 21.1.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-13444V-Prior to 21.1.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-28052",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Bouncy Castle Java Library)).   The supported version that is affected is Prior to 21.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Blockchain Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Blockchain Platform. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites (Bouncy Castle Java Library)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13444V-Prior to 21.1.2"
        ],
        "known_not_affected": [
          "P-9617V-All Supported Versions"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13444V-Prior to 21.1.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9617V-All Supported Versions"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13444V-Prior to 21.1.2"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9617V-All Supported Versions"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-28196",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (MIT Kerberos)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.14.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.14.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.14.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-29363",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (p11-kit)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.14.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.14.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.14.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-29582",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Kotlin)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.14.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.14.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.14.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-35198",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications EAGLE Software product of Oracle Communications (component: Measurements (VxWorks)).  Supported versions that are affected are 46.7.0, 46.8.0-46.8.2 and  46.9.1-46.9.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE Software.  Successful attacks of this vulnerability can result in takeover of Oracle Communications EAGLE Software. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10768V-46.7.0",
          "P-10768V-46.8.0-46.8.2",
          "P-10768V-46.9.1-46.9.3"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10768V-46.7.0",
            "P-10768V-46.8.0-46.8.2",
            "P-10768V-46.9.1-46.9.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861808.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10768V-46.7.0",
            "P-10768V-46.8.0-46.8.2",
            "P-10768V-46.9.1-46.9.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-36242",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: OC-CNE (python-cryptography)).   The supported version that is affected is 1.10.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Function Cloud Native Environment accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14125V-1.10.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14125V-1.10.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14125V-1.10.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-36518",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: CNC Console (jackson-databind)).   The supported version that is affected is 1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14250V-1.9.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-1.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859048.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14250V-1.9.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-5245",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Blockchain Platform (component: Backend (Dropwizard-Validation)).   The supported version that is affected is Prior to 21.1.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Blockchain Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Blockchain Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13444V-Prior to 21.1.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13444V-Prior to 21.1.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13444V-Prior to 21.1.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-5413",
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Spring Integration)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-14277V-All Supported Versions"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-All Supported Versions"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14277V-All Supported Versions"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-5421",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle StorageTek ACSLS product of Oracle Systems (component: Software (Spring Framework)).   The supported version that is affected is 8.5.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle StorageTek ACSLS.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle StorageTek ACSLS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle StorageTek ACSLS accessible data as well as  unauthorized read access to a subset of Oracle StorageTek ACSLS accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10088V-8.5.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10088V-8.5.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857179.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10088V-8.5.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-6950",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Integrity product of Oracle Communications Applications (component: Installer (Eclipse Mojarra)).   The supported version that is affected is 7.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Integrity.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Network Integrity accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: General (Eclipse Mojarra)).   The supported version that is affected is Prior to 11.2.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Calculation Manager.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Calculation Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris Cluster product of Oracle Systems (component: Tools (Eclipse Mojarra)).   The supported version that is affected is 4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Solaris Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Solaris Cluster accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4491V-7.3.6",
          "P-5685V-Prior to 11.2.8.0",
          "P-10005V-4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4491V-7.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856673.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5685V-Prior to 11.2.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2775466.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10005V-4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857179.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4491V-7.3.6",
            "P-5685V-Prior to 11.2.8.0",
            "P-10005V-4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-7226",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites (Cryptacular)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Sites. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9617V-12.2.1.3.0",
          "P-9617V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9617V-12.2.1.3.0",
            "P-9617V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9617V-12.2.1.3.0",
            "P-9617V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-7760",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Web Client - Unicode (CodeMirror)).   The supported version that is affected is Prior to 11.2.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4375V-Prior to 11.2.9.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4375V-Prior to 11.2.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2775466.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-4375V-Prior to 11.2.9.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-8174",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Node.js)).   The supported version that is affected is Prior to 21.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Blockchain Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Blockchain Platform. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13444V-Prior to 21.1.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13444V-Prior to 21.1.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13444V-Prior to 21.1.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-8203",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Lodash)).   The supported version that is affected is Prior to 21.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Blockchain Platform.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Blockchain Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Blockchain Platform. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13444V-Prior to 21.1.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13444V-Prior to 21.1.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13444V-Prior to 21.1.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-8231",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (libcurl)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.14.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.14.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.14.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-8554",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Kubernetes)).   The supported version that is affected is 1.15.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Policy accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 5.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.15.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.15.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-8908",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Workbench (Guava)).   The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search executes to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Commerce Guided Search accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: REST Services Manager (Guava)).  Supported versions that are affected are 12.0.0.4 and  12.0.0.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Pricing Design Center executes to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Pricing Design Center accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: File Processing (Guava)).  Supported versions that are affected are 8.58 and  8.59. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Third Party Tools (Guava)).   The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9633V-11.3.2",
          "P-9437V-12.0.0.4",
          "P-9437V-12.0.0.5",
          "P-5085V-8.58",
          "P-5085V-8.59",
          "P-5242V-14.1.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633V-11.3.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859309.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9437V-12.0.0.4",
            "P-9437V-12.0.0.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856675.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.58",
            "P-5085V-8.59"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858976.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-14.1.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.3,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9633V-11.3.2",
            "P-9437V-12.0.0.4",
            "P-9437V-12.0.0.5",
            "P-5085V-8.58",
            "P-5085V-8.59",
            "P-5242V-14.1.1.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2020-9488",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle StorageTek ACSLS product of Oracle Systems (component: Software (Apache Log4j)).   The supported version that is affected is 8.5.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle StorageTek ACSLS.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle StorageTek ACSLS accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10088V-8.5.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10088V-8.5.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857179.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10088V-8.5.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-20289",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: CNC Console (RESTEasy)).   The supported version that is affected is 1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Console accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14250V-1.9.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-1.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859048.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14250V-1.9.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-21275",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: REST Service Manager (Jacoco)).  Supported versions that are affected are 12.0.0.4 and  12.0.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Pricing Design Center accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9437V-12.0.0.4",
          "P-9437V-12.0.0.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9437V-12.0.0.4",
            "P-9437V-12.0.0.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856675.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9437V-12.0.0.4",
            "P-9437V-12.0.0.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-21409",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy  (Netty)).   The supported version that is affected is 1.14.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.14.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.14.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.14.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-21703",
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Secure Backup (component: Oracle Secure Backup (PHP)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "P-1522V-All Supported Versions"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1522V-All Supported Versions"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1522V-All Supported Versions"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-22096",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: CNC Console (Spring boot)).   The supported version that is affected is 1.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Console accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: SCP (Spring Framework)).   The supported version that is affected is 1.15.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Service Communication Proxy accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14250V-1.9.0",
          "P-14117V-1.15.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-1.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859048.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14117V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859052.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14250V-1.9.0",
            "P-14117V-1.15.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-22118",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Spring Framework)).   The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search executes to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Intelligence Hub product of Oracle Communications (component: Visualization, Mediation (Spring Framework)).  Supported versions that are affected are 8.0.0-8.1.0 and  8.2.0-8.2.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Diameter Intelligence Hub executes to compromise Oracle Communications Diameter Intelligence Hub.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Intelligence Hub. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Integrity product of Oracle Communications Applications (component: MSS Cartridge   (Spring Framework)).   The supported version that is affected is 7.3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Network Integrity executes to compromise Oracle Communications Network Integrity.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Integrity. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9633V-11.3.2",
          "P-11126V-8.0.0-8.1.0",
          "P-11126V-8.2.0-8.2.3",
          "P-4491V-7.3.6"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633V-11.3.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859309.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11126V-8.0.0-8.1.0",
            "P-11126V-8.2.0-8.2.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859054.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4491V-7.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856673.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9633V-11.3.2",
            "P-11126V-8.0.0-8.1.0",
            "P-11126V-8.2.0-8.2.3",
            "P-4491V-7.3.6"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-22132",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Automated Test Suite Framework (Elasticsearch)).   The supported version that is affected is 1.8.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Automated Test Suite accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14488V-1.8.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14488V-1.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859046.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14488V-1.8.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-22569",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: CNC Console (protobuf-java)).   The supported version that is affected is 1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Console executes to compromise Oracle Communications Cloud Native Core Console.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: OCNRF (protobuf-java)).  Supported versions that are affected are 1.15.0 and  1.15.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Repository Function executes to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (protobuf-java)).   The supported version that is affected is 1.15.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Spatial and Graph MapViewer (protobuf-java) component of Oracle Database Server.  Supported versions that are affected are 19c and  21c. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Oracle Spatial and Graph MapViewer (protobuf-java) executes to compromise Oracle Spatial and Graph MapViewer (protobuf-java).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Spatial and Graph MapViewer (protobuf-java). CVSS 3.1 Base Score 2.8 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14250V-1.9.0",
          "P-14118V-1.15.0",
          "P-14118V-1.15.1",
          "P-14277V-1.15.0",
          "P-619V-19c",
          "P-619V-21c"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-1.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859048.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118V-1.15.0",
            "P-14118V-1.15.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861796.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-619V-19c",
            "P-619V-21c"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14250V-1.9.0",
            "P-14118V-1.15.0",
            "P-14118V-1.15.1",
            "P-14277V-1.15.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 2.8,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-619V-19c",
            "P-619V-21c"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-22570",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Compiling  (protobuf)).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-22901",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (cURL)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1042V-12.2.1.3.0",
          "P-1042V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042V-12.2.1.3.0",
            "P-1042V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-1042V-12.2.1.3.0",
            "P-1042V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-22946",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: CNC BSF (cURL)).   The supported version that is affected is 1.11.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: OC-CNE (cURL)).   The supported version that is affected is 1.10.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Function Cloud Native Environment accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: OCNRF (cURL)).  Supported versions that are affected are 1.15.0 and  1.15.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Repository Function accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: NSSF (cURL)).   The supported version that is affected is 1.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: SCP (cURL)).   The supported version that is affected is 1.15.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Service Communication Proxy accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14121V-1.11.0",
          "P-14125V-1.10.0",
          "P-14118V-1.15.0",
          "P-14118V-1.15.1",
          "P-14130V-1.8.0",
          "P-14117V-1.15.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-1.11.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859047.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14125V-1.10.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861795.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118V-1.15.0",
            "P-14118V-1.15.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861796.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-1.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861807.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14117V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859052.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14121V-1.11.0",
            "P-14125V-1.10.0",
            "P-14118V-1.15.0",
            "P-14118V-1.15.1",
            "P-14130V-1.8.0",
            "P-14117V-1.15.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-23017",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle Blockchain Platform (component: Backend (nginx)).   The supported version that is affected is Prior to 21.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to compromise Oracle Blockchain Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Blockchain Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13444V-Prior to 21.1.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13444V-Prior to 21.1.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13444V-Prior to 21.1.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-23450",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: CMP (dojo)).   The supported version that is affected is 12.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (dojo)).  Supported versions that are affected are 17.7-17.12, 18.8, 19.12, 20.12 and  21.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Primavera Unifier as well as  unauthorized update, insert or delete access to some of Primavera Unifier accessible data and  unauthorized read access to a subset of Primavera Unifier accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10900V-12.6.0.0.0",
          "P-10354V-17.7-17.12",
          "P-10354V-18.8",
          "P-10354V-19.12",
          "P-10354V-20.12",
          "P-10354V-21.12"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-12.6.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859061.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10354V-17.7-17.12",
            "P-10354V-18.8",
            "P-10354V-19.12",
            "P-10354V-20.12",
            "P-10354V-21.12"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856639.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10900V-12.6.0.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.6,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10354V-17.7-17.12",
            "P-10354V-18.8",
            "P-10354V-19.12",
            "P-10354V-20.12",
            "P-10354V-21.12"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-2351",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Enterprise Default Management product of Oracle Financial Services Applications (component: Collections (JDBC)).  Supported versions that are affected are 2.10.0 and  2.12.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Banking Enterprise Default Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Enterprise Default Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Banking Enterprise Default Management. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Platform product of Oracle Financial Services Applications (component: Security (JDBC)).  Supported versions that are affected are 2.6.2, 2.7.1 and  2.12.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Banking Platform.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Banking Platform. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (JDBC, OCCI)).   The supported version that is affected is 21.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Blockchain Platform.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Blockchain Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Blockchain Platform.  Note: This is a hotfix on top of version 21.1.2. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Pipeline Configuration Center,  Oracle Data Manager,  Rated Event Loader (JDBC)).  Supported versions that are affected are 12.0.0.4 and  12.0.0.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications Billing and Revenue Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Intelligence Hub product of Oracle Communications (component: Integrated DIH (JDBC, OCCI)).  Supported versions that are affected are 8.0.0-8.2.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications Diameter Intelligence Hub.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Diameter Intelligence Hub, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Intelligence Hub. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications IP Service Activator product of Oracle Communications Applications (component: Service Activator (OCCI)).   The supported version that is affected is 7.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications IP Service Activator.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications IP Service Activator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications IP Service Activator. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: Cloud Native Deployment (JDBC)).  Supported versions that are affected are 12.0.0.4 and  12.0.0.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications Pricing Design Center.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Pricing Design Center, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Pricing Design Center. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Services Gatekeeper product of Oracle Communications (component: Third party software/products (JDBC)).   The supported version that is affected is 7.0.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications Services Gatekeeper.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Services Gatekeeper, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Services Gatekeeper. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Development Tools (JDBC, OCCI)).  Supported versions that are affected are 12.6.0, 12.6.2-12.6.4 and  12.7.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Documaker.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Documaker, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Documaker. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Enterprise Manager Ops Center product of Oracle Enterprise Manager (component: Networking (OCCI)).   The supported version that is affected is 12.4.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Enterprise Manager Ops Center.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Enterprise Manager Ops Center, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Enterprise Manager Ops Center. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Application Adapters product of Oracle GoldenGate (component: General (OCCI)).   The supported version that is affected is Prior to 23.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle GoldenGate Application Adapters.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle GoldenGate Application Adapters, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate Application Adapters. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Database and Comm SEC (OCCI)).   The supported version that is affected is Prior to 9.2.6.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics SEC (JDBC)).   The supported version that is affected is Prior to 9.2.6.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle StorageTek Tape Analytics (STA) product of Oracle Systems (component: Application Server (JDBC)).   The supported version that is affected is 2.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle StorageTek Tape Analytics (STA).  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle StorageTek Tape Analytics (STA), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle StorageTek Tape Analytics (STA). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle StorageTek ACSLS product of Oracle Systems (component: Software (JDBC)).   The supported version that is affected is 8.5.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle StorageTek ACSLS.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle StorageTek ACSLS, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle StorageTek ACSLS. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13390V-2.10.0",
          "P-13390V-2.12.0",
          "P-9178V-2.6.2",
          "P-9178V-2.7.1",
          "P-9178V-2.12.0",
          "P-13444V-21.1.2",
          "P-2136V-12.0.0.4",
          "P-2136V-12.0.0.5",
          "P-11126V-8.0.0-8.2.3",
          "P-2261V-7.4.0",
          "P-9437V-12.0.0.4",
          "P-9437V-12.0.0.5",
          "P-5381V-7.0.0.0.0",
          "P-5477V-12.6.0",
          "P-5477V-12.6.2-12.6.4",
          "P-5477V-12.7.0",
          "P-9835V-12.4.0.0",
          "P-5760V-Prior to 23.1",
          "P-4781(Database and Comm SEC)V-Prior to 9.2.6.3",
          "P-4781(Monitoring and Diagnostics SEC)V-Prior to 9.2.6.3",
          "P-10085V-2.4",
          "P-10088V-8.5.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13390V-2.10.0",
            "P-13390V-2.12.0",
            "P-9178V-2.6.2",
            "P-9178V-2.7.1",
            "P-9178V-2.12.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861653.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13444V-21.1.2",
            "P-5760V-Prior to 23.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2136V-12.0.0.4",
            "P-2136V-12.0.0.5",
            "P-9437V-12.0.0.4",
            "P-9437V-12.0.0.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856675.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11126V-8.0.0-8.2.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859054.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2261V-7.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856708.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5381V-7.0.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859062.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5477V-12.6.0",
            "P-5477V-12.6.2-12.6.4",
            "P-5477V-12.7.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857284.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9835V-12.4.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844807.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781(Database and Comm SEC)V-Prior to 9.2.6.3",
            "P-4781(Monitoring and Diagnostics SEC)V-Prior to 9.2.6.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858978.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10085V-2.4",
            "P-10088V-8.5.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857179.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13390V-2.10.0",
            "P-13390V-2.12.0",
            "P-9178V-2.6.2",
            "P-9178V-2.7.1",
            "P-9178V-2.12.0",
            "P-13444V-21.1.2",
            "P-2136V-12.0.0.4",
            "P-2136V-12.0.0.5",
            "P-11126V-8.0.0-8.2.3",
            "P-2261V-7.4.0",
            "P-9437V-12.0.0.4",
            "P-9437V-12.0.0.5",
            "P-5381V-7.0.0.0.0",
            "P-5477V-12.6.0",
            "P-5477V-12.6.2-12.6.4",
            "P-5477V-12.7.0",
            "P-9835V-12.4.0.0",
            "P-5760V-Prior to 23.1",
            "P-4781(Database and Comm SEC)V-Prior to 9.2.6.3",
            "P-4781(Monitoring and Diagnostics SEC)V-Prior to 9.2.6.3",
            "P-10085V-2.4",
            "P-10088V-8.5.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-2464",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Engineered Systems Utilities component of Oracle Autonomous Health Framework.  Supported versions that are affected are 12.1.0.2, 19c and  21c. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Engineered Systems Utilities executes to compromise Engineered Systems Utilities.  Successful attacks of this vulnerability can result in takeover of Engineered Systems Utilities. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10655V-12.1.0.2",
          "P-10655V-19c",
          "P-10655V-21c"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10655V-12.1.0.2",
            "P-10655V-19c",
            "P-10655V-21c"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10655V-12.1.0.2",
            "P-10655V-19c",
            "P-10655V-21c"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-2471",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: CNC Console (MySQL Connectors)).   The supported version that is affected is 1.9.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Console accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: NSSF (MySQL)).   The supported version that is affected is 1.8.0. Difficult to exploit vulnerability allows high privileged attacker with network access via TCP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (MySQL)).   The supported version that is affected is 1.15.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (MySQL)).   The supported version that is affected is 1.7.0. Difficult to exploit vulnerability allows high privileged attacker with network access via TCP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14250V-1.9.0",
          "P-14130V-1.8.0",
          "P-14277V-1.15.0",
          "P-14123V-1.7.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-1.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859048.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-1.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861807.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14123V-1.7.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859050.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14250V-1.9.0",
            "P-14130V-1.8.0",
            "P-14277V-1.15.0",
            "P-14123V-1.7.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-26291",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GoldenGate Big Data and Application Adapters product of Oracle GoldenGate (component: General (Apache Maven)).   The supported version that is affected is Prior to 23.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GoldenGate Big Data and Application Adapters.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle GoldenGate Big Data and Application Adapters accessible data as well as  unauthorized access to critical data or complete access to all Oracle GoldenGate Big Data and Application Adapters accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5760V-Prior to 23.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5760V-Prior to 23.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5760V-Prior to 23.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-28168",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Eclipse Jersey)).   The supported version that is affected is 1.15.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: UDR (Eclipse Jersey)).   The supported version that is affected is 1.15.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Unified Data Repository executes to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Unified Data Repository accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.15.0",
          "P-14119V-1.15.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14119V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859053.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.15.0",
            "P-14119V-1.15.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-28169",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Eclipse Jetty)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.14.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.14.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.14.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-28170",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Jakarta)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Third Party Jars (JBoss Enterprise Application Platform)).   The supported version that is affected is 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.14.0",
          "P-5242V-14.1.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.14.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-14.1.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.14.0",
            "P-5242V-14.1.1.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-28657",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (Apache Tika)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebCenter Portal executes to compromise Oracle WebCenter Portal.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1696V-12.2.1.3.0",
          "P-1696V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1696V-12.2.1.3.0",
            "P-1696V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-1696V-12.2.1.3.0",
            "P-1696V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-29425",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security (Apache Commons IO)).   The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as  unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Apache Commons IO)).   The supported version that is affected is Prior to 21.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Blockchain Platform.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Blockchain Platform accessible data as well as  unauthorized read access to a subset of Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy   (Apache Commons IO)).   The supported version that is affected is 1.14.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Policy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Contacts Server product of Oracle Communications Applications (component: File Upload (Apache Commons IO)).   The supported version that is affected is 8.0.0.6.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Contacts Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Contacts Server accessible data as well as  unauthorized read access to a subset of Oracle Communications Contacts Server accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Design Studio product of Oracle Communications Applications (component: OSM Plugin (Apache Commons IO)).  Supported versions that are affected are 7.3.5 and  7.4.0-7.4.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Design Studio.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Design Studio accessible data as well as  unauthorized read access to a subset of Oracle Communications Design Studio accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Intelligence Hub product of Oracle Communications (component: Database (Apache Commons IO)).  Supported versions that are affected are 8.0.0-8.1.0 and  8.2.0-8.2.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications Diameter Intelligence Hub.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Diameter Intelligence Hub accessible data as well as  unauthorized read access to a subset of Oracle Communications Diameter Intelligence Hub accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: OSM SDK (Apache Commons IO)).  Supported versions that are affected are 7.3 and  7.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Order and Service Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Order and Service Management accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: CMP (Apache Commons IO)).   The supported version that is affected is 12.5.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Policy Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Policy Management accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: REST Service Manager (Apache Commons IO)).  Supported versions that are affected are 12.0.0.4 and  12.0.0.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Pricing Design Center accessible data as well as  unauthorized read access to a subset of Oracle Communications Pricing Design Center accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Health Sciences Information Manager product of Oracle HealthCare Applications (component: Health Policy Engine (Apache Commons IO)).  Supported versions that are affected are 3.0.1-3.0.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences Information Manager.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Health Sciences Information Manager accessible data as well as  unauthorized read access to a subset of Oracle Health Sciences Information Manager accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR Comandline (Apache Commons IO)).   The supported version that is affected is 8.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Data Repository.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Healthcare Data Repository accessible data as well as  unauthorized read access to a subset of Oracle Healthcare Data Repository accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: CDI support (Apache Commons IO)).  Supported versions that are affected are 1.4.7 and  2.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Helidon accessible data as well as  unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Insurance Policy Administration product of Oracle Insurance Applications (component: Architecture (Apache Commons IO)).  Supported versions that are affected are 11.0.2, 11.1.0, 11.2.8, 11.3.0 and  11.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Insurance Policy Administration accessible data as well as  unauthorized read access to a subset of Oracle Insurance Policy Administration accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Insurance Rules Palette product of Oracle Insurance Applications (component: Architecture (Apache Commons IO)).  Supported versions that are affected are 11.0.2, 11.1.0, 11.2.8, 11.3.0 and  11.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Rules Palette.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Insurance Rules Palette accessible data as well as  unauthorized read access to a subset of Oracle Insurance Rules Palette accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle REST Data Services (component: General (Apache Commons IO)).   The supported version that is affected is Prior to 21.2. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle REST Data Services.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle REST Data Services accessible data as well as  unauthorized read access to a subset of Oracle REST Data Services accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris Cluster product of Oracle Systems (component: Tools (Apache Commons IO)).   The supported version that is affected is 4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Solaris Cluster.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Solaris Cluster accessible data as well as  unauthorized read access to a subset of Oracle Solaris Cluster accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (Apache Commons IO)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data as well as  unauthorized read access to a subset of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4461V-9.3.6",
          "P-13444V-Prior to 21.1.2",
          "P-14277V-1.14.0",
          "P-10696V-8.0.0.6.0",
          "P-2283V-7.3.5",
          "P-2283V-7.4.0-7.4.2",
          "P-11126V-8.0.0-8.1.0",
          "P-11126V-8.2.0-8.2.3",
          "P-2270V-7.3",
          "P-2270V-7.4",
          "P-10900V-12.5.0.0.0",
          "P-9437V-12.0.0.4",
          "P-9437V-12.0.0.5",
          "P-9177V-3.0.1-3.0.4",
          "P-9161V-8.1.0",
          "P-13972V-1.4.7",
          "P-13972V-2.2.0",
          "P-5279V-11.0.2",
          "P-5279V-11.1.0",
          "P-5279V-11.2.8",
          "P-5279V-11.3.0",
          "P-5279V-11.3.1",
          "P-5288V-11.0.2",
          "P-5288V-11.1.0",
          "P-5288V-11.2.8",
          "P-5288V-11.3.0",
          "P-5288V-11.3.1",
          "P-10005V-4",
          "P-1696V-12.2.1.3.0",
          "P-1696V-12.2.1.4.0",
          "P-9456V-Prior to 21.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4461V-9.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858979.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13444V-Prior to 21.1.2",
            "P-9456V-Prior to 21.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.14.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10696V-8.0.0.6.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856674.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2283V-7.3.5",
            "P-2283V-7.4.0-7.4.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856707.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11126V-8.0.0-8.1.0",
            "P-11126V-8.2.0-8.2.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859054.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2270V-7.3",
            "P-2270V-7.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856706.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-12.5.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859061.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9437V-12.0.0.4",
            "P-9437V-12.0.0.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856675.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9177V-3.0.1-3.0.4",
            "P-9161V-8.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2862542.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13972V-1.4.7",
            "P-13972V-2.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2645279.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5279V-11.0.2",
            "P-5279V-11.1.0",
            "P-5279V-11.2.8",
            "P-5279V-11.3.0",
            "P-5279V-11.3.1",
            "P-5288V-11.0.2",
            "P-5288V-11.1.0",
            "P-5288V-11.2.8",
            "P-5288V-11.3.0",
            "P-5288V-11.3.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857284.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10005V-4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857179.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1696V-12.2.1.3.0",
            "P-1696V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4461V-9.3.6",
            "P-13444V-Prior to 21.1.2",
            "P-14277V-1.14.0",
            "P-10696V-8.0.0.6.0",
            "P-2283V-7.3.5",
            "P-2283V-7.4.0-7.4.2",
            "P-11126V-8.0.0-8.1.0",
            "P-11126V-8.2.0-8.2.3",
            "P-2270V-7.3",
            "P-2270V-7.4",
            "P-10900V-12.5.0.0.0",
            "P-9437V-12.0.0.4",
            "P-9437V-12.0.0.5",
            "P-9177V-3.0.1-3.0.4",
            "P-9161V-8.1.0",
            "P-13972V-1.4.7",
            "P-13972V-2.2.0",
            "P-5279V-11.0.2",
            "P-5279V-11.1.0",
            "P-5279V-11.2.8",
            "P-5279V-11.3.0",
            "P-5279V-11.3.1",
            "P-5288V-11.0.2",
            "P-5288V-11.1.0",
            "P-5288V-11.2.8",
            "P-5288V-11.3.0",
            "P-5288V-11.3.1",
            "P-10005V-4",
            "P-1696V-12.2.1.3.0",
            "P-1696V-12.2.1.4.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 4.2,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9456V-Prior to 21.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-29921",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: BSF (Python)).   The supported version that is affected is 1.11.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: NSSF (Python)).   The supported version that is affected is 1.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14121V-1.11.0",
          "P-14130V-1.8.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-1.11.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859047.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-1.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861807.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14121V-1.11.0",
            "P-14130V-1.8.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-30129",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Infrastructure (Apache MINA SSHD)).   The supported version that is affected is 14.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Payments. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure (Apache MINA SSHD)).   The supported version that is affected is 14.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Trade Finance. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Treasury Management product of Oracle Financial Services Applications (component: Infrastructure (Apache MINA SSHD)).   The supported version that is affected is 14.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Treasury Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Treasury Management. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: CNC Console (Apache MINA SSHD)).   The supported version that is affected is 1.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Database - Enterprise Edition Portable Clusterware (Apache MINA SSHD) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure (Apache MINA SSHD)).  Supported versions that are affected are 14.0-14.3 and  14.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle FLEXCUBE Universal Banking. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: FMW Remote Diagnostic Agent   (Apache MINA SSHD and Apache MINA)).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Middleware Common Libraries and Tools. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle NoSQL Database (component: Administration (Apache MINA SSHD)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Diagnostic Assistant (Apache MINA SSHD)).   The supported version that is affected is 2.12.42. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise OSS Support Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of OSS Support Tools. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Segment (Apache MINA SSHD)).  Supported versions that are affected are 18.0 and  19.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Customer Management and Segmentation Foundation. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13011V-14.5",
          "P-14134V-14.5",
          "P-14133V-14.5",
          "P-14250V-1.9.0",
          "P-9052V-14.0-14.3",
          "P-9052V-14.5",
          "P-4647V-12.2.1.3.0",
          "P-4647V-12.2.1.4.0",
          "P-4647V-14.1.1.0.0",
          "P-1330V-2.12.42",
          "P-13388V-18.0",
          "P-13388V-19.0"
        ],
        "known_not_affected": [
          "P-5(Oracle Database - Enterprise Edition Portable Clusterware)V-All Supported Versions",
          "P-13373V-All Supported Versions"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13011V-14.5",
            "P-14134V-14.5",
            "P-14133V-14.5",
            "P-9052V-14.0-14.3",
            "P-9052V-14.5"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-1.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859048.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Oracle Database - Enterprise Edition Portable Clusterware)V-All Supported Versions",
            "P-13373V-All Supported Versions"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4647V-12.2.1.3.0",
            "P-4647V-12.2.1.4.0",
            "P-4647V-14.1.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1330V-2.12.42"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859097.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13388V-18.0",
            "P-13388V-19.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855697.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13011V-14.5",
            "P-14134V-14.5",
            "P-14133V-14.5",
            "P-14250V-1.9.0",
            "P-9052V-14.0-14.3",
            "P-9052V-14.5",
            "P-4647V-12.2.1.3.0",
            "P-4647V-12.2.1.4.0",
            "P-4647V-14.1.1.0.0",
            "P-1330V-2.12.42",
            "P-13388V-18.0",
            "P-13388V-19.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Oracle Database - Enterprise Edition Portable Clusterware)V-All Supported Versions",
            "P-13373V-All Supported Versions"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-30468",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Intelligence Hub product of Oracle Communications (component: Visualization, Mediation (Apache CXF)).  Supported versions that are affected are 8.0.0-8.1.0 and  8.2.0-8.2.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Communications Diameter Intelligence Hub.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Intelligence Hub. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11126V-8.0.0-8.1.0",
          "P-11126V-8.2.0-8.2.3"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11126V-8.0.0-8.1.0",
            "P-11126V-8.2.0-8.2.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859054.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-11126V-8.0.0-8.1.0",
            "P-11126V-8.2.0-8.2.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-3156",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Performance Intelligence Center (PIC) Software product of Oracle Communications (component: Platform (Sudo)).  Supported versions that are affected are 10.3.0.0.0-10.3.0.2.1 and  10.4.0.1.0-10.4.0.3.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Performance Intelligence Center (PIC) Software executes to compromise Oracle Communications Performance Intelligence Center (PIC) Software.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Performance Intelligence Center (PIC) Software. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11044V-10.3.0.0.0-10.3.0.2.1",
          "P-11044V-10.4.0.1.0-10.4.0.3.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11044V-10.3.0.0.0-10.3.0.2.1",
            "P-11044V-10.4.0.1.0-10.4.0.3.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859060.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-11044V-10.3.0.0.0-10.3.0.2.1",
            "P-11044V-10.4.0.1.0-10.4.0.3.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-31812",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure (Apache PDFBox)).   The supported version that is affected is 14.5. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Banking Trade Finance executes to compromise Oracle Banking Trade Finance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Trade Finance. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Treasury Management product of Oracle Financial Services Applications (component: Infrastructure (Apache PDFBox)).   The supported version that is affected is 14.5. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Banking Treasury Management executes to compromise Oracle Banking Treasury Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Treasury Management. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure (Apache PDFBox)).  Supported versions that are affected are 14.0-14.3 and  14.5. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle FLEXCUBE Universal Banking executes to compromise Oracle FLEXCUBE Universal Banking.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle FLEXCUBE Universal Banking. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration (Apache PDFbox)).   The supported version that is affected is Prior to 11.2.8.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Office (Apache PDFbox)).  Supported versions that are affected are 16.0.6, 17.0.4, 18.0.3, 19.0.2 and  20.0.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Retail Xstore Point of Service executes to compromise Oracle Retail Xstore Point of Service.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (Apache PDFbox)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebCenter Portal executes to compromise Oracle WebCenter Portal.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14134V-14.5",
          "P-14133V-14.5",
          "P-9052V-14.0-14.3",
          "P-9052V-14.5",
          "P-4392V-Prior to 11.2.8.0",
          "P-11513V-16.0.6",
          "P-11513V-17.0.4",
          "P-11513V-18.0.3",
          "P-11513V-19.0.2",
          "P-11513V-20.0.1",
          "P-1696V-12.2.1.3.0",
          "P-1696V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14134V-14.5",
            "P-14133V-14.5",
            "P-9052V-14.0-14.3",
            "P-9052V-14.5"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4392V-Prior to 11.2.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2775466.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11513V-16.0.6",
            "P-11513V-17.0.4",
            "P-11513V-18.0.3",
            "P-11513V-19.0.2",
            "P-11513V-20.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855697.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1696V-12.2.1.3.0",
            "P-1696V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14134V-14.5",
            "P-14133V-14.5",
            "P-9052V-14.0-14.3",
            "P-9052V-14.5",
            "P-4392V-Prior to 11.2.8.0",
            "P-11513V-16.0.6",
            "P-11513V-17.0.4",
            "P-11513V-18.0.3",
            "P-11513V-19.0.2",
            "P-11513V-20.0.1",
            "P-1696V-12.2.1.3.0",
            "P-1696V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-3200",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Signaling (libsolv)).   The supported version that is affected is 1.15.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 3.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.15.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.3,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.15.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-32066",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech-Cloud (Ruby)).   The supported version that is affected is Prior to 9.2.6.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4781V-Prior to 9.2.6.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-Prior to 9.2.6.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858978.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4781V-Prior to 9.2.6.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-32626",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: FDP (Redis)).  Supported versions that are affected are 4.3, 4.4 and  5.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10761V-4.3",
          "P-10761V-4.4",
          "P-10761V-5.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10761V-4.3",
            "P-10761V-4.4",
            "P-10761V-5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859059.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10761V-4.3",
            "P-10761V-4.4",
            "P-10761V-5.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-33037",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Translational Research product of Oracle HealthCare Applications (component: Datastudio (Apache Tomcat)).   The supported version that is affected is 4.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Translational Research.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Healthcare Translational Research accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server (Apache Tomcat)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Managed File Transfer.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Managed File Transfer accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9427V-4.1.0",
          "P-10198V-12.2.1.3.0",
          "P-10198V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9427V-4.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2862542.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10198V-12.2.1.3.0",
            "P-10198V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9427V-4.1.0",
            "P-10198V-12.2.1.3.0",
            "P-10198V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-33813",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications Applications (component: ISC (Apache Tika)).   The supported version that is affected is 8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Messaging Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8496V-8.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8496V-8.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856674.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8496V-8.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-33880",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (aaugustin websockets)).   The supported version that is affected is 1.14.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.14.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.14.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.14.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-34429",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Framework (Eclipse Jetty)).   The supported version that is affected is 20.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail EFTLink.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Retail EFTLink accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11516V-20.0.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11516V-20.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855697.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-11516V-20.0.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-3450",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Enterprise Manager for Storage Management product of Oracle Enterprise Manager (component: Privilege Management (OpenSSL)).   The supported version that is affected is 13.4.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Enterprise Manager for Storage Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Enterprise Manager for Storage Management accessible data as well as  unauthorized access to critical data or complete access to all Enterprise Manager for Storage Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10303V-13.4.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10303V-13.4.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844807.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10303V-13.4.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-35043",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Insurance Policy Administration product of Oracle Insurance Applications (component: Architecture (AntiSamy)).  Supported versions that are affected are 11.0.2, 11.1.0, 11.2.8, 11.3.0 and  11.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Insurance Policy Administration, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Insurance Policy Administration accessible data as well as  unauthorized read access to a subset of Oracle Insurance Policy Administration accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5279V-11.0.2",
          "P-5279V-11.1.0",
          "P-5279V-11.2.8",
          "P-5279V-11.3.0",
          "P-5279V-11.3.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5279V-11.0.2",
            "P-5279V-11.1.0",
            "P-5279V-11.2.8",
            "P-5279V-11.3.0",
            "P-5279V-11.3.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857284.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5279V-11.0.2",
            "P-5279V-11.1.0",
            "P-5279V-11.2.8",
            "P-5279V-11.3.0",
            "P-5279V-11.3.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-3518",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install (libxml2)).  Supported versions that are affected are 13.4.0.0 and  13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PeopleSoft CDA (libxml2)).   The supported version that is affected is 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1370V-13.4.0.0",
          "P-1370V-13.5.0.0",
          "P-5085V-8.58"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1370V-13.4.0.0",
            "P-1370V-13.5.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844807.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.58"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858976.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-1370V-13.4.0.0",
            "P-1370V-13.5.0.0",
            "P-5085V-8.58"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-3520",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (lz4)).   The supported version that is affected is 1.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.14.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.14.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.14.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-3521",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: OC-CNE (rpm)).   The supported version that is affected is 1.10.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Function Cloud Native Environment executes to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Function Cloud Native Environment accessible data. CVSS 3.1 Base Score 4.4 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14125V-1.10.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14125V-1.10.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14125V-1.10.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-35515",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Automated Test Suite (Apache Commons Compress)).   The supported version that is affected is 1.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14488V-1.8.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14488V-1.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859046.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14488V-1.8.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-35574",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (glibc)).   The supported version that is affected is 1.15.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.15.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.15.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-3572",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: OC-CNE (python-pip)).   The supported version that is affected is 1.10.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Function Cloud Native Environment accessible data. CVSS 3.1 Base Score 5.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (python-pip)).   The supported version that is affected is 1.15.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 5.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14125V-1.10.0",
          "P-14277V-1.15.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14125V-1.10.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861795.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14125V-1.10.0",
            "P-14277V-1.15.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-36090",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Infrastructure (Apache Commons Compress)).   The supported version that is affected is 14.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Payments.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Payments. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure (Apache Commons Compress)).   The supported version that is affected is 14.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Trade Finance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Trade Finance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Treasury Management product of Oracle Financial Services Applications (component: Infrastructure (Apache Commons Compress)).   The supported version that is affected is 14.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Treasury Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Treasury Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care (Apache Commons Compress)).   The supported version that is affected is 12.0.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Intelligence Hub product of Oracle Communications (component: Integrated DIH (Apache Commons Compress)).  Supported versions that are affected are 8.0.0-8.2.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Intelligence Hub.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Intelligence Hub. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure (Apache Commons Compress)).  Supported versions that are affected are 12.4, 14.0-14.3 and  14.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle FLEXCUBE Universal Banking. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Global Lifecycle Management OPatch product of Oracle Global Lifecycle Management (component: Centralized Third Party Jars (Apache Commons Compress)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR Commandline (Apache Commons Compress)).   The supported version that is affected is 8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Data Repository.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Healthcare Data Repository. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Insurance Policy Administration product of Oracle Insurance Applications (component: Architecture (Apache Commons Compress)).  Supported versions that are affected are 11.0.2, 11.1.0, 11.2.8, 11.3.0 and  11.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Insurance Policy Administration. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (Apache Commons Compress)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13011V-14.5",
          "P-14134V-14.5",
          "P-14133V-14.5",
          "P-2136V-12.0.0.4",
          "P-11126V-8.0.0-8.2.3",
          "P-9052V-12.4",
          "P-9052V-14.0-14.3",
          "P-9052V-14.5",
          "P-9161V-8.1.0",
          "P-5279V-11.0.2",
          "P-5279V-11.1.0",
          "P-5279V-11.2.8",
          "P-5279V-11.3.0",
          "P-5279V-11.3.1",
          "P-1696V-12.2.1.3.0",
          "P-1696V-12.2.1.4.0"
        ],
        "known_not_affected": [
          "P-12753V-All Supported Versions"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13011V-14.5",
            "P-14134V-14.5",
            "P-14133V-14.5",
            "P-9052V-12.4",
            "P-9052V-14.0-14.3",
            "P-9052V-14.5"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2136V-12.0.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856675.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11126V-8.0.0-8.2.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859054.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-12753V-All Supported Versions",
            "P-1696V-12.2.1.3.0",
            "P-1696V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9161V-8.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2862542.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5279V-11.0.2",
            "P-5279V-11.1.0",
            "P-5279V-11.2.8",
            "P-5279V-11.3.0",
            "P-5279V-11.3.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857284.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13011V-14.5",
            "P-14134V-14.5",
            "P-14133V-14.5",
            "P-2136V-12.0.0.4",
            "P-11126V-8.0.0-8.2.3",
            "P-9052V-12.4",
            "P-9052V-14.0-14.3",
            "P-9052V-14.5",
            "P-9161V-8.1.0",
            "P-5279V-11.0.2",
            "P-5279V-11.1.0",
            "P-5279V-11.2.8",
            "P-5279V-11.3.0",
            "P-5279V-11.3.1",
            "P-1696V-12.2.1.3.0",
            "P-1696V-12.2.1.4.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-12753V-All Supported Versions"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-36374",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure (Apache Ant)).   The supported version that is affected is 14.5. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Banking Trade Finance executes to compromise Oracle Banking Trade Finance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Trade Finance. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Treasury Management product of Oracle Financial Services Applications (component: Infrastructure (Apache Ant)).   The supported version that is affected is 14.5. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Banking Treasury Management executes to compromise Oracle Banking Treasury Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Treasury Management. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Automated Test Suite (Apache Ant)).   The supported version that is affected is 1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Automated Test Suite executes to compromise Oracle Communications Cloud Native Core Automated Test Suite.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: CNC BSF (Apache Ant)).   The supported version that is affected is 1.11.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Binding Support Function executes to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Intelligence Hub product of Oracle Communications (component: Visualization (Apache Ant)).  Supported versions that are affected are 8.0.0-8.1.0 and  8.2.0-8.2.3. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Diameter Intelligence Hub executes to compromise Oracle Communications Diameter Intelligence Hub.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Intelligence Hub. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Installer, OSM SDK (Apache Ant)).  Supported versions that are affected are 7.3 and  7.4. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Order and Service Management executes to compromise Oracle Communications Order and Service Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Order and Service Management. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Installation (Apache Ant)).  Supported versions that are affected are 19.0.1 and  20.0.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Retail EFTLink executes to compromise Oracle Retail EFTLink.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail EFTLink. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Invoice Matching product of Oracle Retail Applications (component: Security (Apache Ant)).   The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Retail Invoice Matching executes to compromise Oracle Retail Invoice Matching.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Invoice Matching. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Ant)).  Supported versions that are affected are 16.0.6, 17.0.4, 18.0.3, 19.0.2 and  20.0.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Retail Xstore Point of Service executes to compromise Oracle Retail Xstore Point of Service.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14134V-14.5",
          "P-14133V-14.5",
          "P-14488V-1.9.0",
          "P-14121V-1.11.0",
          "P-11126V-8.0.0-8.1.0",
          "P-11126V-8.2.0-8.2.3",
          "P-2270V-7.3",
          "P-2270V-7.4",
          "P-11516V-19.0.1",
          "P-11516V-20.0.1",
          "P-1810V-16.0.3",
          "P-11513V-16.0.6",
          "P-11513V-17.0.4",
          "P-11513V-18.0.3",
          "P-11513V-19.0.2",
          "P-11513V-20.0.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14134V-14.5",
            "P-14133V-14.5"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14488V-1.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859046.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-1.11.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859047.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11126V-8.0.0-8.1.0",
            "P-11126V-8.2.0-8.2.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859054.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2270V-7.3",
            "P-2270V-7.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856706.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11516V-19.0.1",
            "P-11516V-20.0.1",
            "P-1810V-16.0.3",
            "P-11513V-16.0.6",
            "P-11513V-17.0.4",
            "P-11513V-18.0.3",
            "P-11513V-19.0.2",
            "P-11513V-20.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855697.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14134V-14.5",
            "P-14133V-14.5",
            "P-14488V-1.9.0",
            "P-14121V-1.11.0",
            "P-11126V-8.0.0-8.1.0",
            "P-11126V-8.2.0-8.2.3",
            "P-2270V-7.3",
            "P-2270V-7.4",
            "P-11516V-19.0.1",
            "P-11516V-20.0.1",
            "P-1810V-16.0.3",
            "P-11513V-16.0.6",
            "P-11513V-17.0.4",
            "P-11513V-18.0.3",
            "P-11513V-19.0.2",
            "P-11513V-20.0.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-3690",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: NSSF (Undertow)).   The supported version that is affected is 1.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14130V-1.8.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-1.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861807.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14130V-1.8.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-3711",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Health Sciences InForm Publisher product of Oracle Health Sciences Applications (component: Connector (OpenSSL)).  Supported versions that are affected are 6.2.1.0 and  6.3.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Health Sciences InForm Publisher.  Successful attacks of this vulnerability can result in takeover of Oracle Health Sciences InForm Publisher. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure (OpenSSL)).   The supported version that is affected is Prior to 9.2.6.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards World Security product of Oracle JD Edwards (component: World Software Security (OpenSSL)).   The supported version that is affected is A9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise JD Edwards World Security.  Successful attacks of this vulnerability can result in takeover of JD Edwards World Security. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9638V-6.2.1.0",
          "P-9638V-6.3.1.1",
          "P-4781V-Prior to 9.2.6.3",
          "P-4839V-A9.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9638V-6.2.1.0",
            "P-9638V-6.3.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2854079.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-Prior to 9.2.6.3",
            "P-4839V-A9.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858978.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9638V-6.2.1.0",
            "P-9638V-6.3.1.1",
            "P-4781V-Prior to 9.2.6.3",
            "P-4839V-A9.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-3712",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: CNC Console (OpenSSL)).   The supported version that is affected is 1.9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Console accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 7.4 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (OpenSSL)).   The supported version that is affected is 1.7.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 7.4 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: UDR (OpenSSL)).   The supported version that is affected is 1.15.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Unified Data Repository accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 7.4 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Security (OpenSSL)).  Supported versions that are affected are 8.4 and  9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Session Border Controller accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Border Controller. CVSS 3.1 Base Score 7.4 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Session Manager product of Oracle Communications (component: Security (OpenSSL)).  Supported versions that are affected are 8.2.5 and  8.4.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Communications Unified Session Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Session Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Session Manager. CVSS 3.1 Base Score 7.4 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications (component: Security (OpenSSL)).  Supported versions that are affected are 3.2 and  3.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Enterprise Communications Broker.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Enterprise Communications Broker accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Communications Broker. CVSS 3.1 Base Score 7.4 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: Security (OpenSSL)).  Supported versions that are affected are 8.4 and  9.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Enterprise Session Border Controller.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Enterprise Session Border Controller accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Session Border Controller. CVSS 3.1 Base Score 7.4 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14250V-1.9.0",
          "P-14123V-1.7.0",
          "P-14119V-1.15.0",
          "P-10750V-8.4",
          "P-10750V-9.0",
          "P-10753V-8.2.5",
          "P-10753V-8.4.5",
          "P-10758V-3.2",
          "P-10758V-3.3",
          "P-10757V-8.4",
          "P-10757V-9.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-1.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859048.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14123V-1.7.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859050.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14119V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859053.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10750V-8.4",
            "P-10750V-9.0",
            "P-10757V-8.4",
            "P-10757V-9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858583.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10753V-8.2.5",
            "P-10753V-8.4.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858584.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10758V-3.2",
            "P-10758V-3.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858599.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14250V-1.9.0",
            "P-14123V-1.7.0",
            "P-14119V-1.15.0",
            "P-10750V-8.4",
            "P-10750V-9.0",
            "P-10753V-8.2.5",
            "P-10753V-8.4.5",
            "P-10758V-3.2",
            "P-10758V-3.3",
            "P-10757V-8.4",
            "P-10757V-9.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-37137",
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle NoSQL Database (component: Administration  (Netty)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (Netty)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1696V-12.2.1.3.0",
          "P-1696V-12.2.1.4.0"
        ],
        "known_not_affected": [
          "P-13373V-All Supported Versions"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13373V-All Supported Versions"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1696V-12.2.1.3.0",
            "P-1696V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-13373V-All Supported Versions"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-1696V-12.2.1.3.0",
            "P-1696V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-37714",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure (jsoup)).   The supported version that is affected is 14.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Trade Finance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Trade Finance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Treasury Management product of Oracle Financial Services Applications (component: Infrastructure (jsoup)).   The supported version that is affected is 14.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Treasury Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Treasury Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Installer (jsoup)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Process Management Suite. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure (jsoup)).  Supported versions that are affected are 14.0-14.3 and  14.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle FLEXCUBE Universal Banking. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hospitality Token Proxy Service product of Oracle Hospitality Applications (component: TPS Service (jsoup)).   The supported version that is affected is 19.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Token Proxy Service.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hospitality Token Proxy Service. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search (jsoup)).  Supported versions that are affected are 8.58 and  8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Segment  (jsoup)).  Supported versions that are affected are 17.0-19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Customer Management and Segmentation Foundation. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (jsoup)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14134V-14.5",
          "P-14133V-14.5",
          "P-5325V-12.2.1.3.0",
          "P-5325V-12.2.1.4.0",
          "P-9052V-14.0-14.3",
          "P-9052V-14.5",
          "P-13387V-19.2",
          "P-5085V-8.58",
          "P-5085V-8.59",
          "P-13388V-17.0-19.0",
          "P-1696V-12.2.1.3.0",
          "P-1696V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14134V-14.5",
            "P-14133V-14.5",
            "P-9052V-14.0-14.3",
            "P-9052V-14.5"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5325V-12.2.1.3.0",
            "P-5325V-12.2.1.4.0",
            "P-1696V-12.2.1.3.0",
            "P-1696V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13387V-19.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859245.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.58",
            "P-5085V-8.59"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858976.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13388V-17.0-19.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855697.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14134V-14.5",
            "P-14133V-14.5",
            "P-5325V-12.2.1.3.0",
            "P-5325V-12.2.1.4.0",
            "P-9052V-14.0-14.3",
            "P-9052V-14.5",
            "P-13387V-19.2",
            "P-5085V-8.58",
            "P-5085V-8.59",
            "P-13388V-17.0-19.0",
            "P-1696V-12.2.1.3.0",
            "P-1696V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-3807",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (ansi-regex)).   The supported version that is affected is 1.15.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.15.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.15.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-38153",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Apache Kafka)).   The supported version that is affected is 1.15.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Others (Apache Kafka)).  Supported versions that are affected are 8.0.6.0-8.0.9.0 and  8.1.0.0-8.1.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Third Party (Apache Kafka)).  Supported versions that are affected are 8.0.6.0-8.0.8.0, 8.1.1.0, 8.1.1.1 and  8.1.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Behavior Detection Platform accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Installers (Apache Kafka)).  Supported versions that are affected are 8.0.7.1, 8.0.7.2, 8.0.8.0, 8.0.8.1, 8.1.1.0 and  8.1.1.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Enterprise Case Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Financial Services Enterprise Case Management accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.15.0",
          "P-5680V-8.0.6.0-8.0.9.0",
          "P-5680V-8.1.0.0-8.1.2.0",
          "P-9190V-8.0.6.0-8.0.8.0",
          "P-9190V-8.1.1.0",
          "P-9190V-8.1.1.1",
          "P-9190V-8.1.2.0",
          "P-13545V-8.0.7.1",
          "P-13545V-8.0.7.2",
          "P-13545V-8.0.8.0",
          "P-13545V-8.0.8.1",
          "P-13545V-8.1.1.0",
          "P-13545V-8.1.1.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.0.6.0-8.0.9.0",
            "P-5680V-8.1.0.0-8.1.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856189.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9190V-8.0.6.0-8.0.8.0",
            "P-9190V-8.1.1.0",
            "P-9190V-8.1.1.1",
            "P-9190V-8.1.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2863604.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13545V-8.0.7.1",
            "P-13545V-8.0.7.2",
            "P-13545V-8.0.8.0",
            "P-13545V-8.0.8.1",
            "P-13545V-8.1.1.0",
            "P-13545V-8.1.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856550.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.15.0",
            "P-5680V-8.0.6.0-8.0.9.0",
            "P-5680V-8.1.0.0-8.1.2.0",
            "P-9190V-8.0.6.0-8.0.8.0",
            "P-9190V-8.1.1.0",
            "P-9190V-8.1.1.1",
            "P-9190V-8.1.2.0",
            "P-13545V-8.0.7.1",
            "P-13545V-8.0.7.2",
            "P-13545V-8.0.8.0",
            "P-13545V-8.0.8.1",
            "P-13545V-8.1.1.0",
            "P-13545V-8.1.1.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-39139",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (XStream)).   The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (XStream)).  Supported versions that are affected are 16.0.6, 17.0.4, 18.0.3, 19.0.2 and  20.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9633V-11.3.2",
          "P-11513V-16.0.6",
          "P-11513V-17.0.4",
          "P-11513V-18.0.3",
          "P-11513V-19.0.2",
          "P-11513V-20.0.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633V-11.3.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859309.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11513V-16.0.6",
            "P-11513V-17.0.4",
            "P-11513V-18.0.3",
            "P-11513V-19.0.2",
            "P-11513V-20.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855697.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9633V-11.3.2",
            "P-11513V-16.0.6",
            "P-11513V-17.0.4",
            "P-11513V-18.0.3",
            "P-11513V-19.0.2",
            "P-11513V-20.0.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-39140",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (XStream)).   The supported version that is affected is 1.14.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  While the vulnerability is in Oracle Communications Cloud Native Core Policy, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 6.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.14.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.14.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.14.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-39153",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Automated Test Suite Framework (XStream)).   The supported version that is affected is 1.9.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite.  While the vulnerability is in Oracle Communications Cloud Native Core Automated Test Suite, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14488V-1.9.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14488V-1.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859046.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14488V-1.9.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-39275",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener (Apache HTTP Server)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Operating System Image).   The supported version that is affected is 8.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle ZFS Storage Appliance Kit.  Successful attacks of this vulnerability can result in takeover of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1042V-12.2.1.3.0",
          "P-1042V-12.2.1.4.0",
          "P-10026V-8.8"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042V-12.2.1.3.0",
            "P-1042V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10026V-8.8"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857179.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-1042V-12.2.1.3.0",
            "P-1042V-12.2.1.4.0",
            "P-10026V-8.8"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-40438",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Enterprise Manager Ops Center product of Oracle Enterprise Manager (component: User Interface (Apache HTTP Server)).   The supported version that is affected is 12.4.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Ops Center.  While the vulnerability is in Enterprise Manager Ops Center, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Enterprise Manager Ops Center. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Web Server  (Apache HTTP Server)).   The supported version that is affected is 5.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Secure Global Desktop.  While the vulnerability is in Oracle Secure Global Desktop, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Secure Global Desktop. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9835V-12.4.0.0",
          "P-8539V-5.6"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9835V-12.4.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844807.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8539V-5.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859130.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-9835V-12.4.0.0",
            "P-8539V-5.6"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-40690",
      "notes": [
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Apache Santuario XML Security For Java)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications Applications (component: ISC (Apache Santuario XML Security For Java)).   The supported version that is affected is 8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Messaging Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Installation    (Apache Santuario XML Security For Java)).  Supported versions that are affected are 8.5.5 and  8.5.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Outside In Technology accessible data.  Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS Base Score depend on the software that uses Outside In Technology. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology, but if data is not received over a network the CVSS score may be lower. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security (Apache Santuario XML Security for Java)).  Supported versions that are affected are 8.58 and  8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Bulk Data Integration product of Oracle Retail Applications (component: BDI Job Scheduler (Apache Santuario XML Security For Java)).   The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Bulk Data Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Bulk Data Integration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration Bugs (Apache Santuario XML Security For Java)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Financial Integration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Apache Santuario XML Security For Java)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Integration Bus accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Merchandising System product of Oracle Retail Applications (component: Foundation (Apache Santuario XML Security For Java)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Merchandising System.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Merchandising System accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Apache Santuario XML Security For Java)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Service Backbone accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8496V-8.1",
          "P-2276V-8.5.5",
          "P-2276V-8.5.6",
          "P-5085V-8.58",
          "P-5085V-8.59",
          "P-12968V-16.0.3",
          "P-10722V-14.1.3.2",
          "P-10722V-15.0.3.1",
          "P-10722V-16.0.3",
          "P-10722V-19.0.1",
          "P-1807V-14.1.3.2",
          "P-1807V-15.0.3.1",
          "P-1807V-16.0.3",
          "P-1807V-19.0.1",
          "P-1816V-16.0.3",
          "P-1816V-19.0.1",
          "P-10867V-14.1.3.2",
          "P-10867V-15.0.3.1",
          "P-10867V-16.0.3",
          "P-10867V-19.0.1"
        ],
        "known_not_affected": [
          "P-14277V-All Supported Versions"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-All Supported Versions"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8496V-8.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856674.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2276V-8.5.5",
            "P-2276V-8.5.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.58",
            "P-5085V-8.59"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858976.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-12968V-16.0.3",
            "P-10722V-14.1.3.2",
            "P-10722V-15.0.3.1",
            "P-10722V-16.0.3",
            "P-10722V-19.0.1",
            "P-1807V-14.1.3.2",
            "P-1807V-15.0.3.1",
            "P-1807V-16.0.3",
            "P-1807V-19.0.1",
            "P-1816V-16.0.3",
            "P-1816V-19.0.1",
            "P-10867V-14.1.3.2",
            "P-10867V-15.0.3.1",
            "P-10867V-16.0.3",
            "P-10867V-19.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855697.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14277V-All Supported Versions"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8496V-8.1",
            "P-2276V-8.5.5",
            "P-2276V-8.5.6",
            "P-5085V-8.58",
            "P-5085V-8.59",
            "P-12968V-16.0.3",
            "P-10722V-14.1.3.2",
            "P-10722V-15.0.3.1",
            "P-10722V-16.0.3",
            "P-10722V-19.0.1",
            "P-1807V-14.1.3.2",
            "P-1807V-15.0.3.1",
            "P-1807V-16.0.3",
            "P-1807V-19.0.1",
            "P-1816V-16.0.3",
            "P-1816V-19.0.1",
            "P-10867V-14.1.3.2",
            "P-10867V-15.0.3.1",
            "P-10867V-16.0.3",
            "P-10867V-19.0.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-41165",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security (CKEditor)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as  unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Application Express (CKEditor) component of Oracle Database Server.   The supported version that is affected is Prior to 22.1. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express (CKEditor).  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express (CKEditor), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Application Express (CKEditor) accessible data as well as  unauthorized read access to a subset of Oracle Application Express (CKEditor) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (CKEditor)).   The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Commerce Guided Search accessible data as well as  unauthorized read access to a subset of Oracle Commerce Guided Search accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Rich Text Editor (CKEditor)).  Supported versions that are affected are 8.58 and  8.59. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (CKEditor)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data as well as  unauthorized read access to a subset of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4461V-9.3.6",
          "P-1348V-Prior to 22.1",
          "P-9633V-11.3.2",
          "P-5085V-8.58",
          "P-5085V-8.59",
          "P-1696V-12.2.1.3.0",
          "P-1696V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4461V-9.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858979.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1348V-Prior to 22.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633V-11.3.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859309.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.58",
            "P-5085V-8.59"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858976.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1696V-12.2.1.3.0",
            "P-1696V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4461V-9.3.6",
            "P-1348V-Prior to 22.1",
            "P-9633V-11.3.2",
            "P-5085V-8.58",
            "P-5085V-8.59",
            "P-1696V-12.2.1.3.0",
            "P-1696V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-41184",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Interactive Session Recorder product of Oracle Communications (component: Dashboard (jQueryUI)).   The supported version that is affected is 6.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Interactive Session Recorder.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Interactive Session Recorder, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Interactive Session Recorder accessible data as well as  unauthorized read access to a subset of Oracle Communications Interactive Session Recorder accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (jQueryUI)).  Supported versions that are affected are 4.3, 4.4 and  5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Operations Monitor, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Operations Monitor accessible data as well as  unauthorized read access to a subset of Oracle Communications Operations Monitor accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hospitality Suite8 product of Oracle Hospitality Applications (component: WebConnect (jQueryUI)).  Supported versions that are affected are 8.10.2 and  8.11.0-8.14.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Suite8.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Suite8, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hospitality Suite8 accessible data as well as  unauthorized read access to a subset of Oracle Hospitality Suite8 accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (jQueryUI)).  Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MySQL Enterprise Monitor, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Enterprise Monitor accessible data as well as  unauthorized read access to a subset of MySQL Enterprise Monitor accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: User Interface (jQueryUI)).  Supported versions that are affected are 17.7-17.12, 18.8, 19.12, 20.12 and  21.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Unifier, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera Unifier accessible data as well as  unauthorized read access to a subset of Primavera Unifier accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console, Samples (jQueryUI)).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10765V-6.4",
          "P-10761V-4.3",
          "P-10761V-4.4",
          "P-10761V-5.0",
          "P-12619V-8.10.2",
          "P-12619V-8.11.0-8.14.0",
          "P-8480V-8.0.29 and prior",
          "P-10354V-17.7-17.12",
          "P-10354V-18.8",
          "P-10354V-19.12",
          "P-10354V-20.12",
          "P-10354V-21.12",
          "P-5242V-12.2.1.3.0",
          "P-5242V-12.2.1.4.0",
          "P-5242V-14.1.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10765V-6.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859058.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10761V-4.3",
            "P-10761V-4.4",
            "P-10761V-5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859059.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-12619V-8.10.2",
            "P-12619V-8.11.0-8.14.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857213.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8480V-8.0.29 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10354V-17.7-17.12",
            "P-10354V-18.8",
            "P-10354V-19.12",
            "P-10354V-20.12",
            "P-10354V-21.12"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856639.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-12.2.1.3.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10765V-6.4",
            "P-10761V-4.3",
            "P-10761V-4.4",
            "P-10761V-5.0",
            "P-12619V-8.10.2",
            "P-12619V-8.11.0-8.14.0",
            "P-8480V-8.0.29 and prior",
            "P-10354V-17.7-17.12",
            "P-10354V-18.8",
            "P-10354V-19.12",
            "P-10354V-20.12",
            "P-10354V-21.12",
            "P-5242V-12.2.1.3.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.1.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-4160",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security (OpenSSL)).  Supported versions that are affected are 8.58 and  8.59. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.58",
          "P-5085V-8.59"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.58",
            "P-5085V-8.59"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858976.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.58",
            "P-5085V-8.59"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-41973",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Diagnostic Assistant (Apache MINA)).   The supported version that is affected is 2.12.42. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise OSS Support Tools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of OSS Support Tools. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1330V-2.12.42"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1330V-2.12.42"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-1330V-2.12.42"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-42013",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Upgrade SEC (Apache HTTP Server)).   The supported version that is affected is Prior to 9.2.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4781V-Prior to 9.2.6.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-Prior to 9.2.6.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858978.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4781V-Prior to 9.2.6.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-42340",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security (Apache Tomcat)).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Apache Tomcat)).   The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: SCP (Apache Tomcat)).   The supported version that is affected is 1.15.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Security (Apache Tomcat)).   The supported version that is affected is Prior to 9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Element Manager. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Instant Messaging Server product of Oracle Communications Applications (component: DBPlugin (Apache Tomcat)).   The supported version that is affected is 10.0.1.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Instant Messaging Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Instant Messaging Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: General (Apache Tomcat)).   The supported version that is affected is Prior to 9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Report Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Route Manager product of Oracle Communications (component: Third Party (Apache Tomcat)).   The supported version that is affected is Prior to 9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Route Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Route Manager. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Database Enterprise Edition (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Management Cloud Engine product of Oracle Communications (component: Security (Apache Tomcat)).   The supported version that is affected is Prior to 1.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Management Cloud Engine.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Management Cloud Engine. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (Apache Tomcat)).  Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Enterprise Monitor. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4461V-9.3.6",
          "P-9633V-11.3.2",
          "P-14117V-1.15.0",
          "P-11052V-Prior to 9.0",
          "P-8495V-10.0.1.5.0",
          "P-10770V-Prior to 9.0",
          "P-10771V-Prior to 9.0",
          "P-14252V-Prior to 1.5.0",
          "P-8480V-8.0.29 and prior"
        ],
        "known_not_affected": [
          "P-5(Oracle Database Enterprise Edition)V-All Supported Versions"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4461V-9.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858979.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633V-11.3.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859309.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14117V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859052.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11052V-Prior to 9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859056.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8495V-10.0.1.5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856674.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10770V-Prior to 9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859063.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10771V-Prior to 9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859064.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Oracle Database Enterprise Edition)V-All Supported Versions"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14252V-Prior to 1.5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859067.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8480V-8.0.29 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4461V-9.3.6",
            "P-9633V-11.3.2",
            "P-14117V-1.15.0",
            "P-11052V-Prior to 9.0",
            "P-8495V-10.0.1.5.0",
            "P-10770V-Prior to 9.0",
            "P-10771V-Prior to 9.0",
            "P-14252V-Prior to 1.5.0",
            "P-8480V-8.0.29 and prior"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Oracle Database Enterprise Edition)V-All Supported Versions"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-42392",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (H2)).   The supported version that is affected is 1.15.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.15.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.15.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-43527",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: BSF (NSS)).   The supported version that is affected is 1.11.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: OCNRF (NSS)).  Supported versions that are affected are 1.15.0 and  1.15.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: NSSF (NSS)).   The supported version that is affected is 1.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: CMP (NSS)).   The supported version that is affected is 12.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14121V-1.11.0",
          "P-14118V-1.15.0",
          "P-14118V-1.15.1",
          "P-14130V-1.8.0",
          "P-10900V-12.6.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-1.11.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859047.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118V-1.15.0",
            "P-14118V-1.15.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861796.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-1.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861807.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-12.6.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859061.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14121V-1.11.0",
            "P-14118V-1.15.0",
            "P-14118V-1.15.1",
            "P-14130V-1.8.0",
            "P-10900V-12.6.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-43797",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Configuration and Parsing (Netty)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Policy (Netty)).   The supported version that is affected is 1.11.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Binding Support Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: NSSF (Netty)).   The supported version that is affected is 1.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Network Slice Selection Function accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Netty)).   The supported version that is affected is 1.15.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Netty)).   The supported version that is affected is 1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: UDR (Netty)).   The supported version that is affected is 1.15.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Unified Data Repository accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications Applications (component: ISC (Netty)).   The supported version that is affected is 8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Messaging Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Messaging Server accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Reactive WebServer (Netty)).  Supported versions that are affected are 1.4.10 and 2.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Helidon accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search (Netty)).  Supported versions that are affected are 8.58 and  8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2545V-12.2.1.4.0",
          "P-2545V-14.1.1.0.0",
          "P-14121V-1.11.0",
          "P-14130V-1.8.0",
          "P-14277V-1.15.0",
          "P-14123V-1.7.0",
          "P-14119V-1.15.0",
          "P-8496V-8.1",
          "P-13972V-1.4.10",
          "P-13972V-2.4.0",
          "P-5085V-8.58",
          "P-5085V-8.59"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2545V-12.2.1.4.0",
            "P-2545V-14.1.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14121V-1.11.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859047.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-1.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861807.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14123V-1.7.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859050.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14119V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859053.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8496V-8.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856674.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13972V-1.4.10",
            "P-13972V-2.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2645279.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.58",
            "P-5085V-8.59"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858976.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-2545V-12.2.1.4.0",
            "P-2545V-14.1.1.0.0",
            "P-14121V-1.11.0",
            "P-14130V-1.8.0",
            "P-14277V-1.15.0",
            "P-14123V-1.7.0",
            "P-14119V-1.15.0",
            "P-8496V-8.1",
            "P-13972V-1.4.10",
            "P-13972V-2.4.0",
            "P-5085V-8.58",
            "P-5085V-8.59"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-43859",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Diameter Intelligence Hub product of Oracle Communications (component: Visualization, Database (XStream)).  Supported versions that are affected are 8.0.0-8.1.0 and  8.2.0-8.2.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Intelligence Hub.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Intelligence Hub. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: CMP (XStream)).   The supported version that is affected is 12.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Policy Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11126V-8.0.0-8.1.0",
          "P-11126V-8.2.0-8.2.3",
          "P-10900V-12.6.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11126V-8.0.0-8.1.0",
            "P-11126V-8.2.0-8.2.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859054.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-12.6.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859061.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-11126V-8.0.0-8.1.0",
            "P-11126V-8.2.0-8.2.3",
            "P-10900V-12.6.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-44224",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module  (Apache HTTP Server)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle HTTP Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1042V-12.2.1.3.0",
          "P-1042V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1042V-12.2.1.3.0",
            "P-1042V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
            "version": "3.1"
          },
          "products": [
            "P-1042V-12.2.1.3.0",
            "P-1042V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-44533",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search  (Node.js)).  Supported versions that are affected are 8.58 and  8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.58",
          "P-5085V-8.59"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.58",
            "P-5085V-8.59"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858976.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.58",
            "P-5085V-8.59"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-44790",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Security (Apache HTTP Server)).   The supported version that is affected is Prior to 9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Element Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (Apache HTTP Server)).  Supported versions that are affected are 4.3, 4.4 and  5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: General (Apache HTTP Server)).   The supported version that is affected is Prior to 9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Report Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Route Manager product of Oracle Communications (component: Third Party (Apache HTTP Server)).   The supported version that is affected is Prior to 9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Route Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Route Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in Oracle Secure Backup (component: Oracle Secure Backup (Apache HTTP Server)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11052V-Prior to 9.0",
          "P-10761V-4.3",
          "P-10761V-4.4",
          "P-10761V-5.0",
          "P-10770V-Prior to 9.0",
          "P-10771V-Prior to 9.0"
        ],
        "known_not_affected": [
          "P-1522V-All Supported Versions"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11052V-Prior to 9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859056.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10761V-4.3",
            "P-10761V-4.4",
            "P-10761V-5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859059.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10770V-Prior to 9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859063.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10771V-Prior to 9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859064.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1522V-All Supported Versions"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-11052V-Prior to 9.0",
            "P-10761V-4.3",
            "P-10761V-4.4",
            "P-10761V-5.0",
            "P-10770V-Prior to 9.0",
            "P-10771V-Prior to 9.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1522V-All Supported Versions"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2021-44832",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Installation Issues (Apache Log4j)).   The supported version that is affected is 6.2.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.  Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security (Apache Log4j)).   The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client (Apache Log4j)).   The supported version that is affected is 3.6. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector.  Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM MCAD Connector. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Autovue for Agile Product Lifecycle Management product of Oracle Supply Chain (component: Internal Operations (Apache Log4j)).   The supported version that is affected is 21.0.2. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Autovue for Agile Product Lifecycle Management.  Successful attacks of this vulnerability can result in takeover of Oracle Autovue for Agile Product Lifecycle Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Deposits and Lines of Credit Servicing product of Oracle Financial Services Applications (component: Web UI (Apache Log4j)).   The supported version that is affected is 2.12.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Deposits and Lines of Credit Servicing.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Deposits and Lines of Credit Servicing. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Enterprise Default Management product of Oracle Financial Services Applications (component: Collections (Apache Log4j)).  Supported versions that are affected are 2.7.1 and  2.12.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Enterprise Default Management.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Enterprise Default Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Loans Servicing product of Oracle Financial Services Applications (component: Web UI (Apache Log4j)).   The supported version that is affected is 2.12.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Loans Servicing.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Loans Servicing. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Party Management product of Oracle Financial Services Applications (component: Web UI (Apache Log4j)).   The supported version that is affected is 2.7.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Party Management.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Party Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Infrastructure (Apache Log4j)).   The supported version that is affected is 14.5. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Payments.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Payments. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Platform product of Oracle Financial Services Applications (component: SECURITY (Apache Log4j)).  Supported versions that are affected are 2.6.2, 2.7.1 and  2.12.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Platform. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure (Apache Log4j)).   The supported version that is affected is 14.5. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Trade Finance. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Treasury Management product of Oracle Financial Services Applications (component: Infrastructure (Apache Log4j)).   The supported version that is affected is 14.5. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Treasury Management.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Treasury Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications ASAP product of Oracle Communications Applications (component: SRP (Apache Log4j)).   The supported version that is affected is 7.3. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications ASAP.  Successful attacks of this vulnerability can result in takeover of Oracle Communications ASAP. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Rated Event Manager,  Business Operations Center,  Kafka Data Manager (Apache Log4j)).  Supported versions that are affected are 12.0.0.4 and  12.0.0.5. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: CNC Console (Apache Log4j)).   The supported version that is affected is 1.9.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: DBTier (Apache Log4j)).   The supported version that is affected is 1.10.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: OCNRF (Apache Log4j)).  Supported versions that are affected are 1.15.0 and  1.15.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: NSSF (Apache Log4j)).   The supported version that is affected is 1.8.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy  (Apache Log4j)).   The supported version that is affected is 1.15.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP (Apache Log4j)).   The supported version that is affected is 1.7.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: SCP (Apache Log4j)).   The supported version that is affected is 1.15.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: UDR (Apache Log4j)).   The supported version that is affected is 1.15.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Convergence product of Oracle Communications Applications (component: Configuration (Apache Log4j)).  Supported versions that are affected are 3.0.2.2 and  3.0.3.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Convergence.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Convergence. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications Applications (component: Network Gateway (Apache Log4j)).  Supported versions that are affected are 6.0.1.0.0 and  12.0.1.0.0-12.0.4.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Convergent Charging Controller.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Convergent Charging Controller. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications EAGLE Element Management System product of Oracle Communications (component: Platform (Apache Log4j)).   The supported version that is affected is 46.6. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications EAGLE Element Management System.  Successful attacks of this vulnerability can result in takeover of Oracle Communications EAGLE Element Management System. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications EAGLE FTP Table Base Retrieval product of Oracle Communications (component: Core (Apache Log4j)).   The supported version that is affected is 4.5. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications EAGLE FTP Table Base Retrieval.  Successful attacks of this vulnerability can result in takeover of Oracle Communications EAGLE FTP Table Base Retrieval. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Security (Apache Log4j)).   The supported version that is affected is Prior to 9.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Element Manager. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Evolved Communications Application Server product of Oracle Communications (component: SDC,SCF (Apache Log4j)).   The supported version that is affected is 7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Evolved Communications Application Server.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Evolved Communications Application Server. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications IP Service Activator product of Oracle Communications Applications (component: Logging (Apache Log4j)).   The supported version that is affected is 7.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications IP Service Activator.  Successful attacks of this vulnerability can result in takeover of Oracle Communications IP Service Activator. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications Applications (component: ISC (Apache Log4j)).   The supported version that is affected is 8.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Messaging Server. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications Applications (component: Gateway (Apache Log4j)).  Supported versions that are affected are 6.0.1.0.0 and  12.0.1.0.0-12.0.4.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Network Charging and Control.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Charging and Control. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Integrity product of Oracle Communications Applications (component: Cartridge Deployer Tool (Apache Log4j)).   The supported version that is affected is 7.3.6. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Network Integrity.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Integrity. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Performance Intelligence Center (PIC) Software product of Oracle Communications (component: Management (Apache Log4j)).   The supported version that is affected is 10.4.0.3. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Performance Intelligence Center (PIC) Software.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Performance Intelligence Center (PIC) Software. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: REST Services Manager (Apache Log4j)).  Supported versions that are affected are 12.0.0.4 and  12.0.0.5. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Pricing Design Center. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Services Gatekeeper product of Oracle Communications (component: OCSG common services - CORE (Apache Log4j)).   The supported version that is affected is 7.0.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Services Gatekeeper.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Services Gatekeeper. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: General (Apache Log4j)).   The supported version that is affected is Prior to 9.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Session Report Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Route Manager product of Oracle Communications (component: Third Party (Apache Log4j)).   The supported version that is affected is Prior to 9.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Session Route Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Route Manager. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Logging (Apache Log4j)).  Supported versions that are affected are 7.3.5 and  7.4.1-7.4.2. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Security (Apache Log4j)).   The supported version that is affected is 12.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications User Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications User Data Repository. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications WebRTC Session Controller product of Oracle Communications (component: Admin console, LWPR (Apache Log4j)).   The supported version that is affected is 7.2.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications WebRTC Session Controller.  Successful attacks of this vulnerability can result in takeover of Oracle Communications WebRTC Session Controller. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Runtime Java agent for ODI (Apache Log4j)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle E-Business Suite Information Discovery product of Oracle E-Business Suite (component: Logging (Apache Log4j)).  Supported versions that are affected are Enterprise Information Discovery: 7-9. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle E-Business Suite Information Discovery.  Successful attacks of this vulnerability can result in takeover of Oracle E-Business Suite Information Discovery.  Note: Oracle E-Business Suite version is 12.2. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Logging (Apache Log4j)).   The supported version that is affected is Enterprise Command Center: 7.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Command Center Framework.  Note: Oracle E-Business Suite version is 12.2. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install (Apache Log4j)).  Supported versions that are affected are 13.4.0.0 and  13.5.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in takeover of Enterprise Manager Base Platform. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Enterprise Manager Ops Center product of Oracle Enterprise Manager (component: Networking (Apache Log4j)).   The supported version that is affected is 12.4.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Ops Center.  Successful attacks of this vulnerability can result in takeover of Enterprise Manager Ops Center. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Enterprise Manager for Peoplesoft product of Oracle Enterprise Manager (component: PSEM Plugin (Apache Log4j)).  Supported versions that are affected are 13.4.1.1 and  13.5.1.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager for Peoplesoft.  Successful attacks of this vulnerability can result in takeover of Enterprise Manager for Peoplesoft. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure (Apache Log4j)).  Supported versions that are affected are 11.83.3, 12.1-12.4, 14.0-14.3 and  14.5. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking.  Successful attacks of this vulnerability can result in takeover of Oracle FLEXCUBE Universal Banking. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Health Sciences Empirica Signal product of Oracle Health Sciences Applications (component: Logging (Apache Log4j)).  Supported versions that are affected are 9.1.0.6 and  9.2.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Health Sciences Empirica Signal.  Successful attacks of this vulnerability can result in takeover of Oracle Health Sciences Empirica Signal. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Cognos logging (Apache Log4j)).  Supported versions that are affected are 6.2.1.1, 6.3.2.1 and  7.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Health Sciences InForm.  Successful attacks of this vulnerability can result in takeover of Oracle Health Sciences InForm. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Health Sciences Information Manager product of Oracle HealthCare Applications (component: Record Locator (Apache Log4j)).  Supported versions that are affected are 3.0.1-3.0.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Health Sciences Information Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Health Sciences Information Manager. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR (Apache Log4j)).   The supported version that is affected is 8.1.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Healthcare Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Data Repository. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Foundation product of Oracle HealthCare Applications (component: RPD Generation (Apache Log4j)).  Supported versions that are affected are 7.3.0.1-7.3.0.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Healthcare Foundation.  Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Foundation. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Master Person Index product of Oracle HealthCare Applications (component: IHE (Apache Log4j)).   The supported version that is affected is 5.0.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Healthcare Master Person Index.  Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Master Person Index. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Translational Research product of Oracle HealthCare Applications (component: Datastudio (Apache Log4j)).   The supported version that is affected is 4.1.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Healthcare Translational Research.  Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Translational Research. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hospitality Suite8 product of Oracle Hospitality Applications (component: Leisure (Apache Log4j)).  Supported versions that are affected are 8.13.0 and  8.14.0. Difficult to exploit vulnerability allows high privileged attacker with network access via TCP to compromise Oracle Hospitality Suite8.  Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Suite8. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hospitality Token Proxy Service product of Oracle Hospitality Applications (component: TPS Service (Apache Log4j)).   The supported version that is affected is 19.2. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality Token Proxy Service.  Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Token Proxy Service. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion BI+ product of Oracle Hyperion (component: Architect (Apache Log4j)).   The supported version that is affected is Prior to 11.2.8.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion BI+.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion BI+. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Installation/Configuration (Apache Log4j)).   The supported version that is affected is Prior to 11.2.8.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security (Apache Log4j)).   The supported version that is affected is Prior to 11.2.8.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration (Apache Log4j)).   The supported version that is affected is Prior to 11.2.8.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Planning product of Oracle Hyperion (component: Security (Apache Log4j)).   The supported version that is affected is Prior to 11.2.8.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Planning.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Planning. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Install (Apache Log4j)).   The supported version that is affected is Prior to 11.2.8.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Profitability and Cost Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Profitability and Cost Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Tax Provision product of Oracle Hyperion (component: Tax Provision (Apache Log4j)).   The supported version that is affected is Prior to 11.2.8.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Tax Provision.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Tax Provision. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Identity Management Suite product of Oracle Fusion Middleware (component: Installer (Apache Log4j)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Identity Management Suite.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Management Suite. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: General and Misc (Apache Log4j)).   The supported version that is affected is 9.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Identity Manager Connector.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Instantis EnterpriseTrack product of Oracle Construction and Engineering (component: Logging (Apache Log4j)).  Supported versions that are affected are 17.1, 17.2 and  17.3. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Instantis EnterpriseTrack.  Successful attacks of this vulnerability can result in takeover of Instantis EnterpriseTrack. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Insurance Data Gateway product of Oracle Insurance Applications (component: Security (Apache Log4j)).   The supported version that is affected is 1.0.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Insurance Data Gateway.  Successful attacks of this vulnerability can result in takeover of Oracle Insurance Data Gateway. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Insurance Insbridge Rating and Underwriting product of Oracle Insurance Applications (component: Framework Administrator IBFA (Apache Log4j)).  Supported versions that are affected are 5.2.0, 5.4.0-5.6.0 and  5.6.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Insurance Insbridge Rating and Underwriting.  Successful attacks of this vulnerability can result in takeover of Oracle Insurance Insbridge Rating and Underwriting. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Oracle JDeveloper (Apache Log4j)).   The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server (Apache Log4j)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer.  Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Management Cloud Engine product of Oracle Communications (component: Security (Apache Log4j)).   The supported version that is affected is 1.5.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Management Cloud Engine.  Successful attacks of this vulnerability can result in takeover of Management Cloud Engine. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (Apache Log4j)).  Supported versions that are affected are 8.0.29 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor.  Successful attacks of this vulnerability can result in takeover of MySQL Enterprise Monitor. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Payment Interface product of Oracle Hospitality Applications (component: OPI Core (Apache Log4j)).  Supported versions that are affected are 19.1 and  20.3. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Payment Interface.  Successful attacks of this vulnerability can result in takeover of Oracle Payment Interface. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security (Apache Log4j)).  Supported versions that are affected are 8.58 and  8.59. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Customer Insights product of Oracle Retail Applications (component: Other (Apache Log4j)).  Supported versions that are affected are 15.0.2 and  16.0.2. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Retail Customer Insights.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Customer Insights. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Data Extractor for Merchandising product of Oracle Retail Applications (component: Installer (Apache Log4j)).  Supported versions that are affected are 15.0.2 and  16.0.2. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Retail Data Extractor for Merchandising.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Data Extractor for Merchandising. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Installation (Apache Log4j)).  Supported versions that are affected are 17.0.2, 18.0.1, 19.0.1, 20.0.1 and  21.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Retail EFTLink.  Successful attacks of this vulnerability can result in takeover of Oracle Retail EFTLink. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration Bugs (Apache Log4j)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.1-16.0.3, 19.0.0 and  19.0.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Financial Integration. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Apache Log4j)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.1-16.0.3, 19.0.0 and  19.0.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Integration Bus. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Merchandising System product of Oracle Retail Applications (component: Foundation (Apache Log4j)).  Supported versions that are affected are 16.0.3 and  19.0.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Retail Merchandising System.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Merchandising System. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Apache Log4j)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.1-16.0.3, 19.0.0 and  19.0.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Store Inventory Management product of Oracle Retail Applications (component: SIM Integration (Apache Log4j)).  Supported versions that are affected are 14.0.4.13, 14.1.3.14, 14.1.3.5, 15.0.3.3, 15.0.3.8 and  16.0.3.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Retail Store Inventory Management.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Store Inventory Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle SQL Developer (component: Installation (Apache Log4j)).   The supported version that is affected is Prior to 21.4.2. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle SQL Developer.  Successful attacks of this vulnerability can result in takeover of Oracle SQL Developer. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Taleo Platform product of Oracle Taleo (component: Taleo Connect Client Installer (Apache Log4j)).   The supported version that is affected is Prior to 22.1. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Taleo Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Taleo Platform. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component: General (Apache Log4j)).  Supported versions that are affected are 4.3.0.1.0-4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0 and  4.4.0.3.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Utilities Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Framework. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (Apache Log4j)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Advanced UI  (Apache Log4j)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4436V-6.2.1.0",
          "P-4461V-9.3.6",
          "P-4440V-3.6",
          "P-4434V-21.0.2",
          "P-13928V-2.12.0",
          "P-13390V-2.7.1",
          "P-13390V-2.12.0",
          "P-13927V-2.12.0",
          "P-13929V-2.7.0",
          "P-13011V-14.5",
          "P-9178V-2.6.2",
          "P-9178V-2.7.1",
          "P-9178V-2.12.0",
          "P-14134V-14.5",
          "P-14133V-14.5",
          "P-2260V-7.3",
          "P-2136V-12.0.0.4",
          "P-2136V-12.0.0.5",
          "P-14250V-1.9.0",
          "P-14125V-1.10.0",
          "P-14118V-1.15.0",
          "P-14118V-1.15.1",
          "P-14130V-1.8.0",
          "P-14277V-1.15.0",
          "P-14123V-1.7.0",
          "P-14117V-1.15.0",
          "P-14119V-1.15.0",
          "P-8501V-3.0.2.2",
          "P-8501V-3.0.3.0",
          "P-12985V-6.0.1.0.0",
          "P-12985V-12.0.1.0.0-12.0.4.0.0",
          "P-11125V-46.6",
          "P-11116V-4.5",
          "P-11052V-Prior to 9.0",
          "P-10994V-7.1",
          "P-2261V-7.4.0",
          "P-8496V-8.1",
          "P-4623V-6.0.1.0.0",
          "P-4623V-12.0.1.0.0-12.0.4.0.0",
          "P-4491V-7.3.6",
          "P-11044V-10.4.0.3",
          "P-9437V-12.0.0.4",
          "P-9437V-12.0.0.5",
          "P-5381V-7.0.0.0.0",
          "P-10770V-Prior to 9.0",
          "P-10771V-Prior to 9.0",
          "P-4516V-7.3.5",
          "P-4516V-7.4.1-7.4.2",
          "P-11108V-12.4",
          "P-10811V-7.2.1",
          "P-2196V-12.2.1.3.0",
          "P-2196V-12.2.1.4.0",
          "P-10240V-Enterprise Information Discovery: 7-9",
          "P-13788V-Enterprise Command Center: 7.0",
          "P-1370V-13.4.0.0",
          "P-1370V-13.5.0.0",
          "P-9835V-12.4.0.0",
          "P-2131V-13.4.1.1",
          "P-2131V-13.5.1.1",
          "P-9052V-11.83.3",
          "P-9052V-12.1-12.4",
          "P-9052V-14.0-14.3",
          "P-9052V-14.5",
          "P-9646V-9.1.0.6",
          "P-9646V-9.2.0.0",
          "P-9636V-6.2.1.1",
          "P-9636V-6.3.2.1",
          "P-9636V-7.0.0.0",
          "P-9177V-3.0.1-3.0.4",
          "P-9161V-8.1.1",
          "P-12950V-7.3.0.1-7.3.0.4",
          "P-8575V-5.0.1",
          "P-9427V-4.1.1",
          "P-12619V-8.13.0",
          "P-12619V-8.14.0",
          "P-13387V-19.2",
          "P-4361V-Prior to 11.2.8.0",
          "P-4375V-Prior to 11.2.8.0",
          "P-4390V-Prior to 11.2.8.0",
          "P-4392V-Prior to 11.2.8.0",
          "P-4402V-Prior to 11.2.8.0",
          "P-4403V-Prior to 11.2.8.0",
          "P-10505V-Prior to 11.2.8.0",
          "P-1980V-12.2.1.3.0",
          "P-1980V-12.2.1.4.0",
          "P-1999V-9.1.0",
          "P-10563V-17.1",
          "P-10563V-17.2",
          "P-10563V-17.3",
          "P-13628V-1.0.1",
          "P-5484V-5.2.0",
          "P-5484V-5.4.0-5.6.0",
          "P-5484V-5.6.1",
          "P-807V-12.2.1.4.0",
          "P-10198V-12.2.1.3.0",
          "P-10198V-12.2.1.4.0",
          "P-14252V-1.5.0",
          "P-8480V-8.0.29 and prior",
          "P-13173V-19.1",
          "P-13173V-20.3",
          "P-5085V-8.58",
          "P-5085V-8.59",
          "P-10263V-15.0.2",
          "P-10263V-16.0.2",
          "P-12936V-15.0.2",
          "P-12936V-16.0.2",
          "P-11516V-17.0.2",
          "P-11516V-18.0.1",
          "P-11516V-19.0.1",
          "P-11516V-20.0.1",
          "P-11516V-21.0.0",
          "P-10722V-14.1.3.2",
          "P-10722V-15.0.3.1",
          "P-10722V-16.0.1-16.0.3",
          "P-10722V-19.0.0",
          "P-10722V-19.0.1",
          "P-1807V-14.1.3.2",
          "P-1807V-15.0.3.1",
          "P-1807V-16.0.1-16.0.3",
          "P-1807V-19.0.0",
          "P-1807V-19.0.1",
          "P-1816V-16.0.3",
          "P-1816V-19.0.1",
          "P-10867V-14.1.3.2",
          "P-10867V-15.0.3.1",
          "P-10867V-16.0.1-16.0.3",
          "P-10867V-19.0.0",
          "P-10867V-19.0.1",
          "P-1838V-14.0.4.13",
          "P-1838V-14.1.3.14",
          "P-1838V-14.1.3.5",
          "P-1838V-15.0.3.3",
          "P-1838V-15.0.3.8",
          "P-1838V-16.0.3.7",
          "P-1875V-Prior to 21.4.2",
          "P-9830V-Prior to 22.1",
          "P-2245V-4.3.0.1.0-4.3.0.6.0",
          "P-2245V-4.4.0.0.0",
          "P-2245V-4.4.0.2.0",
          "P-2245V-4.4.0.3.0",
          "P-1696V-12.2.1.3.0",
          "P-1696V-12.2.1.4.0",
          "P-9617V-12.2.1.3.0",
          "P-9617V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4436V-6.2.1.0",
            "P-4461V-9.3.6",
            "P-4440V-3.6",
            "P-4434V-21.0.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858979.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13928V-2.12.0",
            "P-13927V-2.12.0",
            "P-13011V-14.5",
            "P-14134V-14.5",
            "P-14133V-14.5",
            "P-9052V-11.83.3",
            "P-9052V-12.1-12.4",
            "P-9052V-14.0-14.3",
            "P-9052V-14.5"
          ],
          "url": "https://support.oracle.com"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13390V-2.7.1",
            "P-13390V-2.12.0",
            "P-13929V-2.7.0",
            "P-9178V-2.6.2",
            "P-9178V-2.7.1",
            "P-9178V-2.12.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861653.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2260V-7.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856716.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2136V-12.0.0.4",
            "P-2136V-12.0.0.5",
            "P-9437V-12.0.0.4",
            "P-9437V-12.0.0.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856675.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-1.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859048.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14125V-1.10.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861795.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118V-1.15.0",
            "P-14118V-1.15.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861796.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-1.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861807.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14123V-1.7.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859050.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14117V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859052.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14119V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859053.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8501V-3.0.2.2",
            "P-8501V-3.0.3.0",
            "P-8496V-8.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856674.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-12985V-6.0.1.0.0",
            "P-12985V-12.0.1.0.0-12.0.4.0.0",
            "P-4623V-6.0.1.0.0",
            "P-4623V-12.0.1.0.0-12.0.4.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856694.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11125V-46.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859068.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11116V-4.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861832.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11052V-Prior to 9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859056.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10994V-7.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859057.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2261V-7.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856708.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4491V-7.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856673.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11044V-10.4.0.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859060.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5381V-7.0.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859062.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10770V-Prior to 9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859063.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10771V-Prior to 9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859064.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.3.5",
            "P-4516V-7.4.1-7.4.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856709.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11108V-12.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2862337.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10811V-7.2.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861922.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2196V-12.2.1.3.0",
            "P-2196V-12.2.1.4.0",
            "P-1980V-12.2.1.3.0",
            "P-1980V-12.2.1.4.0",
            "P-1999V-9.1.0",
            "P-807V-12.2.1.4.0",
            "P-10198V-12.2.1.3.0",
            "P-10198V-12.2.1.4.0",
            "P-1696V-12.2.1.3.0",
            "P-1696V-12.2.1.4.0",
            "P-9617V-12.2.1.3.0",
            "P-9617V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10240V-Enterprise Information Discovery: 7-9",
            "P-13788V-Enterprise Command Center: 7.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1370V-13.4.0.0",
            "P-1370V-13.5.0.0",
            "P-9835V-12.4.0.0",
            "P-2131V-13.4.1.1",
            "P-2131V-13.5.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844807.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9646V-9.1.0.6",
            "P-9646V-9.2.0.0",
            "P-9636V-6.2.1.1",
            "P-9636V-6.3.2.1",
            "P-9636V-7.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2854079.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9177V-3.0.1-3.0.4",
            "P-9161V-8.1.1",
            "P-12950V-7.3.0.1-7.3.0.4",
            "P-8575V-5.0.1",
            "P-9427V-4.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2862542.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-12619V-8.13.0",
            "P-12619V-8.14.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857213.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13387V-19.2",
            "P-13173V-19.1",
            "P-13173V-20.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859245.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4361V-Prior to 11.2.8.0",
            "P-4375V-Prior to 11.2.8.0",
            "P-4390V-Prior to 11.2.8.0",
            "P-4392V-Prior to 11.2.8.0",
            "P-4402V-Prior to 11.2.8.0",
            "P-4403V-Prior to 11.2.8.0",
            "P-10505V-Prior to 11.2.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2775466.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10563V-17.1",
            "P-10563V-17.2",
            "P-10563V-17.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856639.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13628V-1.0.1",
            "P-5484V-5.2.0",
            "P-5484V-5.4.0-5.6.0",
            "P-5484V-5.6.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857284.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14252V-1.5.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859067.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8480V-8.0.29 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.58",
            "P-5085V-8.59"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858976.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10263V-15.0.2",
            "P-10263V-16.0.2",
            "P-12936V-15.0.2",
            "P-12936V-16.0.2",
            "P-11516V-17.0.2",
            "P-11516V-18.0.1",
            "P-11516V-19.0.1",
            "P-11516V-20.0.1",
            "P-11516V-21.0.0",
            "P-10722V-14.1.3.2",
            "P-10722V-15.0.3.1",
            "P-10722V-16.0.1-16.0.3",
            "P-10722V-19.0.0",
            "P-10722V-19.0.1",
            "P-1807V-14.1.3.2",
            "P-1807V-15.0.3.1",
            "P-1807V-16.0.1-16.0.3",
            "P-1807V-19.0.0",
            "P-1807V-19.0.1",
            "P-1816V-16.0.3",
            "P-1816V-19.0.1",
            "P-10867V-14.1.3.2",
            "P-10867V-15.0.3.1",
            "P-10867V-16.0.1-16.0.3",
            "P-10867V-19.0.0",
            "P-10867V-19.0.1",
            "P-1838V-14.0.4.13",
            "P-1838V-14.1.3.14",
            "P-1838V-14.1.3.5",
            "P-1838V-15.0.3.3",
            "P-1838V-15.0.3.8",
            "P-1838V-16.0.3.7"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855697.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1875V-Prior to 21.4.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9830V-Prior to 22.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2862405.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2245V-4.3.0.1.0-4.3.0.6.0",
            "P-2245V-4.4.0.0.0",
            "P-2245V-4.4.0.2.0",
            "P-2245V-4.4.0.3.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856383.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.6,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4436V-6.2.1.0",
            "P-4461V-9.3.6",
            "P-4440V-3.6",
            "P-4434V-21.0.2",
            "P-13928V-2.12.0",
            "P-13390V-2.7.1",
            "P-13390V-2.12.0",
            "P-13927V-2.12.0",
            "P-13929V-2.7.0",
            "P-13011V-14.5",
            "P-9178V-2.6.2",
            "P-9178V-2.7.1",
            "P-9178V-2.12.0",
            "P-14134V-14.5",
            "P-14133V-14.5",
            "P-2260V-7.3",
            "P-2136V-12.0.0.4",
            "P-2136V-12.0.0.5",
            "P-14250V-1.9.0",
            "P-14125V-1.10.0",
            "P-14118V-1.15.0",
            "P-14118V-1.15.1",
            "P-14130V-1.8.0",
            "P-14277V-1.15.0",
            "P-14123V-1.7.0",
            "P-14117V-1.15.0",
            "P-14119V-1.15.0",
            "P-8501V-3.0.2.2",
            "P-8501V-3.0.3.0",
            "P-12985V-6.0.1.0.0",
            "P-12985V-12.0.1.0.0-12.0.4.0.0",
            "P-11125V-46.6",
            "P-11116V-4.5",
            "P-11052V-Prior to 9.0",
            "P-10994V-7.1",
            "P-2261V-7.4.0",
            "P-8496V-8.1",
            "P-4623V-6.0.1.0.0",
            "P-4623V-12.0.1.0.0-12.0.4.0.0",
            "P-4491V-7.3.6",
            "P-11044V-10.4.0.3",
            "P-9437V-12.0.0.4",
            "P-9437V-12.0.0.5",
            "P-5381V-7.0.0.0.0",
            "P-10770V-Prior to 9.0",
            "P-10771V-Prior to 9.0",
            "P-4516V-7.3.5",
            "P-4516V-7.4.1-7.4.2",
            "P-11108V-12.4",
            "P-10811V-7.2.1",
            "P-2196V-12.2.1.3.0",
            "P-2196V-12.2.1.4.0",
            "P-10240V-Enterprise Information Discovery: 7-9",
            "P-13788V-Enterprise Command Center: 7.0",
            "P-1370V-13.4.0.0",
            "P-1370V-13.5.0.0",
            "P-9835V-12.4.0.0",
            "P-2131V-13.4.1.1",
            "P-2131V-13.5.1.1",
            "P-9052V-11.83.3",
            "P-9052V-12.1-12.4",
            "P-9052V-14.0-14.3",
            "P-9052V-14.5",
            "P-9646V-9.1.0.6",
            "P-9646V-9.2.0.0",
            "P-9636V-6.2.1.1",
            "P-9636V-6.3.2.1",
            "P-9636V-7.0.0.0",
            "P-9177V-3.0.1-3.0.4",
            "P-9161V-8.1.1",
            "P-12950V-7.3.0.1-7.3.0.4",
            "P-8575V-5.0.1",
            "P-9427V-4.1.1",
            "P-12619V-8.13.0",
            "P-12619V-8.14.0",
            "P-13387V-19.2",
            "P-4361V-Prior to 11.2.8.0",
            "P-4375V-Prior to 11.2.8.0",
            "P-4390V-Prior to 11.2.8.0",
            "P-4392V-Prior to 11.2.8.0",
            "P-4402V-Prior to 11.2.8.0",
            "P-4403V-Prior to 11.2.8.0",
            "P-10505V-Prior to 11.2.8.0",
            "P-1980V-12.2.1.3.0",
            "P-1980V-12.2.1.4.0",
            "P-1999V-9.1.0",
            "P-10563V-17.1",
            "P-10563V-17.2",
            "P-10563V-17.3",
            "P-13628V-1.0.1",
            "P-5484V-5.2.0",
            "P-5484V-5.4.0-5.6.0",
            "P-5484V-5.6.1",
            "P-807V-12.2.1.4.0",
            "P-10198V-12.2.1.3.0",
            "P-10198V-12.2.1.4.0",
            "P-14252V-1.5.0",
            "P-8480V-8.0.29 and prior",
            "P-13173V-19.1",
            "P-13173V-20.3",
            "P-5085V-8.58",
            "P-5085V-8.59",
            "P-10263V-15.0.2",
            "P-10263V-16.0.2",
            "P-12936V-15.0.2",
            "P-12936V-16.0.2",
            "P-11516V-17.0.2",
            "P-11516V-18.0.1",
            "P-11516V-19.0.1",
            "P-11516V-20.0.1",
            "P-11516V-21.0.0",
            "P-10722V-14.1.3.2",
            "P-10722V-15.0.3.1",
            "P-10722V-16.0.1-16.0.3",
            "P-10722V-19.0.0",
            "P-10722V-19.0.1",
            "P-1807V-14.1.3.2",
            "P-1807V-15.0.3.1",
            "P-1807V-16.0.1-16.0.3",
            "P-1807V-19.0.0",
            "P-1807V-19.0.1",
            "P-1816V-16.0.3",
            "P-1816V-19.0.1",
            "P-10867V-14.1.3.2",
            "P-10867V-15.0.3.1",
            "P-10867V-16.0.1-16.0.3",
            "P-10867V-19.0.0",
            "P-10867V-19.0.1",
            "P-1838V-14.0.4.13",
            "P-1838V-14.1.3.14",
            "P-1838V-14.1.3.5",
            "P-1838V-15.0.3.3",
            "P-1838V-15.0.3.8",
            "P-1838V-16.0.3.7",
            "P-1875V-Prior to 21.4.2",
            "P-9830V-Prior to 22.1",
            "P-2245V-4.3.0.1.0-4.3.0.6.0",
            "P-2245V-4.4.0.0.0",
            "P-2245V-4.4.0.2.0",
            "P-2245V-4.4.0.3.0",
            "P-1696V-12.2.1.3.0",
            "P-1696V-12.2.1.4.0",
            "P-9617V-12.2.1.3.0",
            "P-9617V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-0778",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Node  (OpenSSL)).  Supported versions that are affected are Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and  22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GraalVM Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++ (OpenSSL)).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC (OpenSSL)).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (OpenSSL)).  Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Enterprise Monitor. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging   (OpenSSL)).  Supported versions that are affected are 5.7.37 and prior and   8.0.28 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: Workbench: libssh (OpenSSL)).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5",
          "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
          "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2",
          "P-8576(Connector/C++)V-8.0.28 and prior",
          "P-8576(Connector/ODBC)V-8.0.28 and prior",
          "P-8480V-8.0.29 and prior",
          "P-8478V-5.7.37 and prior",
          "P-8478V-8.0.28 and prior",
          "P-4627V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5",
            "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
            "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855980.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8576(Connector/C++)V-8.0.28 and prior",
            "P-8576(Connector/ODBC)V-8.0.28 and prior",
            "P-8480V-8.0.29 and prior",
            "P-8478V-5.7.37 and prior",
            "P-8478V-8.0.28 and prior",
            "P-4627V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5",
            "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
            "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2",
            "P-8576(Connector/C++)V-8.0.28 and prior",
            "P-8576(Connector/ODBC)V-8.0.28 and prior",
            "P-8480V-8.0.29 and prior",
            "P-8478V-5.7.37 and prior",
            "P-8478V-8.0.28 and prior",
            "P-4627V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-20612",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Automated Test Suite Framework  (Jenkins)).   The supported version that is affected is 1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Automated Test Suite accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14488V-1.9.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14488V-1.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859046.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14488V-1.9.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-20613",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Automated Test Suite (Jenkins Mailer)).   The supported version that is affected is 1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Automated Test Suite accessible data. CVSS 3.1 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14488V-1.9.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14488V-1.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859046.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14488V-1.9.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-20615",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Automated Test Suite Framework (Jenkins Matrix Project)).   The supported version that is affected is 1.9.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Cloud Native Core Automated Test Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Automated Test Suite accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Automated Test Suite accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14488V-1.9.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14488V-1.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859046.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-14488V-1.9.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Paulino Calderon"
          ],
          "organization": "websec mx"
        }
      ],
      "cve": "CVE-2022-21404",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Reactive WebServer).  Supported versions that are affected are 1.4.10 and  2.0.0-RC1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13972V-1.4.10",
          "P-13972V-2.0.0-RC1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13972V-1.4.10",
            "P-13972V-2.0.0-RC1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2645279.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-13972V-1.4.10",
            "P-13972V-2.0.0-RC1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21405",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Oracle Explorer).   The supported version that is affected is 18.3. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where OSS Support Tools executes to compromise OSS Support Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in OSS Support Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all OSS Support Tools accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1330V-18.3"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1330V-18.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1330V-18.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21409",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime).   The supported version that is affected is Prior to 9.2.6.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4781(Web Runtime)V-Prior to 9.2.6.3"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781(Web Runtime)V-Prior to 9.2.6.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858978.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4781(Web Runtime)V-Prior to 9.2.6.3"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Alexander Kornbrust"
          ],
          "organization": "Red Database Security"
        },
        {
          "names": [
            "Emad Al-Mousa"
          ]
        }
      ],
      "cve": "CVE-2022-21410",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Database - Enterprise Edition Sharding component of Oracle Database Server.   The supported version that is affected is 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Sharding.  Successful attacks of this vulnerability can result in takeover of Oracle Database - Enterprise Edition Sharding. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(Oracle Database - Enterprise Edition Sharding)V-19c"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Oracle Database - Enterprise Edition Sharding)V-19c"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5(Oracle Database - Enterprise Edition Sharding)V-19c"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Harrison Neal"
          ]
        }
      ],
      "cve": "CVE-2022-21411",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the RDBMS Gateway / Generic ODBC Connectivity component of Oracle Database Server.  Supported versions that are affected are 12.1.0.2, 19c and  21c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise RDBMS Gateway / Generic ODBC Connectivity.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of RDBMS Gateway / Generic ODBC Connectivity accessible data as well as  unauthorized read access to a subset of RDBMS Gateway / Generic ODBC Connectivity accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(RDBMS Gateway / Generic ODBC Connectivity)V-12.1.0.2",
          "P-5(RDBMS Gateway / Generic ODBC Connectivity)V-19c",
          "P-5(RDBMS Gateway / Generic ODBC Connectivity)V-21c"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(RDBMS Gateway / Generic ODBC Connectivity)V-12.1.0.2",
            "P-5(RDBMS Gateway / Generic ODBC Connectivity)V-19c",
            "P-5(RDBMS Gateway / Generic ODBC Connectivity)V-21c"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(RDBMS Gateway / Generic ODBC Connectivity)V-12.1.0.2",
            "P-5(RDBMS Gateway / Generic ODBC Connectivity)V-19c",
            "P-5(RDBMS Gateway / Generic ODBC Connectivity)V-21c"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21412",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21413",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21414",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21415",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21416",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility).   The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Solaris accessible data. CVSS 3.1 Base Score 5.0 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10006V-11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10006V-11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857179.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10006V-11"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21417",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 5.7.37 and prior and  8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-5.7.37 and prior",
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-5.7.37 and prior",
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-5.7.37 and prior",
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21418",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.0 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "AnhNH"
          ],
          "organization": "Sacombank"
        },
        {
          "names": [
            "ChauUHM"
          ],
          "organization": "Sacombank"
        },
        {
          "names": [
            "TuanNT"
          ],
          "organization": "Sacombank"
        },
        {
          "names": [
            "TungHT"
          ],
          "organization": "Sacombank"
        }
      ],
      "cve": "CVE-2022-21419",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Visual Analyzer).  Supported versions that are affected are 5.5.0.0.0 and  5.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2025V-5.5.0.0.0",
          "P-2025V-5.9.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-5.5.0.0.0",
            "P-2025V-5.9.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853459.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-2025V-5.5.0.0.0",
            "P-2025V-5.9.0.0.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Cl0und"
          ],
          "organization": "Syclover Security Team"
        },
        {
          "names": [
            "Liboheng"
          ],
          "organization": "Tophant Starlight laboratory"
        }
      ],
      "cve": "CVE-2022-21420",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2545V-12.2.1.3.0",
          "P-2545V-12.2.1.4.0",
          "P-2545V-14.1.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2545V-12.2.1.3.0",
            "P-2545V-12.2.1.4.0",
            "P-2545V-14.1.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2545V-12.2.1.3.0",
            "P-2545V-12.2.1.4.0",
            "P-2545V-14.1.1.0.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "r00t4dm"
          ]
        }
      ],
      "cve": "CVE-2022-21421",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General).  Supported versions that are affected are 5.5.0.0.0, 5.9.0.0.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2025V-5.5.0.0.0",
          "P-2025V-5.9.0.0.0",
          "P-2025V-12.2.1.3.0",
          "P-2025V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-5.5.0.0.0",
            "P-2025V-5.9.0.0.0",
            "P-2025V-12.2.1.3.0",
            "P-2025V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853459.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-2025V-5.5.0.0.0",
            "P-2025V-5.9.0.0.0",
            "P-2025V-12.2.1.3.0",
            "P-2025V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21422",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager).  Supported versions that are affected are 12.0.0.4 and  12.0.0.5. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2136V-12.0.0.4",
          "P-2136V-12.0.0.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2136V-12.0.0.4",
            "P-2136V-12.0.0.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856675.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2136V-12.0.0.4",
            "P-2136V-12.0.0.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21423",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21424",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager).   The supported version that is affected is 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Billing and Revenue Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Billing and Revenue Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2136V-12.0.0.4"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2136V-12.0.0.4"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856675.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "P-2136V-12.0.0.4"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21425",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21426",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP).  Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and  22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-Oracle Java SE:7u331",
          "P-856V-Oracle Java SE:8u321",
          "P-856V-Oracle Java SE:11.0.14",
          "P-856V-Oracle Java SE:17.0.2",
          "P-856V-Oracle Java SE:18",
          "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5",
          "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
          "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-Oracle Java SE:7u331",
            "P-856V-Oracle Java SE:8u321",
            "P-856V-Oracle Java SE:11.0.14",
            "P-856V-Oracle Java SE:17.0.2",
            "P-856V-Oracle Java SE:18",
            "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5",
            "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
            "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855980.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-856V-Oracle Java SE:7u331",
            "P-856V-Oracle Java SE:8u321",
            "P-856V-Oracle Java SE:11.0.14",
            "P-856V-Oracle Java SE:17.0.2",
            "P-856V-Oracle Java SE:18",
            "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5",
            "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
            "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21427",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS).  Supported versions that are affected are 5.7.37 and prior and  8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-5.7.37 and prior",
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-5.7.37 and prior",
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-5.7.37 and prior",
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21430",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager).  Supported versions that are affected are 12.0.0.4 and  12.0.0.5. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Communications Billing and Revenue Management.  While the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2136V-12.0.0.4",
          "P-2136V-12.0.0.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2136V-12.0.0.4",
            "P-2136V-12.0.0.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856675.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2136V-12.0.0.4",
            "P-2136V-12.0.0.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21431",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager).  Supported versions that are affected are 12.0.0.4 and  12.0.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Billing and Revenue Management.  While the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2136V-12.0.0.4",
          "P-2136V-12.0.0.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2136V-12.0.0.4",
            "P-2136V-12.0.0.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856675.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 10,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2136V-12.0.0.4",
            "P-2136V-12.0.0.5"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "osword from SGLAB"
          ],
          "organization": "Legendsec at Qi'anxin Group"
        }
      ],
      "cve": "CVE-2022-21434",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and  22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-Oracle Java SE:7u331",
          "P-856V-Oracle Java SE:8u321",
          "P-856V-Oracle Java SE:11.0.14",
          "P-856V-Oracle Java SE:17.0.2",
          "P-856V-Oracle Java SE:18",
          "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5",
          "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
          "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-Oracle Java SE:7u331",
            "P-856V-Oracle Java SE:8u321",
            "P-856V-Oracle Java SE:11.0.14",
            "P-856V-Oracle Java SE:17.0.2",
            "P-856V-Oracle Java SE:18",
            "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5",
            "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
            "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855980.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-856V-Oracle Java SE:7u331",
            "P-856V-Oracle Java SE:8u321",
            "P-856V-Oracle Java SE:11.0.14",
            "P-856V-Oracle Java SE:17.0.2",
            "P-856V-Oracle Java SE:18",
            "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5",
            "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
            "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21435",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21436",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21437",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Shihao Wen"
          ]
        }
      ],
      "cve": "CVE-2022-21438",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21440",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "4ra1n"
          ]
        },
        {
          "names": [
            "r00t4dm"
          ]
        }
      ],
      "cve": "CVE-2022-21441",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3/IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5242V-12.2.1.3.0",
          "P-5242V-12.2.1.4.0",
          "P-5242V-14.1.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-12.2.1.3.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5242V-12.2.1.3.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.1.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21442",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in Oracle GoldenGate (component: OGG Core Library).   The supported version that is affected is Prior to 23.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate.  While the vulnerability is in Oracle GoldenGate, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5757V-Prior to 23.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5757V-Prior to 23.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-5757V-Prior to 23.1"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Markus Loewe"
          ]
        }
      ],
      "cve": "CVE-2022-21443",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and  22.0.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-Oracle Java SE:7u331",
          "P-856V-Oracle Java SE:8u321",
          "P-856V-Oracle Java SE:11.0.14",
          "P-856V-Oracle Java SE:17.0.2",
          "P-856V-Oracle Java SE:18",
          "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5",
          "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
          "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-Oracle Java SE:7u331",
            "P-856V-Oracle Java SE:8u321",
            "P-856V-Oracle Java SE:11.0.14",
            "P-856V-Oracle Java SE:17.0.2",
            "P-856V-Oracle Java SE:18",
            "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5",
            "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
            "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855980.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-856V-Oracle Java SE:7u331",
            "P-856V-Oracle Java SE:8u321",
            "P-856V-Oracle Java SE:11.0.14",
            "P-856V-Oracle Java SE:17.0.2",
            "P-856V-Oracle Java SE:18",
            "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5",
            "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
            "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21444",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL).  Supported versions that are affected are 5.7.37 and prior and  8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-5.7.37 and prior",
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-5.7.37 and prior",
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-5.7.37 and prior",
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Jangggg"
          ],
          "organization": "VNPT"
        },
        {
          "names": [
            "peterjson  - Security Engineering - VNG Corporation"
          ]
        }
      ],
      "cve": "CVE-2022-21445",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Development Framework (ADF).  Successful attacks of this vulnerability can result in takeover of Oracle Application Development Framework (ADF). Note: Oracle Application Development Framework (ADF) is downloaded via Oracle JDeveloper Product. Please refer to Fusion Middleware Patch Advisor for more details. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-807V-12.2.1.3.0",
          "P-807V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-807V-12.2.1.3.0",
            "P-807V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-807V-12.2.1.3.0",
            "P-807V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21446",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility).   The supported version that is affected is 11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Solaris accessible data as well as  unauthorized read access to a subset of Oracle Solaris accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10006V-11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10006V-11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857179.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10006V-11"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21447",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise CS Academic Advisement product of Oracle PeopleSoft (component: Advising Notes).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Academic Advisement.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Academic Advisement accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5181V-9.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5181V-9.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858976.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5181V-9.2"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "AnhNH"
          ],
          "organization": "Sacombank"
        },
        {
          "names": [
            "ChauUHM"
          ],
          "organization": "Sacombank"
        },
        {
          "names": [
            "TuanNT"
          ],
          "organization": "Sacombank"
        },
        {
          "names": [
            "TungHT"
          ],
          "organization": "Sacombank"
        }
      ],
      "cve": "CVE-2022-21448",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Visual Analyzer).   The supported version that is affected is 5.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2025V-5.9.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-5.9.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853459.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-2025V-5.9.0.0.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Neil Madden"
          ],
          "organization": "ForgeRock"
        }
      ],
      "cve": "CVE-2022-21449",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Oracle Java SE: 17.0.2, 18; Oracle GraalVM Enterprise Edition: 21.3.1 and  22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-Oracle Java SE:17.0.2",
          "P-856V-Oracle Java SE:18",
          "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
          "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-Oracle Java SE:17.0.2",
            "P-856V-Oracle Java SE:18",
            "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
            "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855980.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-856V-Oracle Java SE:17.0.2",
            "P-856V-Oracle Java SE:18",
            "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
            "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Vikas Khanna"
          ]
        }
      ],
      "cve": "CVE-2022-21450",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub product of Oracle PeopleSoft (component: My Links).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PRTL Interaction Hub accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5090V-9.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5090V-9.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858976.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5090V-9.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21451",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 5.7.37 and prior and  8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-5.7.37 and prior",
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-5.7.37 and prior",
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-5.7.37 and prior",
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21452",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "wangze from Codesafe Team"
          ],
          "organization": "Legendsec at Qi"
        }
      ],
      "cve": "CVE-2022-21453",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5242V-12.2.1.3.0",
          "P-5242V-12.2.1.4.0",
          "P-5242V-14.1.1.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-12.2.1.3.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5242V-12.2.1.3.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.1.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21454",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin).  Supported versions that are affected are 5.7.37 and prior and  8.0.28 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-5.7.37 and prior",
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-5.7.37 and prior",
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-5.7.37 and prior",
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21456",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Navigation Pages, Portal, Query).  Supported versions that are affected are 8.58 and  8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.58",
          "P-5085V-8.59"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.58",
            "P-5085V-8.59"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858976.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.58",
            "P-5085V-8.59"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21457",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PAM Auth Plugin).  Supported versions that are affected are 8.0.28 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21458",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Navigation Pages, Portal, Query).  Supported versions that are affected are 8.58 and  8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.58",
          "P-5085V-8.59"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.58",
            "P-5085V-8.59"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858976.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.58",
            "P-5085V-8.59"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Shihao Wen"
          ]
        }
      ],
      "cve": "CVE-2022-21459",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21460",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Logging).  Supported versions that are affected are 5.7.37 and prior and  8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-5.7.37 and prior",
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-5.7.37 and prior",
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8478V-5.7.37 and prior",
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21461",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel).   The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Solaris accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10006V-11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10006V-11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857179.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-10006V-11"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21462",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21463",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel).   The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10006V-11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10006V-11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857179.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10006V-11"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21464",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC).   The supported version that is affected is Prior to 9.2.6.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools and  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4781V-Prior to 9.2.6.3"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4781V-Prior to 9.2.6.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858978.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-4781V-Prior to 9.2.6.3"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Aobo Wang"
          ],
          "organization": "Chaitin Security Research Lab"
        },
        {
          "names": [
            "Kun Yang"
          ],
          "organization": "Chaitin Security Research Lab"
        }
      ],
      "cve": "CVE-2022-21465",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is Prior to 6.1.34. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as  unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.7 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-Prior to 6.1.34"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-Prior to 6.1.34"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859130.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-Prior to 6.1.34"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Dimitris Doganos"
          ],
          "organization": "COSMOTE - Mobile Telecommunications S.A."
        }
      ],
      "cve": "CVE-2022-21466",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Tools and Frameworks).   The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9633V-11.3.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9633V-11.3.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859309.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9633V-11.3.2"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Natalia Trojanowska"
          ],
          "organization": "SecuRing"
        }
      ],
      "cve": "CVE-2022-21467",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Attachments).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4461V-9.3.6"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4461V-9.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858979.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4461V-9.3.6"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "bendtheory"
          ]
        },
        {
          "names": [
            "HolyBugx"
          ]
        },
        {
          "names": [
            "Iustin Ladunca (youstin)"
          ]
        }
      ],
      "cve": "CVE-2022-21468",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Popups).  Supported versions that are affected are 12.2.4-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data as well as  unauthorized read access to a subset of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1472V-12.2.4-12.2.11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1472V-12.2.4-12.2.11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1472V-12.2.4-12.2.11"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Michael MOSKOPP"
          ],
          "organization": "Sogeti"
        }
      ],
      "cve": "CVE-2022-21469",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: UI Framework).  Supported versions that are affected are 13.4.0.0 and  13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 4.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1370V-13.4.0.0",
          "P-1370V-13.5.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1370V-13.4.0.0",
            "P-1370V-13.5.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844807.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4.7,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1370V-13.4.0.0",
            "P-1370V-13.5.0.0"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Niels van Gijzen"
          ],
          "organization": "HackDefense"
        },
        {
          "names": [
            "Sander Meijering"
          ],
          "organization": "HackDefense"
        }
      ],
      "cve": "CVE-2022-21470",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Process Scheduler).  Supported versions that are affected are 8.58 and  8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5085V-8.58",
          "P-5085V-8.59"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5085V-8.58",
            "P-5085V-8.59"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858976.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5085V-8.58",
            "P-5085V-8.59"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Aobo Wang"
          ],
          "organization": "Chaitin Security Research Lab"
        },
        {
          "names": [
            "Kun Yang"
          ],
          "organization": "Chaitin Security Research Lab"
        }
      ],
      "cve": "CVE-2022-21471",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is Prior to 6.1.34. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-Prior to 6.1.34"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-Prior to 6.1.34"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859130.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-Prior to 6.1.34"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21472",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure).  Supported versions that are affected are 12.4, 14.0-14.3 and  14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle FLEXCUBE Universal Banking accessible data as well as  unauthorized read access to a subset of Oracle FLEXCUBE Universal Banking accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle FLEXCUBE Universal Banking. CVSS 3.1 Base Score 5.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9052V-12.4",
          "P-9052V-14.0-14.3",
          "P-9052V-14.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9052V-12.4",
            "P-9052V-14.0-14.3",
            "P-9052V-14.5"
          ],
          "url": "https://support.oracle.com"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "P-9052V-12.4",
            "P-9052V-14.0-14.3",
            "P-9052V-14.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21473",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Treasury Management product of Oracle Financial Services Applications (component: Infrastructure).   The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Treasury Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Treasury Management accessible data as well as  unauthorized read access to a subset of Oracle Banking Treasury Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Treasury Management. CVSS 3.1 Base Score 5.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14133V-14.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14133V-14.5"
          ],
          "url": "https://support.oracle.com"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14133V-14.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21474",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure).   The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Trade Finance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Trade Finance accessible data as well as  unauthorized read access to a subset of Oracle Banking Trade Finance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Trade Finance. CVSS 3.1 Base Score 5.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14134V-14.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14134V-14.5"
          ],
          "url": "https://support.oracle.com"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "P-14134V-14.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21475",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Infrastructure).   The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Payments accessible data as well as  unauthorized read access to a subset of Oracle Banking Payments accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Payments. CVSS 3.1 Base Score 5.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-13011V-14.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13011V-14.5"
          ],
          "url": "https://support.oracle.com"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:H/A:L",
            "version": "3.1"
          },
          "products": [
            "P-13011V-14.5"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21476",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and  22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-Oracle Java SE:7u331",
          "P-856V-Oracle Java SE:8u321",
          "P-856V-Oracle Java SE:11.0.14",
          "P-856V-Oracle Java SE:17.0.2",
          "P-856V-Oracle Java SE:18",
          "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5",
          "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
          "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-Oracle Java SE:7u331",
            "P-856V-Oracle Java SE:8u321",
            "P-856V-Oracle Java SE:11.0.14",
            "P-856V-Oracle Java SE:17.0.2",
            "P-856V-Oracle Java SE:18",
            "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5",
            "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
            "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855980.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-856V-Oracle Java SE:7u331",
            "P-856V-Oracle Java SE:8u321",
            "P-856V-Oracle Java SE:11.0.14",
            "P-856V-Oracle Java SE:17.0.2",
            "P-856V-Oracle Java SE:18",
            "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5",
            "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
            "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Omar Younis"
          ],
          "organization": "Cysiv"
        }
      ],
      "cve": "CVE-2022-21477",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Upload).  Supported versions that are affected are 12.2.6-12.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data as well as  unauthorized read access to a subset of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1472V-12.2.6-12.2.11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1472V-12.2.6-12.2.11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1472V-12.2.6-12.2.11"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21478",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21479",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server and  unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8478V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8478V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8478V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21480",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: User Interface).  Supported versions that are affected are 6.4.3 and  6.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Transportation Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Transportation Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data as well as  unauthorized read access to a subset of Oracle Transportation Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1991V-6.4.3",
          "P-1991V-6.5.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1991V-6.4.3",
            "P-1991V-6.5.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858979.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1991V-6.4.3",
            "P-1991V-6.5.1"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Ahmed Shah"
          ],
          "organization": "Red Canari"
        }
      ],
      "cve": "CVE-2022-21481",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the PeopleSoft Enterprise FIN Cash Management product of Oracle PeopleSoft (component: Financial Gateway).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Cash Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise FIN Cash Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Cash Management accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise FIN Cash Management accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-4979V-9.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4979V-9.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858976.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-4979V-9.2"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Anonymous researcher working with Trend Micro's Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2022-21482",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8479V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8479V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8479V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "lc working with Trend Micro Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2022-21483",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and  8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8479V-7.4.35 and prior",
          "P-8479V-7.5.25 and prior",
          "P-8479V-7.6.21 and prior",
          "P-8479V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8479V-7.4.35 and prior",
            "P-8479V-7.5.25 and prior",
            "P-8479V-7.6.21 and prior",
            "P-8479V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8479V-7.4.35 and prior",
            "P-8479V-7.5.25 and prior",
            "P-8479V-7.6.21 and prior",
            "P-8479V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "lc working with Trend Micro Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2022-21484",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and  8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 2.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8479V-7.4.35 and prior",
          "P-8479V-7.5.25 and prior",
          "P-8479V-7.6.21 and prior",
          "P-8479V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8479V-7.4.35 and prior",
            "P-8479V-7.5.25 and prior",
            "P-8479V-7.6.21 and prior",
            "P-8479V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.9,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-8479V-7.4.35 and prior",
            "P-8479V-7.5.25 and prior",
            "P-8479V-7.6.21 and prior",
            "P-8479V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Lucas Leong (wmliang)"
          ],
          "organization": "Trend Micro Zero Day Initiative"
        }
      ],
      "cve": "CVE-2022-21485",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and  8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 2.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8479V-7.4.35 and prior",
          "P-8479V-7.5.25 and prior",
          "P-8479V-7.6.21 and prior",
          "P-8479V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8479V-7.4.35 and prior",
            "P-8479V-7.5.25 and prior",
            "P-8479V-7.6.21 and prior",
            "P-8479V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.9,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-8479V-7.4.35 and prior",
            "P-8479V-7.5.25 and prior",
            "P-8479V-7.6.21 and prior",
            "P-8479V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Lucas Leong (wmliang)"
          ],
          "organization": "Trend Micro Zero Day Initiative"
        }
      ],
      "cve": "CVE-2022-21486",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and  8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 2.9 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8479V-7.4.35 and prior",
          "P-8479V-7.5.25 and prior",
          "P-8479V-7.6.21 and prior",
          "P-8479V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8479V-7.4.35 and prior",
            "P-8479V-7.5.25 and prior",
            "P-8479V-7.6.21 and prior",
            "P-8479V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 2.9,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "P-8479V-7.4.35 and prior",
            "P-8479V-7.5.25 and prior",
            "P-8479V-7.6.21 and prior",
            "P-8479V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Adi Farshteindiker"
          ]
        },
        {
          "names": [
            "Luo Likang"
          ],
          "organization": "NSFocus Security Team"
        }
      ],
      "cve": "CVE-2022-21487",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is Prior to 6.1.34. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370(Core)V-Prior to 6.1.34"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370(Core)V-Prior to 6.1.34"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859130.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.8,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8370(Core)V-Prior to 6.1.34"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Adi Farshteindiker"
          ]
        }
      ],
      "cve": "CVE-2022-21488",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is Prior to 6.1.34. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.8 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-Prior to 6.1.34"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-Prior to 6.1.34"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859130.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.8,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-8370V-Prior to 6.1.34"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "lc working with Trend Micro Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2022-21489",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and  8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8479V-7.4.35 and prior",
          "P-8479V-7.5.25 and prior",
          "P-8479V-7.6.21 and prior",
          "P-8479V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8479V-7.4.35 and prior",
            "P-8479V-7.5.25 and prior",
            "P-8479V-7.6.21 and prior",
            "P-8479V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8479V-7.4.35 and prior",
            "P-8479V-7.5.25 and prior",
            "P-8479V-7.6.21 and prior",
            "P-8479V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Anonymous researcher working with Trend Micro's Zero Day Initiative"
          ]
        }
      ],
      "cve": "CVE-2022-21490",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General).  Supported versions that are affected are 7.4.35 and prior, 7.5.25 and prior, 7.6.21 and prior and  8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8479V-7.4.35 and prior",
          "P-8479V-7.5.25 and prior",
          "P-8479V-7.6.21 and prior",
          "P-8479V-8.0.28 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8479V-7.4.35 and prior",
            "P-8479V-7.5.25 and prior",
            "P-8479V-7.6.21 and prior",
            "P-8479V-8.0.28 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8479V-7.4.35 and prior",
            "P-8479V-7.5.25 and prior",
            "P-8479V-7.6.21 and prior",
            "P-8479V-8.0.28 and prior"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Oliver Bachtik"
          ],
          "organization": "NVISO"
        }
      ],
      "cve": "CVE-2022-21491",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is Prior to 6.1.34. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox.  Note: This vulnerability applies to Windows systems only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-8370V-Prior to 6.1.34"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8370V-Prior to 6.1.34"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859130.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-8370V-Prior to 6.1.34"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "AnhNH"
          ],
          "organization": "Sacombank"
        },
        {
          "names": [
            "ChauUHM"
          ],
          "organization": "Sacombank"
        },
        {
          "names": [
            "TuanNT"
          ],
          "organization": "Sacombank"
        },
        {
          "names": [
            "TungHT"
          ],
          "organization": "Sacombank"
        }
      ],
      "cve": "CVE-2022-21492",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Server).   The supported version that is affected is 5.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2025V-5.9.0.0.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025V-5.9.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853459.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-2025V-5.9.0.0.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21493",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel).   The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10006V-11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10006V-11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857179.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10006V-11"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21494",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel).   The supported version that is affected is 11. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 4.0 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-10006V-11"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10006V-11"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2857179.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-10006V-11"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Anthony Weems"
          ]
        },
        {
          "names": [
            "Karan Lyons"
          ]
        }
      ],
      "cve": "CVE-2022-21496",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI).  Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and  22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-856V-Oracle Java SE:7u331",
          "P-856V-Oracle Java SE:8u321",
          "P-856V-Oracle Java SE:11.0.14",
          "P-856V-Oracle Java SE:17.0.2",
          "P-856V-Oracle Java SE:18",
          "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5",
          "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
          "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-856V-Oracle Java SE:7u331",
            "P-856V-Oracle Java SE:8u321",
            "P-856V-Oracle Java SE:11.0.14",
            "P-856V-Oracle Java SE:17.0.2",
            "P-856V-Oracle Java SE:18",
            "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5",
            "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
            "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855980.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-856V-Oracle Java SE:7u331",
            "P-856V-Oracle Java SE:8u321",
            "P-856V-Oracle Java SE:11.0.14",
            "P-856V-Oracle Java SE:17.0.2",
            "P-856V-Oracle Java SE:18",
            "P-13497V-Oracle GraalVM Enterprise Edition:20.3.5",
            "P-13497V-Oracle GraalVM Enterprise Edition:21.3.1",
            "P-13497V-Oracle GraalVM Enterprise Edition:22.0.0.2"
          ]
        }
      ]
    },
    {
      "acknowledgments": [
        {
          "names": [
            "Jangggg"
          ],
          "organization": "VNPT"
        },
        {
          "names": [
            "peterjson  - Security Engineering - VNG Corporation"
          ]
        }
      ],
      "cve": "CVE-2022-21497",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Services Manager.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Web Services Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Web Services Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-1775V-12.2.1.3.0",
          "P-1775V-12.2.1.4.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1775V-12.2.1.3.0",
            "P-1775V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-1775V-12.2.1.3.0",
            "P-1775V-12.2.1.4.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-21498",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 12.1.0.2, 19c and  21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via multiple protocols to compromise Java VM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Java VM accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-5(Java VM)V-12.1.0.2",
          "P-5(Java VM)V-19c",
          "P-5(Java VM)V-21c"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Java VM)V-12.1.0.2",
            "P-5(Java VM)V-19c",
            "P-5(Java VM)V-21c"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Java VM)V-12.1.0.2",
            "P-5(Java VM)V-19c",
            "P-5(Java VM)V-21c"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-22947",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: NEF (Spring Cloud Gateway)).   The supported version that is affected is 22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  While the vulnerability is in Oracle Communications Cloud Native Core Network Exposure Function, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: NSSF (Spring Cloud Gateway)).  Supported versions that are affected are 22.1.0 and  1.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  While the vulnerability is in Oracle Communications Cloud Native Core Network Slice Selection Function, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14122V-22.1.0",
          "P-14130V-22.1.0",
          "P-14130V-1.8.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-22.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2863903.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-22.1.0",
            "P-14130V-1.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861807.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 10,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14122V-22.1.0",
            "P-14130V-22.1.0",
            "P-14130V-1.8.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-22965",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Automation Test Suite (Spring Framework)).  Supported versions that are affected are 1.9.0 and  22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: CNC Console (Spring Framework)).  Supported versions that are affected are 1.9.0 and  22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: NEF (Spring Framework)).   The supported version that is affected is 22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: OCNRF (Spring Framework)).  Supported versions that are affected are 1.15.0 and  22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Repository Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Network Slice Selection Function product of Oracle Communications (component: NSSF (Spring Framework)).  Supported versions that are affected are 22.1.0 and  1.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Slice Selection Function.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Slice Selection Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Spring Framework)).  Supported versions that are affected are 1.15.0 and  22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: OC SEPP (Spring framework)).  Supported versions that are affected are 1.7.0 and  22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: UDR (Spring Framework)).  Supported versions that are affected are 1.15.0 and  22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: CMP (Spring Framework)).   The supported version that is affected is 12.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Others (Spring Framework)).  Supported versions that are affected are 8.1.1.0 and  8.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: BD (Spring Framework)).  Supported versions that are affected are 8.1.1.0, 8.1.1.1 and  8.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Installers (Spring Framework)).  Supported versions that are affected are 8.1.1.0, 8.1.1.1 and  8.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Enterprise Case Management.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Enterprise Case Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (Spring Framework)).  Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor.  Successful attacks of this vulnerability can result in takeover of MySQL Enterprise Monitor.  Note: The patch for CVE-2022-22965 also addresses CVE-2022-22968. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installer (Spring Framework)).   The supported version that is affected is 3.6.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics.  Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Spring Framework)).  Supported versions that are affected are 20.0.1 and  21.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Management (Spring Framework)).  Supported versions that are affected are 9.0 and  9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SD-WAN Edge.  Successful attacks of this vulnerability can result in takeover of Oracle SD-WAN Edge. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14488V-1.9.0",
          "P-14488V-22.1.0",
          "P-14250V-1.9.0",
          "P-14250V-22.1.0",
          "P-14122V-22.1.0",
          "P-14118V-1.15.0",
          "P-14118V-22.1.0",
          "P-14130V-22.1.0",
          "P-14130V-1.8.0",
          "P-14277V-1.15.0",
          "P-14277V-22.1.0",
          "P-14123V-1.7.0",
          "P-14123V-22.1.0",
          "P-14119V-1.15.0",
          "P-14119V-22.1.0",
          "P-10900V-12.6.0.0.0",
          "P-5680V-8.1.1.0",
          "P-5680V-8.1.2.0",
          "P-9190V-8.1.1.0",
          "P-9190V-8.1.1.1",
          "P-9190V-8.1.2.0",
          "P-13545V-8.1.1.0",
          "P-13545V-8.1.1.1",
          "P-13545V-8.1.2.0",
          "P-8480V-8.0.29 and prior",
          "P-9387V-3.6.1.0",
          "P-11513V-20.0.1",
          "P-11513V-21.0.0",
          "P-13940V-9.0",
          "P-13940V-9.1"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14488V-1.9.0",
            "P-14488V-22.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859046.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-1.9.0",
            "P-14250V-22.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859048.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14122V-22.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2863903.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14118V-1.15.0",
            "P-14118V-22.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861796.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14130V-22.1.0",
            "P-14130V-1.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861807.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.15.0",
            "P-14277V-22.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14123V-1.7.0",
            "P-14123V-22.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859050.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14119V-1.15.0",
            "P-14119V-22.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859053.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10900V-12.6.0.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859061.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.1.1.0",
            "P-5680V-8.1.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856189.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9190V-8.1.1.0",
            "P-9190V-8.1.1.1",
            "P-9190V-8.1.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2863604.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13545V-8.1.1.0",
            "P-13545V-8.1.1.1",
            "P-13545V-8.1.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856550.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8480V-8.0.29 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9387V-3.6.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858979.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11513V-20.0.1",
            "P-11513V-21.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855697.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13940V-9.0",
            "P-13940V-9.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2863674.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14488V-1.9.0",
            "P-14488V-22.1.0",
            "P-14250V-1.9.0",
            "P-14250V-22.1.0",
            "P-14122V-22.1.0",
            "P-14118V-1.15.0",
            "P-14118V-22.1.0",
            "P-14130V-22.1.0",
            "P-14130V-1.8.0",
            "P-14277V-1.15.0",
            "P-14277V-22.1.0",
            "P-14123V-1.7.0",
            "P-14123V-22.1.0",
            "P-14119V-1.15.0",
            "P-14119V-22.1.0",
            "P-10900V-12.6.0.0.0",
            "P-5680V-8.1.1.0",
            "P-5680V-8.1.2.0",
            "P-9190V-8.1.1.0",
            "P-9190V-8.1.1.1",
            "P-9190V-8.1.2.0",
            "P-13545V-8.1.1.0",
            "P-13545V-8.1.1.1",
            "P-13545V-8.1.2.0",
            "P-8480V-8.0.29 and prior",
            "P-9387V-3.6.1.0",
            "P-11513V-20.0.1",
            "P-11513V-21.0.0",
            "P-13940V-9.0",
            "P-13940V-9.1"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-23181",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy   (Apache Tomcat)).   The supported version that is affected is 1.15.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General  (Apache Tomcat)).  Supported versions that are affected are 8.0.29 and prior. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Enterprise Monitor executes to compromise MySQL Enterprise Monitor.  Successful attacks of this vulnerability can result in takeover of MySQL Enterprise Monitor. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14277V-1.15.0",
          "P-8480V-8.0.29 and prior"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14277V-1.15.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859049.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8480V-8.0.29 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14277V-1.15.0",
            "P-8480V-8.0.29 and prior"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-23221",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: CNC Console (H2)).   The supported version that is affected is 1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-14250V-1.9.0"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-14250V-1.9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859048.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-14250V-1.9.0"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-23305",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Advanced Supply Chain Planning product of Oracle Supply Chain (component: MscObieeSrvlt (Apache Log4j)).  Supported versions that are affected are 12.1 and  12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Supply Chain Planning.  Successful attacks of this vulnerability can result in takeover of Oracle Advanced Supply Chain Planning. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Server (Apache Log4j)).   The supported version that is affected is 5.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: BI Platform Security (Apache Log4j)).  Supported versions that are affected are 5.9.0.0.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Storage Service Integration (Apache Log4j)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Runtime Engine  (JBoss Enterprise Application Platform)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in takeover of Oracle Business Process Management Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications EAGLE FTP Table Base Retrieval product of Oracle Communications (component: Core (Apache Log4j)).   The supported version that is affected is 4.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications EAGLE FTP Table Base Retrieval.  Successful attacks of this vulnerability can result in takeover of Oracle Communications EAGLE FTP Table Base Retrieval. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications Applications (component: ISC (Apache Log4j)).   The supported version that is affected is 8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Messaging Server.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Messaging Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Network Integrity product of Oracle Communications Applications (component: Cartridge Deployer Tool (Apache Log4j)).   The supported version that is affected is 7.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Network Integrity.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Integrity. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Logging (Apache Log4j)).  Supported versions that are affected are 7.3.4-7.3.5 and  7.4.1-7.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle E-Business Suite Cloud Manager and Cloud Backup Module product of Oracle E-Business Suite (component: Logging (Apache Log4j)).  Supported versions that are affected are EBS Cloud Manager and Backup Module: Prior to 22.1.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Suite Cloud Manager and Cloud Backup Module.  Successful attacks of this vulnerability can result in takeover of Oracle E-Business Suite Cloud Manager and Cloud Backup Module. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Oracle Management Service (Apache Log4j)).  Supported versions that are affected are 13.4.0.0 and  13.5.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in takeover of Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Infrastructure (Apache Log4j)).  Supported versions that are affected are 2.7.0.0, 2.7.0.1 and  2.8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Revenue Management and Billing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle GoldenGate Application Adapters product of Oracle GoldenGate (component: General (Apache Log4j)). This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Healthcare Data Repository product of Oracle HealthCare Applications (component: FHIR (Apache Log4j)).   The supported version that is affected is 8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Data Repository. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Installation/Configuration (Apache Log4j)).   The supported version that is affected is Prior to 11.2.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration (Apache Log4j)).   The supported version that is affected is Prior to 11.2.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Infrastructure Technology.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Identity Management Suite product of Oracle Fusion Middleware (component: Installer (Apache Log4j)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Management Suite.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Management Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: General and Misc (Apache Log4j)). For supported versions that are affected see note. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector.  Note: The supported versions of Oracle Identity Manager Connector are not impacted by CVE-2022-23305, CVE-2022-23302, CVE-2022-23307, and CVE-2021-4104. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Oracle JDeveloper (Apache Log4j)).   The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party Patch (Apache Log4j)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in takeover of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General  (Apache Log4j)).  Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor.  Successful attacks of this vulnerability can result in takeover of MySQL Enterprise Monitor. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Tuxedo product of Oracle Fusion Middleware (component: Third Party Patch (Apache Log4j)).   The supported version that is affected is 12.2.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Tuxedo.  Successful attacks of this vulnerability can result in takeover of Oracle Tuxedo. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Third Party Jars (Apache Log4j)).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-719V-12.1",
          "P-719V-12.2",
          "P-2025(Analytics Server)V-5.9.0.0.0",
          "P-2025(BI Platform Security)V-5.9.0.0.0",
          "P-2025(BI Platform Security)V-12.2.1.3.0",
          "P-2025(BI Platform Security)V-12.2.1.4.0",
          "P-2025(Storage Service Integration)V-12.2.1.4.0",
          "P-5325V-12.2.1.3.0",
          "P-5325V-12.2.1.4.0",
          "P-11116V-4.5",
          "P-8496V-8.1",
          "P-4491V-7.3.6",
          "P-4516V-7.3.4-7.3.5",
          "P-4516V-7.4.1-7.4.2",
          "P-12808V-EBS Cloud Manager and Backup Module: Prior to 22.1.1.1",
          "P-1370V-13.4.0.0",
          "P-1370V-13.5.0.0",
          "P-5322V-2.7.0.0",
          "P-5322V-2.7.0.1",
          "P-5322V-2.8.0.0",
          "P-9161V-8.1.0",
          "P-4375V-Prior to 11.2.8.0",
          "P-4392V-Prior to 11.2.8.0",
          "P-1980V-12.2.1.3.0",
          "P-1980V-12.2.1.4.0",
          "P-1999V--",
          "P-807V-12.2.1.3.0",
          "P-4647V-12.2.1.4.0",
          "P-8480V-8.0.29 and prior",
          "P-5433V-12.2.2.0.0",
          "P-5242V-12.2.1.3.0",
          "P-5242V-12.2.1.4.0",
          "P-5242V-14.1.1.0.0"
        ],
        "known_not_affected": [
          "P-5760V-All Supported Versions"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-719V-12.1",
            "P-719V-12.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2858979.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2025(Analytics Server)V-5.9.0.0.0",
            "P-2025(BI Platform Security)V-5.9.0.0.0",
            "P-2025(BI Platform Security)V-12.2.1.3.0",
            "P-2025(BI Platform Security)V-12.2.1.4.0",
            "P-2025(Storage Service Integration)V-12.2.1.4.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853459.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5325V-12.2.1.3.0",
            "P-5325V-12.2.1.4.0",
            "P-1980V-12.2.1.3.0",
            "P-1980V-12.2.1.4.0",
            "P-1999V--",
            "P-807V-12.2.1.3.0",
            "P-4647V-12.2.1.4.0",
            "P-5433V-12.2.2.0.0",
            "P-5242V-12.2.1.3.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11116V-4.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2861832.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8496V-8.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856674.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4491V-7.3.6"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856673.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4516V-7.3.4-7.3.5",
            "P-4516V-7.4.1-7.4.2"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856709.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-12808V-EBS Cloud Manager and Backup Module: Prior to 22.1.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-1370V-13.4.0.0",
            "P-1370V-13.5.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844807.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5322V-2.7.0.0",
            "P-5322V-2.7.0.1",
            "P-5322V-2.8.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2860692.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5760V-All Supported Versions"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9161V-8.1.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2862542.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-4375V-Prior to 11.2.8.0",
            "P-4392V-Prior to 11.2.8.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2775466.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-8480V-8.0.29 and prior"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856097.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-719V-12.1",
            "P-719V-12.2",
            "P-2025(Analytics Server)V-5.9.0.0.0",
            "P-2025(BI Platform Security)V-5.9.0.0.0",
            "P-2025(BI Platform Security)V-12.2.1.3.0",
            "P-2025(BI Platform Security)V-12.2.1.4.0",
            "P-2025(Storage Service Integration)V-12.2.1.4.0",
            "P-5325V-12.2.1.3.0",
            "P-5325V-12.2.1.4.0",
            "P-11116V-4.5",
            "P-8496V-8.1",
            "P-4491V-7.3.6",
            "P-4516V-7.3.4-7.3.5",
            "P-4516V-7.4.1-7.4.2",
            "P-12808V-EBS Cloud Manager and Backup Module: Prior to 22.1.1.1",
            "P-1370V-13.4.0.0",
            "P-1370V-13.5.0.0",
            "P-5322V-2.7.0.0",
            "P-5322V-2.7.0.1",
            "P-5322V-2.8.0.0",
            "P-9161V-8.1.0",
            "P-4375V-Prior to 11.2.8.0",
            "P-4392V-Prior to 11.2.8.0",
            "P-1980V-12.2.1.3.0",
            "P-1980V-12.2.1.4.0",
            "P-1999V--",
            "P-807V-12.2.1.3.0",
            "P-4647V-12.2.1.4.0",
            "P-8480V-8.0.29 and prior",
            "P-5433V-12.2.2.0.0",
            "P-5242V-12.2.1.3.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.1.0.0"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5760V-All Supported Versions"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-23437",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Security (Apache Xerces-J)).   The supported version that is affected is Prior to 9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Element Manager.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Element Manager. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: General (Apache Xerces-J)).   The supported version that is affected is Prior to 9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Report Manager.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Session Route Manager product of Oracle Communications (component: Third Party (Apache Xerces-J)).   The supported version that is affected is Prior to 9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Route Manager.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Route Manager. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Others (Apache Xerces-J)).  Supported versions that are affected are 8.0.6.0-8.0.9.0 and  8.1.0.0-8.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Third Party (Apache Xerces-J)).  Supported versions that are affected are 8.0.6.0-8.0.8.0, 8.1.1.0,  8.1.1.1 and   8.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Installers (Apache Xerces-J)).  Supported versions that are affected are 8.0.7.1, 8.0.7.2, 8.0.8.0, 8.0.8.1, 8.1.1.0 and  8.1.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Enterprise Case Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Enterprise Case Management. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Bulk Data Integration product of Oracle Retail Applications (component: BDI Job Scheduler  (Apache Xerces-J)).   The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Bulk Data Integration.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Bulk Data Integration. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Extract Transform and Load product of Oracle Retail Applications (component: Mathematical Operators (Apache Xerces-J)).   The supported version that is affected is 13.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Extract Transform and Load.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Extract Transform and Load. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Financial Integration product of Oracle Retail Applications (component: PeopleSoft Integration Bugs (Apache Xerces-J)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Financial Integration.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Financial Integration. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Apache Xerces-J)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Integration Bus. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Merchandising System product of Oracle Retail Applications (component: Foundation (Apache Xerces-J)).  Supported versions that are affected are 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Merchandising System.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Merchandising System. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB Installation (Apache Xerces-J)).  Supported versions that are affected are 14.1.3.2, 15.0.3.1, 16.0.3 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Service Backbone. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Third Party Tools (Apache Xerces-J)).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Vulnerability in Oracle iLearning (component: Installation (Apache Xerces-J)).  Supported versions that are affected are 6.2 and  6.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iLearning.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle iLearning. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-11052V-Prior to 9.0",
          "P-10770V-Prior to 9.0",
          "P-10771V-Prior to 9.0",
          "P-5680V-8.0.6.0-8.0.9.0",
          "P-5680V-8.1.0.0-8.1.2.0",
          "P-9190V-8.0.6.0-8.0.8.0",
          "P-9190V-8.1.1.0",
          "P-9190V-8.1.1.1",
          "P-9190V-8.1.2.0",
          "P-13545V-8.0.7.1",
          "P-13545V-8.0.7.2",
          "P-13545V-8.0.8.0",
          "P-13545V-8.0.8.1",
          "P-13545V-8.1.1.0",
          "P-13545V-8.1.1.1",
          "P-12968V-16.0.3",
          "P-1803V-13.2.8",
          "P-10722V-14.1.3.2",
          "P-10722V-15.0.3.1",
          "P-10722V-16.0.3",
          "P-10722V-19.0.1",
          "P-1807V-14.1.3.2",
          "P-1807V-15.0.3.1",
          "P-1807V-16.0.3",
          "P-1807V-19.0.1",
          "P-1816V-16.0.3",
          "P-1816V-19.0.1",
          "P-10867V-14.1.3.2",
          "P-10867V-15.0.3.1",
          "P-10867V-16.0.3",
          "P-10867V-19.0.1",
          "P-5242V-12.2.1.3.0",
          "P-5242V-12.2.1.4.0",
          "P-5242V-14.1.1.0.0",
          "P-902V-6.2",
          "P-902V-6.3"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-11052V-Prior to 9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859056.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10770V-Prior to 9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859063.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-10771V-Prior to 9.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859064.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5680V-8.0.6.0-8.0.9.0",
            "P-5680V-8.1.0.0-8.1.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856189.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9190V-8.0.6.0-8.0.8.0",
            "P-9190V-8.1.1.0",
            "P-9190V-8.1.1.1",
            "P-9190V-8.1.2.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2863604.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-13545V-8.0.7.1",
            "P-13545V-8.0.7.2",
            "P-13545V-8.0.8.0",
            "P-13545V-8.0.8.1",
            "P-13545V-8.1.1.0",
            "P-13545V-8.1.1.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856550.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-12968V-16.0.3",
            "P-1803V-13.2.8",
            "P-10722V-14.1.3.2",
            "P-10722V-15.0.3.1",
            "P-10722V-16.0.3",
            "P-10722V-19.0.1",
            "P-1807V-14.1.3.2",
            "P-1807V-15.0.3.1",
            "P-1807V-16.0.3",
            "P-1807V-19.0.1",
            "P-1816V-16.0.3",
            "P-1816V-19.0.1",
            "P-10867V-14.1.3.2",
            "P-10867V-15.0.3.1",
            "P-10867V-16.0.3",
            "P-10867V-19.0.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2855697.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5242V-12.2.1.3.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.1.0.0"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2853458.2"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-902V-6.2",
            "P-902V-6.3"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2859330.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "P-11052V-Prior to 9.0",
            "P-10770V-Prior to 9.0",
            "P-10771V-Prior to 9.0",
            "P-5680V-8.0.6.0-8.0.9.0",
            "P-5680V-8.1.0.0-8.1.2.0",
            "P-9190V-8.0.6.0-8.0.8.0",
            "P-9190V-8.1.1.0",
            "P-9190V-8.1.1.1",
            "P-9190V-8.1.2.0",
            "P-13545V-8.0.7.1",
            "P-13545V-8.0.7.2",
            "P-13545V-8.0.8.0",
            "P-13545V-8.0.8.1",
            "P-13545V-8.1.1.0",
            "P-13545V-8.1.1.1",
            "P-12968V-16.0.3",
            "P-1803V-13.2.8",
            "P-10722V-14.1.3.2",
            "P-10722V-15.0.3.1",
            "P-10722V-16.0.3",
            "P-10722V-19.0.1",
            "P-1807V-14.1.3.2",
            "P-1807V-15.0.3.1",
            "P-1807V-16.0.3",
            "P-1807V-19.0.1",
            "P-1816V-16.0.3",
            "P-1816V-19.0.1",
            "P-10867V-14.1.3.2",
            "P-10867V-15.0.3.1",
            "P-10867V-16.0.3",
            "P-10867V-19.0.1",
            "P-5242V-12.2.1.3.0",
            "P-5242V-12.2.1.4.0",
            "P-5242V-14.1.1.0.0",
            "P-902V-6.2",
            "P-902V-6.3"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-23990",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications MetaSolv Solution product of Oracle Communications Applications (component: User Interface (LibExpat)).   The supported version that is affected is 6.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications MetaSolv Solution.  Successful attacks of this vulnerability can result in takeover of Oracle Communications MetaSolv Solution. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
          "title": "Vulnerability Description"
        },
        {
          "category": "description",
          "text": "Security-in-Depth issue in the Oracle Database - Enterprise Edition RDBMS (LibExpat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-2267V-6.3.1"
        ],
        "known_not_affected": [
          "P-5(Oracle Database - Enterprise Edition RDBMS)V-All Supported Versions"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-2267V-6.3.1"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856717.1"
        },
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-5(Oracle Database - Enterprise Edition RDBMS)V-All Supported Versions"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2844795.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "P-2267V-6.3.1"
          ]
        },
        {
          "cvss_v3": {
            "baseScore": 0,
            "baseSeverity": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "P-5(Oracle Database - Enterprise Edition RDBMS)V-All Supported Versions"
          ]
        }
      ]
    },
    {
      "cve": "CVE-2022-24329",
      "notes": [
        {
          "category": "description",
          "text": "Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications Applications (component: REST Services Manager (Kotlin)).  Supported versions that are affected are 12.0.0.4 and  12.0.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Pricing Design Center.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Pricing Design Center accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
          "title": "Vulnerability Description"
        }
      ],
      "product_status": {
        "known_affected": [
          "P-9437V-12.0.0.4",
          "P-9437V-12.0.0.5"
        ]
      },
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "Oracle customers with valid support contracts",
          "product_ids": [
            "P-9437V-12.0.0.4",
            "P-9437V-12.0.0.5"
          ],
          "url": "https://support.oracle.com/rs?type=doc&id=2856675.1"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "P-9437V-12.0.0.4",
            "P-9437V-12.0.0.5"
          ]
        }
      ]
    }
  ]
}
View JSON API Download JSON