cpuapr2023csaf
MEDIUM CVSS 4.8 csaf_oracle
Description
No description available.
Timeline
- Published
- 2023-04-18 13:00 UTC
- Last Modified
- 2023-04-25
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"document": {
"category": "csaf_security_advisory",
"csaf_version": "2.0",
"publisher": {
"category": "vendor",
"name": "Oracle",
"namespace": "https://www.oracle.com"
},
"references": [
{
"summary": "URL to html version of Advisory",
"url": "https://www.oracle.com/security-alerts/cpuapr2023.html"
},
{
"category": "self",
"summary": "URL to CSAF version of Advisory",
"url": "https://www.oracle.com/docs/tech/security-alerts/cpuapr2023csaf.json"
}
],
"title": "Oracle Critical Patch Update Advisory - April 2023 - Oracle CSAF",
"tracking": {
"current_release_date": "2023-04-25T10:00:00-07:00",
"id": "CPUApr2023csaf",
"initial_release_date": "2023-04-18T13:00:00-07:00",
"revision_history": [
{
"date": "2023-04-18T13:00:00-07:00",
"number": "1",
"summary": "Initial Release"
},
{
"date": "2023-04-25T10:00:00-07:00",
"number": "2",
"summary": "Rev 2. Added Credit and Protocol for WebLogic"
}
],
"status": "draft",
"version": "2"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle BI Publisher Version 12.2.1.4.0",
"product": {
"name": "Oracle BI Publisher Version 12.2.1.4.0",
"product_id": "P-1479V-12.2.1.4.0"
}
},
{
"category": "product_version",
"name": "Oracle BI Publisher Version 6.4.0.0.0",
"product": {
"name": "Oracle BI Publisher Version 6.4.0.0.0",
"product_id": "P-1479V-6.4.0.0.0"
}
}
],
"category": "product_name",
"name": "Oracle BI Publisher"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Business Intelligence Enterprise Edition Version 12.2.1.4.0",
"product": {
"name": "Oracle Business Intelligence Enterprise Edition Version 12.2.1.4.0",
"product_id": "P-2025V-12.2.1.4.0"
}
},
{
"category": "product_version",
"name": "Oracle Business Intelligence Enterprise Edition Version 5.9.0.0.0",
"product": {
"name": "Oracle Business Intelligence Enterprise Edition Version 5.9.0.0.0",
"product_id": "P-2025V-5.9.0.0.0"
}
},
{
"category": "product_version",
"name": "Oracle Business Intelligence Enterprise Edition Version 6.4.0.0.0",
"product": {
"name": "Oracle Business Intelligence Enterprise Edition Version 6.4.0.0.0",
"product_id": "P-2025V-6.4.0.0.0"
}
}
],
"category": "product_name",
"name": "Oracle Business Intelligence Enterprise Edition"
}
],
"category": "product_family",
"name": "Oracle Analytics"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Big Data Spatial and Graph Version Prior to 23.1",
"product": {
"name": "Oracle Big Data Spatial and Graph Version Prior to 23.1",
"product_id": "P-11528V-Prior to 23.1"
}
}
],
"category": "product_name",
"name": "Oracle Big Data Spatial and Graph"
}
],
"category": "product_family",
"name": "Oracle Big Data Spatial and Graph"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Blockchain Platform Version Prior to 21.1.3",
"product": {
"name": "Oracle Blockchain Platform Version Prior to 21.1.3",
"product_id": "P-13444V-Prior to 21.1.3"
}
}
],
"category": "product_name",
"name": "Oracle Blockchain Platform"
}
],
"category": "product_family",
"name": "Oracle Blockchain Platform"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Commerce Guided Search Version 11.3.2",
"product": {
"name": "Oracle Commerce Guided Search Version 11.3.2",
"product_id": "P-9633V-11.3.2"
}
}
],
"category": "product_name",
"name": "Oracle Commerce Guided Search"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Commerce Platform Version 11.3.0",
"product": {
"name": "Oracle Commerce Platform Version 11.3.0",
"product_id": "P-9348V-11.3.0"
}
},
{
"category": "product_version",
"name": "Oracle Commerce Platform Version 11.3.1",
"product": {
"name": "Oracle Commerce Platform Version 11.3.1",
"product_id": "P-9348V-11.3.1"
}
},
{
"category": "product_version",
"name": "Oracle Commerce Platform Version 11.3.2",
"product": {
"name": "Oracle Commerce Platform Version 11.3.2",
"product_id": "P-9348V-11.3.2"
}
}
],
"category": "product_name",
"name": "Oracle Commerce Platform"
}
],
"category": "product_family",
"name": "Oracle Commerce"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Management Cloud Engine Version 22.1.0.0.0",
"product": {
"name": "Management Cloud Engine Version 22.1.0.0.0",
"product_id": "P-14252V-22.1.0.0.0"
}
}
],
"category": "product_name",
"name": "Management Cloud Engine"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Configuration Console Version 22.4.1",
"product": {
"name": "Oracle Communications Cloud Native Configuration Console Version 22.4.1",
"product_id": "P-14250V-22.4.1"
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Configuration Console Version 23.1.0",
"product": {
"name": "Oracle Communications Cloud Native Configuration Console Version 23.1.0",
"product_id": "P-14250V-23.1.0"
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Configuration Console"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Automated Test Suite Version 22.3.1",
"product": {
"name": "Oracle Communications Cloud Native Core Automated Test Suite Version 22.3.1",
"product_id": "P-14488V-22.3.1"
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Automated Test Suite Version 22.4.0",
"product": {
"name": "Oracle Communications Cloud Native Core Automated Test Suite Version 22.4.0",
"product_id": "P-14488V-22.4.0"
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Automated Test Suite"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Communications Cloud Native Core Binding Support Function Version 22.4.0-22.4.4",
"product": {
"name": "Oracle Communications Cloud Native Core Binding Support Function Version 22.4.0-22.4.4",
"product_id": "P-14121V-22.4.0-22.4.4"
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Binding Support Function Version 23.1.0",
"product": {
"name": "Oracle Communications Cloud Native Core Binding Support Function Version 23.1.0",
"product_id": "P-14121V-23.1.0"
}
},
{
"category": "product_version_range",
"name": "Oracle Communications Cloud Native Core Binding Support Function Version 23.1.0-23.1.1",
"product": {
"name": "Oracle Communications Cloud Native Core Binding Support Function Version 23.1.0-23.1.1",
"product_id": "P-14121V-23.1.0-23.1.1"
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Binding Support Function Version 23.1.1",
"product": {
"name": "Oracle Communications Cloud Native Core Binding Support Function Version 23.1.1",
"product_id": "P-14121V-23.1.1"
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Binding Support Function"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Console Version 22.3.0",
"product": {
"name": "Oracle Communications Cloud Native Core Console Version 22.3.0",
"product_id": "P-14250V-22.3.0"
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Console Version 22.4.0",
"product": {
"name": "Oracle Communications Cloud Native Core Console Version 22.4.0",
"product_id": "P-14250V-22.4.0"
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Console"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Network Exposure Function Version 22.4.2",
"product": {
"name": "Oracle Communications Cloud Native Core Network Exposure Function Version 22.4.2",
"product_id": "P-14122V-22.4.2"
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Network Exposure Function Version 23.1.0",
"product": {
"name": "Oracle Communications Cloud Native Core Network Exposure Function Version 23.1.0",
"product_id": "P-14122V-23.1.0"
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Network Exposure Function"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 22.4.0",
"product": {
"name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment Version 22.4.0",
"product_id": "P-14125V-22.4.0"
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Network Function Cloud Native Environment"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Network Repository Function Version 23.1.0",
"product": {
"name": "Oracle Communications Cloud Native Core Network Repository Function Version 23.1.0",
"product_id": "P-14118V-23.1.0"
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Network Repository Function"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Communications Cloud Native Core Policy Version 22.4.0-22.4.4",
"product": {
"name": "Oracle Communications Cloud Native Core Policy Version 22.4.0-22.4.4",
"product_id": "P-14277V-22.4.0-22.4.4"
}
},
{
"category": "product_version_range",
"name": "Oracle Communications Cloud Native Core Policy Version 23.1.0-23.1.1",
"product": {
"name": "Oracle Communications Cloud Native Core Policy Version 23.1.0-23.1.1",
"product_id": "P-14277V-23.1.0-23.1.1"
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Policy"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 22.4.0",
"product": {
"name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 22.4.0",
"product_id": "P-14123V-22.4.0"
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 22.4.1",
"product": {
"name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 22.4.1",
"product_id": "P-14123V-22.4.1"
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 22.4.2",
"product": {
"name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 22.4.2",
"product_id": "P-14123V-22.4.2"
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 23.1.0",
"product": {
"name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy Version 23.1.0",
"product_id": "P-14123V-23.1.0"
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 22.3.0",
"product": {
"name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 22.3.0",
"product_id": "P-14117V-22.3.0"
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 22.4.0",
"product": {
"name": "Oracle Communications Cloud Native Core Service Communication Proxy Version 22.4.0",
"product_id": "P-14117V-22.4.0"
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Service Communication Proxy"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Unified Data Repository Version 22.4.1",
"product": {
"name": "Oracle Communications Cloud Native Core Unified Data Repository Version 22.4.1",
"product_id": "P-14119V-22.4.1"
}
},
{
"category": "product_version",
"name": "Oracle Communications Cloud Native Core Unified Data Repository Version 23.1.0",
"product": {
"name": "Oracle Communications Cloud Native Core Unified Data Repository Version 23.1.0",
"product_id": "P-14119V-23.1.0"
}
}
],
"category": "product_name",
"name": "Oracle Communications Cloud Native Core Unified Data Repository"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Core Session Manager Version 8.45",
"product": {
"name": "Oracle Communications Core Session Manager Version 8.45",
"product_id": "P-10754V-8.45"
}
},
{
"category": "product_version",
"name": "Oracle Communications Core Session Manager Version 9.15",
"product": {
"name": "Oracle Communications Core Session Manager Version 9.15",
"product_id": "P-10754V-9.15"
}
}
],
"category": "product_name",
"name": "Oracle Communications Core Session Manager"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Diameter Signaling Router Version 8.6.0.0",
"product": {
"name": "Oracle Communications Diameter Signaling Router Version 8.6.0.0",
"product_id": "P-10899V-8.6.0.0"
}
}
],
"category": "product_name",
"name": "Oracle Communications Diameter Signaling Router"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Element Manager Version 9.0.0",
"product": {
"name": "Oracle Communications Element Manager Version 9.0.0",
"product_id": "P-11052V-9.0.0"
}
},
{
"category": "product_version",
"name": "Oracle Communications Element Manager Version 9.0.1",
"product": {
"name": "Oracle Communications Element Manager Version 9.0.1",
"product_id": "P-11052V-9.0.1"
}
}
],
"category": "product_name",
"name": "Oracle Communications Element Manager"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Operations Monitor Version 5.0",
"product": {
"name": "Oracle Communications Operations Monitor Version 5.0",
"product_id": "P-10761V-5.0"
}
}
],
"category": "product_name",
"name": "Oracle Communications Operations Monitor"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Policy Management Version 12.6.0.0.0",
"product": {
"name": "Oracle Communications Policy Management Version 12.6.0.0.0",
"product_id": "P-10900V-12.6.0.0.0"
}
}
],
"category": "product_name",
"name": "Oracle Communications Policy Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Services Gatekeeper Version 7.0.0.0.0",
"product": {
"name": "Oracle Communications Services Gatekeeper Version 7.0.0.0.0",
"product_id": "P-5381V-7.0.0.0.0"
}
}
],
"category": "product_name",
"name": "Oracle Communications Services Gatekeeper"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Session Border Controller Version 9.0",
"product": {
"name": "Oracle Communications Session Border Controller Version 9.0",
"product_id": "P-10750V-9.0"
}
},
{
"category": "product_version",
"name": "Oracle Communications Session Border Controller Version 9.1",
"product": {
"name": "Oracle Communications Session Border Controller Version 9.1",
"product_id": "P-10750V-9.1"
}
}
],
"category": "product_name",
"name": "Oracle Communications Session Border Controller"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Session Report Manager Version 9.0.0",
"product": {
"name": "Oracle Communications Session Report Manager Version 9.0.0",
"product_id": "P-10770V-9.0.0"
}
},
{
"category": "product_version",
"name": "Oracle Communications Session Report Manager Version 9.0.1",
"product": {
"name": "Oracle Communications Session Report Manager Version 9.0.1",
"product_id": "P-10770V-9.0.1"
}
}
],
"category": "product_name",
"name": "Oracle Communications Session Report Manager"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Session Router Version 9.0",
"product": {
"name": "Oracle Communications Session Router Version 9.0",
"product_id": "P-10752V-9.0"
}
},
{
"category": "product_version",
"name": "Oracle Communications Session Router Version 9.1",
"product": {
"name": "Oracle Communications Session Router Version 9.1",
"product_id": "P-10752V-9.1"
}
}
],
"category": "product_name",
"name": "Oracle Communications Session Router"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Subscriber-Aware Load Balancer Version 9.0",
"product": {
"name": "Oracle Communications Subscriber-Aware Load Balancer Version 9.0",
"product_id": "P-10766V-9.0"
}
},
{
"category": "product_version",
"name": "Oracle Communications Subscriber-Aware Load Balancer Version 9.1",
"product": {
"name": "Oracle Communications Subscriber-Aware Load Balancer Version 9.1",
"product_id": "P-10766V-9.1"
}
}
],
"category": "product_name",
"name": "Oracle Communications Subscriber-Aware Load Balancer"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications User Data Repository Version 12.6.1.0.0",
"product": {
"name": "Oracle Communications User Data Repository Version 12.6.1.0.0",
"product_id": "P-11108V-12.6.1.0.0"
}
}
],
"category": "product_name",
"name": "Oracle Communications User Data Repository"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Enterprise Communications Broker Version 3.3",
"product": {
"name": "Oracle Enterprise Communications Broker Version 3.3",
"product_id": "P-10758V-3.3"
}
},
{
"category": "product_version",
"name": "Oracle Enterprise Communications Broker Version 4.0",
"product": {
"name": "Oracle Enterprise Communications Broker Version 4.0",
"product_id": "P-10758V-4.0"
}
}
],
"category": "product_name",
"name": "Oracle Enterprise Communications Broker"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Enterprise Session Router Version 9.1",
"product": {
"name": "Oracle Enterprise Session Router Version 9.1",
"product_id": "P-14615V-9.1"
}
}
],
"category": "product_name",
"name": "Oracle Enterprise Session Router"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle SD-WAN Aware Version 9.0.1.6.0",
"product": {
"name": "Oracle SD-WAN Aware Version 9.0.1.6.0",
"product_id": "P-13941V-9.0.1.6.0"
}
}
],
"category": "product_name",
"name": "Oracle SD-WAN Aware"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle SD-WAN Edge Version 9.1.1.3.0",
"product": {
"name": "Oracle SD-WAN Edge Version 9.1.1.3.0",
"product_id": "P-13940V-9.1.1.3.0"
}
},
{
"category": "product_version",
"name": "Oracle SD-WAN Edge Version 9.1.1.4.0",
"product": {
"name": "Oracle SD-WAN Edge Version 9.1.1.4.0",
"product_id": "P-13940V-9.1.1.4.0"
}
}
],
"category": "product_name",
"name": "Oracle SD-WAN Edge"
}
],
"category": "product_family",
"name": "Oracle Communications"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Communications Convergent Charging Controller Version 12.0.1.0.0-12.0.6.0.0",
"product": {
"name": "Oracle Communications Convergent Charging Controller Version 12.0.1.0.0-12.0.6.0.0",
"product_id": "P-12985V-12.0.1.0.0-12.0.6.0.0"
}
},
{
"category": "product_version_range",
"name": "Oracle Communications Convergent Charging Controller Version 12.0.4-12.0.6",
"product": {
"name": "Oracle Communications Convergent Charging Controller Version 12.0.4-12.0.6",
"product_id": "P-12985V-12.0.4-12.0.6"
}
},
{
"category": "product_version",
"name": "Oracle Communications Convergent Charging Controller Version 6.0.1.0.0",
"product": {
"name": "Oracle Communications Convergent Charging Controller Version 6.0.1.0.0",
"product_id": "P-12985V-6.0.1.0.0"
}
}
],
"category": "product_name",
"name": "Oracle Communications Convergent Charging Controller"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications IP Service Activator Version 7.4.0",
"product": {
"name": "Oracle Communications IP Service Activator Version 7.4.0",
"product_id": "P-2261V-7.4.0"
}
},
{
"category": "product_version",
"name": "Oracle Communications IP Service Activator Version 7.5.0",
"product": {
"name": "Oracle Communications IP Service Activator Version 7.5.0",
"product_id": "P-2261V-7.5.0"
}
}
],
"category": "product_name",
"name": "Oracle Communications IP Service Activator"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Communications Network Charging and Control Version 12.0.1.0.0-12.0.6.0.0",
"product": {
"name": "Oracle Communications Network Charging and Control Version 12.0.1.0.0-12.0.6.0.0",
"product_id": "P-4623V-12.0.1.0.0-12.0.6.0.0"
}
},
{
"category": "product_version_range",
"name": "Oracle Communications Network Charging and Control Version 12.0.4-12.0.6",
"product": {
"name": "Oracle Communications Network Charging and Control Version 12.0.4-12.0.6",
"product_id": "P-4623V-12.0.4-12.0.6"
}
},
{
"category": "product_version",
"name": "Oracle Communications Network Charging and Control Version 6.0.1.0.0",
"product": {
"name": "Oracle Communications Network Charging and Control Version 6.0.1.0.0",
"product_id": "P-4623V-6.0.1.0.0"
}
}
],
"category": "product_name",
"name": "Oracle Communications Network Charging and Control"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Order and Service Management Version 7.4.1",
"product": {
"name": "Oracle Communications Order and Service Management Version 7.4.1",
"product_id": "P-2270V-7.4.1"
}
}
],
"category": "product_name",
"name": "Oracle Communications Order and Service Management"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Communications Unified Assurance Version 5.5.0-5.5.10",
"product": {
"name": "Oracle Communications Unified Assurance Version 5.5.0-5.5.10",
"product_id": "P-14597V-5.5.0-5.5.10"
}
},
{
"category": "product_version_range",
"name": "Oracle Communications Unified Assurance Version 5.5.0-5.5.9",
"product": {
"name": "Oracle Communications Unified Assurance Version 5.5.0-5.5.9",
"product_id": "P-14597V-5.5.0-5.5.9"
}
},
{
"category": "product_version_range",
"name": "Oracle Communications Unified Assurance Version 6.0.0-6.0.1",
"product": {
"name": "Oracle Communications Unified Assurance Version 6.0.0-6.0.1",
"product_id": "P-14597V-6.0.0-6.0.1"
}
},
{
"category": "product_version_range",
"name": "Oracle Communications Unified Assurance Version 6.0.0-6.0.2",
"product": {
"name": "Oracle Communications Unified Assurance Version 6.0.0-6.0.2",
"product_id": "P-14597V-6.0.0-6.0.2"
}
}
],
"category": "product_name",
"name": "Oracle Communications Unified Assurance"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Communications Unified Inventory Management Version 7.4.0",
"product": {
"name": "Oracle Communications Unified Inventory Management Version 7.4.0",
"product_id": "P-4516V-7.4.0"
}
},
{
"category": "product_version",
"name": "Oracle Communications Unified Inventory Management Version 7.4.1",
"product": {
"name": "Oracle Communications Unified Inventory Management Version 7.4.1",
"product_id": "P-4516V-7.4.1"
}
},
{
"category": "product_version",
"name": "Oracle Communications Unified Inventory Management Version 7.4.2",
"product": {
"name": "Oracle Communications Unified Inventory Management Version 7.4.2",
"product_id": "P-4516V-7.4.2"
}
},
{
"category": "product_version",
"name": "Oracle Communications Unified Inventory Management Version 7.5.0",
"product": {
"name": "Oracle Communications Unified Inventory Management Version 7.5.0",
"product_id": "P-4516V-7.5.0"
}
}
],
"category": "product_name",
"name": "Oracle Communications Unified Inventory Management"
}
],
"category": "product_family",
"name": "Oracle Communications Applications"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Primavera P6 Enterprise Project Portfolio Management Version 18.8.0-18.8.26",
"product": {
"name": "Primavera P6 Enterprise Project Portfolio Management Version 18.8.0-18.8.26",
"product_id": "P-5579V-18.8.0-18.8.26"
}
},
{
"category": "product_version_range",
"name": "Primavera P6 Enterprise Project Portfolio Management Version 19.12.0-19.12.21",
"product": {
"name": "Primavera P6 Enterprise Project Portfolio Management Version 19.12.0-19.12.21",
"product_id": "P-5579V-19.12.0-19.12.21"
}
},
{
"category": "product_version_range",
"name": "Primavera P6 Enterprise Project Portfolio Management Version 20.12.0-20.12.18",
"product": {
"name": "Primavera P6 Enterprise Project Portfolio Management Version 20.12.0-20.12.18",
"product_id": "P-5579V-20.12.0-20.12.18"
}
},
{
"category": "product_version_range",
"name": "Primavera P6 Enterprise Project Portfolio Management Version 21.12.0-21.12.12",
"product": {
"name": "Primavera P6 Enterprise Project Portfolio Management Version 21.12.0-21.12.12",
"product_id": "P-5579V-21.12.0-21.12.12"
}
},
{
"category": "product_version_range",
"name": "Primavera P6 Enterprise Project Portfolio Management Version 22.12.0-22.12.3",
"product": {
"name": "Primavera P6 Enterprise Project Portfolio Management Version 22.12.0-22.12.3",
"product_id": "P-5579V-22.12.0-22.12.3"
}
}
],
"category": "product_name",
"name": "Primavera P6 Enterprise Project Portfolio Management"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Primavera Unifier Version 18.8.0-18.8.18",
"product": {
"name": "Primavera Unifier Version 18.8.0-18.8.18",
"product_id": "P-10354V-18.8.0-18.8.18"
}
},
{
"category": "product_version_range",
"name": "Primavera Unifier Version 19.12.0-19.12.16",
"product": {
"name": "Primavera Unifier Version 19.12.0-19.12.16",
"product_id": "P-10354V-19.12.0-19.12.16"
}
},
{
"category": "product_version_range",
"name": "Primavera Unifier Version 20.12.0-20.12.16",
"product": {
"name": "Primavera Unifier Version 20.12.0-20.12.16",
"product_id": "P-10354V-20.12.0-20.12.16"
}
},
{
"category": "product_version_range",
"name": "Primavera Unifier Version 21.12.0-21.12.14",
"product": {
"name": "Primavera Unifier Version 21.12.0-21.12.14",
"product_id": "P-10354V-21.12.0-21.12.14"
}
},
{
"category": "product_version_range",
"name": "Primavera Unifier Version 22.12.0-22.12.3",
"product": {
"name": "Primavera Unifier Version 22.12.0-22.12.3",
"product_id": "P-10354V-22.12.0-22.12.3"
}
}
],
"category": "product_name",
"name": "Primavera Unifier"
}
],
"category": "product_family",
"name": "Oracle Construction and Engineering"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Database Server(Java VM) Version 19c",
"product": {
"name": "Oracle Database Server(Java VM) Version 19c",
"product_id": "P-5(Java VM)V-19c"
}
},
{
"category": "product_version",
"name": "Oracle Database Server(Oracle Database Recovery Manager) Version 19c",
"product": {
"name": "Oracle Database Server(Oracle Database Recovery Manager) Version 19c",
"product_id": "P-5(Oracle Database Recovery Manager)V-19c"
}
},
{
"category": "product_version",
"name": "Oracle Database Server(Oracle Database) Version 19c",
"product": {
"name": "Oracle Database Server(Oracle Database) Version 19c",
"product_id": "P-5(Oracle Database)V-19c"
}
},
{
"category": "product_version",
"name": "Oracle Database Server(Java VM) Version 21c",
"product": {
"name": "Oracle Database Server(Java VM) Version 21c",
"product_id": "P-5(Java VM)V-21c"
}
},
{
"category": "product_version",
"name": "Oracle Database Server(Oracle Database OML4PY) Version 21c",
"product": {
"name": "Oracle Database Server(Oracle Database OML4PY) Version 21c",
"product_id": "P-5(Oracle Database OML4PY)V-21c"
}
},
{
"category": "product_version",
"name": "Oracle Database Server(Oracle Database Recovery Manager) Version 21c",
"product": {
"name": "Oracle Database Server(Oracle Database Recovery Manager) Version 21c",
"product_id": "P-5(Oracle Database Recovery Manager)V-21c"
}
},
{
"category": "product_version",
"name": "Oracle Database Server(Oracle Database Workload Manager) Version 21c",
"product": {
"name": "Oracle Database Server(Oracle Database Workload Manager) Version 21c",
"product_id": "P-5(Oracle Database Workload Manager)V-21c"
}
},
{
"category": "product_version",
"name": "Oracle Database Server(Oracle Database) Version 21c",
"product": {
"name": "Oracle Database Server(Oracle Database) Version 21c",
"product_id": "P-5(Oracle Database)V-21c"
}
}
],
"category": "product_name",
"name": "Oracle Database Server"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle SQLcl Version 21c",
"product": {
"name": "Oracle SQLcl Version 21c",
"product_id": "P-13824V-21c"
}
}
],
"category": "product_name",
"name": "Oracle SQLcl"
},
{
"branches": [
{
"category": "product_version",
"name": "Spatial and Graph Version 19c",
"product": {
"name": "Spatial and Graph Version 19c",
"product_id": "P-619V-19c"
}
},
{
"category": "product_version",
"name": "Spatial and Graph Version 21c",
"product": {
"name": "Spatial and Graph Version 21c",
"product_id": "P-619V-21c"
}
}
],
"category": "product_name",
"name": "Spatial and Graph"
}
],
"category": "product_family",
"name": "Oracle Database Server"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Application Object Library Version 12.2.3-12.2.11",
"product": {
"name": "Oracle Application Object Library Version 12.2.3-12.2.11",
"product_id": "P-510V-12.2.3-12.2.11"
}
}
],
"category": "product_name",
"name": "Oracle Application Object Library"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle User Management Version 12.2.3-12.2.12",
"product": {
"name": "Oracle User Management Version 12.2.3-12.2.12",
"product_id": "P-1475V-12.2.3-12.2.12"
}
}
],
"category": "product_name",
"name": "Oracle User Management"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle iProcurement Version 12.2.3-12.2.12",
"product": {
"name": "Oracle iProcurement Version 12.2.3-12.2.12",
"product_id": "P-398V-12.2.3-12.2.12"
}
}
],
"category": "product_name",
"name": "Oracle iProcurement"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle iReceivables Version 12.2.3-12.2.12",
"product": {
"name": "Oracle iReceivables Version 12.2.3-12.2.12",
"product_id": "P-1106V-12.2.3-12.2.12"
}
}
],
"category": "product_name",
"name": "Oracle iReceivables"
}
],
"category": "product_family",
"name": "Oracle E-Business Suite"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Application Testing Suite Version 13.3.0.1",
"product": {
"name": "Oracle Application Testing Suite Version 13.3.0.1",
"product_id": "P-4622V-13.3.0.1"
}
}
],
"category": "product_name",
"name": "Oracle Application Testing Suite"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Enterprise Manager Ops Center Version 12.4.0.0",
"product": {
"name": "Oracle Enterprise Manager Ops Center Version 12.4.0.0",
"product_id": "P-9835V-12.4.0.0"
}
}
],
"category": "product_name",
"name": "Oracle Enterprise Manager Ops Center"
}
],
"category": "product_family",
"name": "Oracle Enterprise Manager"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Essbase Version 21.4",
"product": {
"name": "Oracle Essbase Version 21.4",
"product_id": "P-4379V-21.4"
}
}
],
"category": "product_name",
"name": "Oracle Essbase"
}
],
"category": "product_family",
"name": "Oracle Essbase"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Banking APIs Version 18.2",
"product": {
"name": "Oracle Banking APIs Version 18.2",
"product_id": "P-13676V-18.2"
}
},
{
"category": "product_version",
"name": "Oracle Banking APIs Version 18.3",
"product": {
"name": "Oracle Banking APIs Version 18.3",
"product_id": "P-13676V-18.3"
}
},
{
"category": "product_version",
"name": "Oracle Banking APIs Version 19.1",
"product": {
"name": "Oracle Banking APIs Version 19.1",
"product_id": "P-13676V-19.1"
}
},
{
"category": "product_version",
"name": "Oracle Banking APIs Version 19.2",
"product": {
"name": "Oracle Banking APIs Version 19.2",
"product_id": "P-13676V-19.2"
}
},
{
"category": "product_version",
"name": "Oracle Banking APIs Version 21.1",
"product": {
"name": "Oracle Banking APIs Version 21.1",
"product_id": "P-13676V-21.1"
}
},
{
"category": "product_version",
"name": "Oracle Banking APIs Version 22.1",
"product": {
"name": "Oracle Banking APIs Version 22.1",
"product_id": "P-13676V-22.1"
}
},
{
"category": "product_version",
"name": "Oracle Banking APIs Version 22.2",
"product": {
"name": "Oracle Banking APIs Version 22.2",
"product_id": "P-13676V-22.2"
}
}
],
"category": "product_name",
"name": "Oracle Banking APIs"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Banking Corporate Lending Version 14.0-14.3",
"product": {
"name": "Oracle Banking Corporate Lending Version 14.0-14.3",
"product_id": "P-12989V-14.0-14.3"
}
},
{
"category": "product_version_range",
"name": "Oracle Banking Corporate Lending Version 14.5-14.7",
"product": {
"name": "Oracle Banking Corporate Lending Version 14.5-14.7",
"product_id": "P-12989V-14.5-14.7"
}
}
],
"category": "product_name",
"name": "Oracle Banking Corporate Lending"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Banking Corporate Lending Process Management Version 14.4-14.7",
"product": {
"name": "Oracle Banking Corporate Lending Process Management Version 14.4-14.7",
"product_id": "P-13701V-14.4-14.7"
}
}
],
"category": "product_name",
"name": "Oracle Banking Corporate Lending Process Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Banking Digital Experience Version 18.2",
"product": {
"name": "Oracle Banking Digital Experience Version 18.2",
"product_id": "P-12605V-18.2"
}
},
{
"category": "product_version",
"name": "Oracle Banking Digital Experience Version 18.3",
"product": {
"name": "Oracle Banking Digital Experience Version 18.3",
"product_id": "P-12605V-18.3"
}
},
{
"category": "product_version",
"name": "Oracle Banking Digital Experience Version 19.1",
"product": {
"name": "Oracle Banking Digital Experience Version 19.1",
"product_id": "P-12605V-19.1"
}
},
{
"category": "product_version",
"name": "Oracle Banking Digital Experience Version 19.2",
"product": {
"name": "Oracle Banking Digital Experience Version 19.2",
"product_id": "P-12605V-19.2"
}
},
{
"category": "product_version",
"name": "Oracle Banking Digital Experience Version 21.1",
"product": {
"name": "Oracle Banking Digital Experience Version 21.1",
"product_id": "P-12605V-21.1"
}
},
{
"category": "product_version",
"name": "Oracle Banking Digital Experience Version 22.1",
"product": {
"name": "Oracle Banking Digital Experience Version 22.1",
"product_id": "P-12605V-22.1"
}
},
{
"category": "product_version",
"name": "Oracle Banking Digital Experience Version 22.2",
"product": {
"name": "Oracle Banking Digital Experience Version 22.2",
"product_id": "P-12605V-22.2"
}
}
],
"category": "product_name",
"name": "Oracle Banking Digital Experience"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Banking Payments Version 14.5",
"product": {
"name": "Oracle Banking Payments Version 14.5",
"product_id": "P-13011V-14.5"
}
},
{
"category": "product_version",
"name": "Oracle Banking Payments Version 14.6",
"product": {
"name": "Oracle Banking Payments Version 14.6",
"product_id": "P-13011V-14.6"
}
},
{
"category": "product_version",
"name": "Oracle Banking Payments Version 14.7",
"product": {
"name": "Oracle Banking Payments Version 14.7",
"product_id": "P-13011V-14.7"
}
}
],
"category": "product_name",
"name": "Oracle Banking Payments"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Banking Trade Finance Version 14.5",
"product": {
"name": "Oracle Banking Trade Finance Version 14.5",
"product_id": "P-14134V-14.5"
}
},
{
"category": "product_version",
"name": "Oracle Banking Trade Finance Version 14.6",
"product": {
"name": "Oracle Banking Trade Finance Version 14.6",
"product_id": "P-14134V-14.6"
}
},
{
"category": "product_version",
"name": "Oracle Banking Trade Finance Version 14.7",
"product": {
"name": "Oracle Banking Trade Finance Version 14.7",
"product_id": "P-14134V-14.7"
}
}
],
"category": "product_name",
"name": "Oracle Banking Trade Finance"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Banking Treasury Management Version 14.5",
"product": {
"name": "Oracle Banking Treasury Management Version 14.5",
"product_id": "P-14133V-14.5"
}
},
{
"category": "product_version",
"name": "Oracle Banking Treasury Management Version 14.6",
"product": {
"name": "Oracle Banking Treasury Management Version 14.6",
"product_id": "P-14133V-14.6"
}
},
{
"category": "product_version",
"name": "Oracle Banking Treasury Management Version 14.7",
"product": {
"name": "Oracle Banking Treasury Management Version 14.7",
"product_id": "P-14133V-14.7"
}
}
],
"category": "product_name",
"name": "Oracle Banking Treasury Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Banking Virtual Account Management Version 14.5",
"product": {
"name": "Oracle Banking Virtual Account Management Version 14.5",
"product_id": "P-13487V-14.5"
}
},
{
"category": "product_version",
"name": "Oracle Banking Virtual Account Management Version 14.6",
"product": {
"name": "Oracle Banking Virtual Account Management Version 14.6",
"product_id": "P-13487V-14.6"
}
},
{
"category": "product_version",
"name": "Oracle Banking Virtual Account Management Version 14.7",
"product": {
"name": "Oracle Banking Virtual Account Management Version 14.7",
"product_id": "P-13487V-14.7"
}
}
],
"category": "product_name",
"name": "Oracle Banking Virtual Account Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle FLEXCUBE Core Banking Version 11.10",
"product": {
"name": "Oracle FLEXCUBE Core Banking Version 11.10",
"product_id": "P-9101V-11.10"
}
},
{
"category": "product_version",
"name": "Oracle FLEXCUBE Core Banking Version 11.11",
"product": {
"name": "Oracle FLEXCUBE Core Banking Version 11.11",
"product_id": "P-9101V-11.11"
}
},
{
"category": "product_version",
"name": "Oracle FLEXCUBE Core Banking Version 11.6",
"product": {
"name": "Oracle FLEXCUBE Core Banking Version 11.6",
"product_id": "P-9101V-11.6"
}
},
{
"category": "product_version",
"name": "Oracle FLEXCUBE Core Banking Version 11.7",
"product": {
"name": "Oracle FLEXCUBE Core Banking Version 11.7",
"product_id": "P-9101V-11.7"
}
},
{
"category": "product_version",
"name": "Oracle FLEXCUBE Core Banking Version 11.8",
"product": {
"name": "Oracle FLEXCUBE Core Banking Version 11.8",
"product_id": "P-9101V-11.8"
}
}
],
"category": "product_name",
"name": "Oracle FLEXCUBE Core Banking"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle FLEXCUBE Universal Banking Version 14.0-14.3",
"product": {
"name": "Oracle FLEXCUBE Universal Banking Version 14.0-14.3",
"product_id": "P-9052V-14.0-14.3"
}
},
{
"category": "product_version_range",
"name": "Oracle FLEXCUBE Universal Banking Version 14.5-14.7",
"product": {
"name": "Oracle FLEXCUBE Universal Banking Version 14.5-14.7",
"product_id": "P-9052V-14.5-14.7"
}
}
],
"category": "product_name",
"name": "Oracle FLEXCUBE Universal Banking"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.7.0",
"product": {
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.7.0",
"product_id": "P-5680V-8.0.7.0"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.8.0",
"product": {
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.8.0",
"product_id": "P-5680V-8.0.8.0"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.9.0",
"product": {
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.0.9.0",
"product_id": "P-5680V-8.0.9.0"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.0.0",
"product": {
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.0.0",
"product_id": "P-5680V-8.1.0.0"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.1.0",
"product": {
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.1.0",
"product_id": "P-5680V-8.1.1.0"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2.0",
"product": {
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2.0",
"product_id": "P-5680V-8.1.2.0"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2.1",
"product": {
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2.1",
"product_id": "P-5680V-8.1.2.1"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2.2",
"product": {
"name": "Oracle Financial Services Analytical Applications Infrastructure Version 8.1.2.2",
"product_id": "P-5680V-8.1.2.2"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Analytical Applications Infrastructure"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Analytical Applications Reconciliation Framework Version 8.0.7.1.2",
"product": {
"name": "Oracle Financial Services Analytical Applications Reconciliation Framework Version 8.0.7.1.2",
"product_id": "P-5748V-8.0.7.1.2"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Analytical Applications Reconciliation Framework Version 8.1.1.1.7",
"product": {
"name": "Oracle Financial Services Analytical Applications Reconciliation Framework Version 8.1.1.1.7",
"product_id": "P-5748V-8.1.1.1.7"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Analytical Applications Reconciliation Framework"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Asset Liability Management Version 8.0.7.8.0",
"product": {
"name": "Oracle Financial Services Asset Liability Management Version 8.0.7.8.0",
"product_id": "P-5662V-8.0.7.8.0"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Asset Liability Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Balance Computation Engine Version 8.1.1.1.1",
"product": {
"name": "Oracle Financial Services Balance Computation Engine Version 8.1.1.1.1",
"product_id": "P-14246V-8.1.1.1.1"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Balance Computation Engine"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Balance Sheet Planning Version 8.0.8.1.4",
"product": {
"name": "Oracle Financial Services Balance Sheet Planning Version 8.0.8.1.4",
"product_id": "P-5663V-8.0.8.1.4"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Balance Sheet Planning"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Behavior Detection Platform Version 8.0.8.1",
"product": {
"name": "Oracle Financial Services Behavior Detection Platform Version 8.0.8.1",
"product_id": "P-9190V-8.0.8.1"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Behavior Detection Platform Version 8.1.1.1",
"product": {
"name": "Oracle Financial Services Behavior Detection Platform Version 8.1.1.1",
"product_id": "P-9190V-8.1.1.1"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Behavior Detection Platform Version 8.1.2.3",
"product": {
"name": "Oracle Financial Services Behavior Detection Platform Version 8.1.2.3",
"product_id": "P-9190V-8.1.2.3"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Behavior Detection Platform Version 8.1.2.4",
"product": {
"name": "Oracle Financial Services Behavior Detection Platform Version 8.1.2.4",
"product_id": "P-9190V-8.1.2.4"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Behavior Detection Platform"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Compliance Studio Version 8.1.2.4",
"product": {
"name": "Oracle Financial Services Compliance Studio Version 8.1.2.4",
"product_id": "P-14392V-8.1.2.4"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Compliance Studio"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Crime and Compliance Management Studio Version 8.0.8.3.5",
"product": {
"name": "Oracle Financial Services Crime and Compliance Management Studio Version 8.0.8.3.5",
"product_id": "P-13595V-8.0.8.3.5"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Crime and Compliance Management Studio"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Currency Transaction Reporting Version 8.0.8.1.0",
"product": {
"name": "Oracle Financial Services Currency Transaction Reporting Version 8.0.8.1.0",
"product_id": "P-9784V-8.0.8.1.0"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Currency Transaction Reporting Version 8.1.1.1.0",
"product": {
"name": "Oracle Financial Services Currency Transaction Reporting Version 8.1.1.1.0",
"product_id": "P-9784V-8.1.1.1.0"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Currency Transaction Reporting Version 8.1.2.3.0",
"product": {
"name": "Oracle Financial Services Currency Transaction Reporting Version 8.1.2.3.0",
"product_id": "P-9784V-8.1.2.3.0"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Currency Transaction Reporting Version 8.1.2.4.1",
"product": {
"name": "Oracle Financial Services Currency Transaction Reporting Version 8.1.2.4.1",
"product_id": "P-9784V-8.1.2.4.1"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Currency Transaction Reporting"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Data Governance for US Regulatory Reporting Version 8.1.2.0",
"product": {
"name": "Oracle Financial Services Data Governance for US Regulatory Reporting Version 8.1.2.0",
"product_id": "P-11669V-8.1.2.0"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Data Governance for US Regulatory Reporting Version 8.1.2.1",
"product": {
"name": "Oracle Financial Services Data Governance for US Regulatory Reporting Version 8.1.2.1",
"product_id": "P-11669V-8.1.2.1"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Data Governance for US Regulatory Reporting"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Data Integration Hub Version 8.0.7.3.1",
"product": {
"name": "Oracle Financial Services Data Integration Hub Version 8.0.7.3.1",
"product_id": "P-11289V-8.0.7.3.1"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Data Integration Hub Version 8.1.0.1.4",
"product": {
"name": "Oracle Financial Services Data Integration Hub Version 8.1.0.1.4",
"product_id": "P-11289V-8.1.0.1.4"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Data Integration Hub Version 8.1.2.2.1",
"product": {
"name": "Oracle Financial Services Data Integration Hub Version 8.1.2.2.1",
"product_id": "P-11289V-8.1.2.2.1"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Data Integration Hub"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Deposit Insurance Calculations for Liquidity Risk Management Version 8.0.7.3.1",
"product": {
"name": "Oracle Financial Services Deposit Insurance Calculations for Liquidity Risk Management Version 8.0.7.3.1",
"product_id": "P-13802V-8.0.7.3.1"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Deposit Insurance Calculations for Liquidity Risk Management Version 8.0.8.3.1",
"product": {
"name": "Oracle Financial Services Deposit Insurance Calculations for Liquidity Risk Management Version 8.0.8.3.1",
"product_id": "P-13802V-8.0.8.3.1"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Deposit Insurance Calculations for Liquidity Risk Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Enterprise Case Management Version 8.0.8.2",
"product": {
"name": "Oracle Financial Services Enterprise Case Management Version 8.0.8.2",
"product_id": "P-13545V-8.0.8.2"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Enterprise Case Management Version 8.1.1.1",
"product": {
"name": "Oracle Financial Services Enterprise Case Management Version 8.1.1.1",
"product_id": "P-13545V-8.1.1.1"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Enterprise Case Management Version 8.1.2.3",
"product": {
"name": "Oracle Financial Services Enterprise Case Management Version 8.1.2.3",
"product_id": "P-13545V-8.1.2.3"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Enterprise Case Management Version 8.1.2.4",
"product": {
"name": "Oracle Financial Services Enterprise Case Management Version 8.1.2.4",
"product_id": "P-13545V-8.1.2.4"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Enterprise Case Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Enterprise Financial Performance Analytics Version 8.0.7.8.1",
"product": {
"name": "Oracle Financial Services Enterprise Financial Performance Analytics Version 8.0.7.8.1",
"product_id": "P-4279V-8.0.7.8.1"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Enterprise Financial Performance Analytics"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Funds Transfer Pricing Version 8.0.7.8.1",
"product": {
"name": "Oracle Financial Services Funds Transfer Pricing Version 8.0.7.8.1",
"product_id": "P-5659V-8.0.7.8.1"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Funds Transfer Pricing"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Institutional Performance Analytics Version 8.0.7.8.1",
"product": {
"name": "Oracle Financial Services Institutional Performance Analytics Version 8.0.7.8.1",
"product_id": "P-10215V-8.0.7.8.1"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Institutional Performance Analytics"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Liquidity Risk Measurement and Management Version 8.0.7.3.1",
"product": {
"name": "Oracle Financial Services Liquidity Risk Measurement and Management Version 8.0.7.3.1",
"product_id": "P-13797V-8.0.7.3.1"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Liquidity Risk Measurement and Management Version 8.0.8.3.1",
"product": {
"name": "Oracle Financial Services Liquidity Risk Measurement and Management Version 8.0.8.3.1",
"product_id": "P-13797V-8.0.8.3.1"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Liquidity Risk Measurement and Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Loan Loss Forecasting and Provisioning Version 8.0.7.8.1",
"product": {
"name": "Oracle Financial Services Loan Loss Forecasting and Provisioning Version 8.0.7.8.1",
"product_id": "P-9332V-8.0.7.8.1"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Loan Loss Forecasting and Provisioning Version 8.0.8.2.1",
"product": {
"name": "Oracle Financial Services Loan Loss Forecasting and Provisioning Version 8.0.8.2.1",
"product_id": "P-9332V-8.0.8.2.1"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Loan Loss Forecasting and Provisioning"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Model Management and Governance Version 8.1.0.0",
"product": {
"name": "Oracle Financial Services Model Management and Governance Version 8.1.0.0",
"product_id": "P-14276V-8.1.0.0"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Model Management and Governance Version 8.1.2.0",
"product": {
"name": "Oracle Financial Services Model Management and Governance Version 8.1.2.0",
"product_id": "P-14276V-8.1.2.0"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Model Management and Governance"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Profitability Management Version 8.0.7.8.1",
"product": {
"name": "Oracle Financial Services Profitability Management Version 8.0.7.8.1",
"product_id": "P-5658V-8.0.7.8.1"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Profitability Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Regulatory Reporting Version 8.0.8.1",
"product": {
"name": "Oracle Financial Services Regulatory Reporting Version 8.0.8.1",
"product_id": "P-9142V-8.0.8.1"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Regulatory Reporting Version 8.1.1.1",
"product": {
"name": "Oracle Financial Services Regulatory Reporting Version 8.1.1.1",
"product_id": "P-9142V-8.1.1.1"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Regulatory Reporting Version 8.1.2.3",
"product": {
"name": "Oracle Financial Services Regulatory Reporting Version 8.1.2.3",
"product_id": "P-9142V-8.1.2.3"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Regulatory Reporting Version 8.1.2.4",
"product": {
"name": "Oracle Financial Services Regulatory Reporting Version 8.1.2.4",
"product_id": "P-9142V-8.1.2.4"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Regulatory Reporting"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Regulatory Reporting with AgileREPORTER Version 8.1.1.2.0",
"product": {
"name": "Oracle Financial Services Regulatory Reporting with AgileREPORTER Version 8.1.1.2.0",
"product_id": "P-13077V-8.1.1.2.0"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Regulatory Reporting with AgileREPORTER"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Retail Performance Analytics Version 8.0.7.8.1",
"product": {
"name": "Oracle Financial Services Retail Performance Analytics Version 8.0.7.8.1",
"product_id": "P-10216V-8.0.7.8.1"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Retail Performance Analytics"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Revenue Management and Billing Version 2.7",
"product": {
"name": "Oracle Financial Services Revenue Management and Billing Version 2.7",
"product_id": "P-5322V-2.7"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Revenue Management and Billing Version 2.7.1",
"product": {
"name": "Oracle Financial Services Revenue Management and Billing Version 2.7.1",
"product_id": "P-5322V-2.7.1"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Revenue Management and Billing Version 2.8",
"product": {
"name": "Oracle Financial Services Revenue Management and Billing Version 2.8",
"product_id": "P-5322V-2.8"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Revenue Management and Billing Version 2.9",
"product": {
"name": "Oracle Financial Services Revenue Management and Billing Version 2.9",
"product_id": "P-5322V-2.9"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Revenue Management and Billing Version 2.9.1",
"product": {
"name": "Oracle Financial Services Revenue Management and Billing Version 2.9.1",
"product_id": "P-5322V-2.9.1"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Revenue Management and Billing Version 3.0",
"product": {
"name": "Oracle Financial Services Revenue Management and Billing Version 3.0",
"product_id": "P-5322V-3.0"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Revenue Management and Billing Version 3.1",
"product": {
"name": "Oracle Financial Services Revenue Management and Billing Version 3.1",
"product_id": "P-5322V-3.1"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Revenue Management and Billing Version 3.2",
"product": {
"name": "Oracle Financial Services Revenue Management and Billing Version 3.2",
"product_id": "P-5322V-3.2"
}
},
{
"category": "product_version",
"name": "Oracle Financial Services Revenue Management and Billing Version 4.0",
"product": {
"name": "Oracle Financial Services Revenue Management and Billing Version 4.0",
"product_id": "P-5322V-4.0"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Revenue Management and Billing"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition Version 8.0.8.0.0",
"product": {
"name": "Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition Version 8.0.8.0.0",
"product_id": "P-13789V-8.0.8.0.0"
}
}
],
"category": "product_name",
"name": "Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition"
}
],
"category": "product_family",
"name": "Oracle Financial Services Applications"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Access Manager Version 12.2.1.4.0",
"product": {
"name": "Oracle Access Manager Version 12.2.1.4.0",
"product_id": "P-5565V-12.2.1.4.0"
}
}
],
"category": "product_name",
"name": "Oracle Access Manager"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Business Process Management Suite Version 12.2.1.4.0",
"product": {
"name": "Oracle Business Process Management Suite Version 12.2.1.4.0",
"product_id": "P-5325V-12.2.1.4.0"
}
}
],
"category": "product_name",
"name": "Oracle Business Process Management Suite"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Coherence Version 12.2.1.4.0",
"product": {
"name": "Oracle Coherence Version 12.2.1.4.0",
"product_id": "P-2545V-12.2.1.4.0"
}
},
{
"category": "product_version",
"name": "Oracle Coherence Version 14.1.1.0.0",
"product": {
"name": "Oracle Coherence Version 14.1.1.0.0",
"product_id": "P-2545V-14.1.1.0.0"
}
}
],
"category": "product_name",
"name": "Oracle Coherence"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Data Integrator Version 12.2.1.4.0",
"product": {
"name": "Oracle Data Integrator Version 12.2.1.4.0",
"product_id": "P-2196V-12.2.1.4.0"
}
}
],
"category": "product_name",
"name": "Oracle Data Integrator"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle HTTP Server Version 12.2.1.4.0",
"product": {
"name": "Oracle HTTP Server Version 12.2.1.4.0",
"product_id": "P-1042V-12.2.1.4.0"
}
}
],
"category": "product_name",
"name": "Oracle HTTP Server"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Identity Manager Version 12.2.1.4.0",
"product": {
"name": "Oracle Identity Manager Version 12.2.1.4.0",
"product_id": "P-1980V-12.2.1.4.0"
}
}
],
"category": "product_name",
"name": "Oracle Identity Manager"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle JDeveloper Version 12.2.1.4.0",
"product": {
"name": "Oracle JDeveloper Version 12.2.1.4.0",
"product_id": "P-807V-12.2.1.4.0"
}
}
],
"category": "product_name",
"name": "Oracle JDeveloper"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Managed File Transfer Version 12.2.1.4.0",
"product": {
"name": "Oracle Managed File Transfer Version 12.2.1.4.0",
"product_id": "P-10198V-12.2.1.4.0"
}
}
],
"category": "product_name",
"name": "Oracle Managed File Transfer"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Middleware Common Libraries and Tools Version 12.2.1.4.0",
"product": {
"name": "Oracle Middleware Common Libraries and Tools Version 12.2.1.4.0",
"product_id": "P-4647V-12.2.1.4.0"
}
}
],
"category": "product_name",
"name": "Oracle Middleware Common Libraries and Tools"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Outside In Technology Version 8.5.6",
"product": {
"name": "Oracle Outside In Technology Version 8.5.6",
"product_id": "P-2276V-8.5.6"
}
}
],
"category": "product_name",
"name": "Oracle Outside In Technology"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle SOA Suite Version 12.2.1.4.0",
"product": {
"name": "Oracle SOA Suite Version 12.2.1.4.0",
"product_id": "P-1675V-12.2.1.4.0"
}
}
],
"category": "product_name",
"name": "Oracle SOA Suite"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle WebCenter Portal Version 12.2.1.4.0",
"product": {
"name": "Oracle WebCenter Portal Version 12.2.1.4.0",
"product_id": "P-1696V-12.2.1.4.0"
}
}
],
"category": "product_name",
"name": "Oracle WebCenter Portal"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle WebCenter Sites Version 12.2.1.4.0",
"product": {
"name": "Oracle WebCenter Sites Version 12.2.1.4.0",
"product_id": "P-9617V-12.2.1.4.0"
}
}
],
"category": "product_name",
"name": "Oracle WebCenter Sites"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle WebLogic Server(Console) Version 12.2.1.3.0",
"product": {
"name": "Oracle WebLogic Server(Console) Version 12.2.1.3.0",
"product_id": "P-5242(Console)V-12.2.1.3.0"
}
},
{
"category": "product_version",
"name": "Oracle WebLogic Server(Third Party) Version 12.2.1.3.0",
"product": {
"name": "Oracle WebLogic Server(Third Party) Version 12.2.1.3.0",
"product_id": "P-5242(Third Party)V-12.2.1.3.0"
}
},
{
"category": "product_version",
"name": "Oracle WebLogic Server Version 12.2.1.3.0",
"product": {
"name": "Oracle WebLogic Server Version 12.2.1.3.0",
"product_id": "P-5242V-12.2.1.3.0"
}
},
{
"category": "product_version",
"name": "Oracle WebLogic Server(Console) Version 12.2.1.4.0",
"product": {
"name": "Oracle WebLogic Server(Console) Version 12.2.1.4.0",
"product_id": "P-5242(Console)V-12.2.1.4.0"
}
},
{
"category": "product_version",
"name": "Oracle WebLogic Server(Third Party) Version 12.2.1.4.0",
"product": {
"name": "Oracle WebLogic Server(Third Party) Version 12.2.1.4.0",
"product_id": "P-5242(Third Party)V-12.2.1.4.0"
}
},
{
"category": "product_version",
"name": "Oracle WebLogic Server Version 12.2.1.4.0",
"product": {
"name": "Oracle WebLogic Server Version 12.2.1.4.0",
"product_id": "P-5242V-12.2.1.4.0"
}
},
{
"category": "product_version",
"name": "Oracle WebLogic Server(Console) Version 14.1.1.0.0",
"product": {
"name": "Oracle WebLogic Server(Console) Version 14.1.1.0.0",
"product_id": "P-5242(Console)V-14.1.1.0.0"
}
},
{
"category": "product_version",
"name": "Oracle WebLogic Server(Third Party) Version 14.1.1.0.0",
"product": {
"name": "Oracle WebLogic Server(Third Party) Version 14.1.1.0.0",
"product_id": "P-5242(Third Party)V-14.1.1.0.0"
}
},
{
"category": "product_version",
"name": "Oracle WebLogic Server Version 14.1.1.0.0",
"product": {
"name": "Oracle WebLogic Server Version 14.1.1.0.0",
"product_id": "P-5242V-14.1.1.0.0"
}
}
],
"category": "product_name",
"name": "Oracle WebLogic Server"
}
],
"category": "product_family",
"name": "Oracle Fusion Middleware"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle GoldenGate Version Prior to 19.1.0.0.230418",
"product": {
"name": "Oracle GoldenGate Version Prior to 19.1.0.0.230418",
"product_id": "P-5757V-Prior to 19.1.0.0.230418"
}
},
{
"category": "product_version_range",
"name": "Oracle GoldenGate Version Prior to 21.10.0.0.0",
"product": {
"name": "Oracle GoldenGate Version Prior to 21.10.0.0.0",
"product_id": "P-5757V-Prior to 21.10.0.0.0"
}
}
],
"category": "product_name",
"name": "Oracle GoldenGate"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle GoldenGate Studio Version Fusion Middleware: 12.2.1.4.0",
"product": {
"name": "Oracle GoldenGate Studio Version Fusion Middleware: 12.2.1.4.0",
"product_id": "P-10945V-Fusion Middleware: 12.2.1.4.0"
}
}
],
"category": "product_name",
"name": "Oracle GoldenGate Studio"
}
],
"category": "product_family",
"name": "Oracle GoldenGate"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Graph Server and Client Version Prior to 23.1.0",
"product": {
"name": "Oracle Graph Server and Client Version Prior to 23.1.0",
"product_id": "P-14069V-Prior to 23.1.0"
}
},
{
"category": "product_version_range",
"name": "Oracle Graph Server and Client Version Prior to 23.2.0",
"product": {
"name": "Oracle Graph Server and Client Version Prior to 23.2.0",
"product_id": "P-14069V-Prior to 23.2.0"
}
}
],
"category": "product_name",
"name": "Oracle Graph Server and Client"
}
],
"category": "product_family",
"name": "Oracle Graph Server and Client"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Argus Insight Version Prior to 8.2.3",
"product": {
"name": "Oracle Argus Insight Version Prior to 8.2.3",
"product_id": "P-5717V-Prior to 8.2.3"
}
}
],
"category": "product_name",
"name": "Oracle Argus Insight"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Argus Safety Version Prior to 8.2.3",
"product": {
"name": "Oracle Argus Safety Version Prior to 8.2.3",
"product_id": "P-5710V-Prior to 8.2.3"
}
}
],
"category": "product_name",
"name": "Oracle Argus Safety"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Clinical Remote Data Capture Version 5.4.0.2",
"product": {
"name": "Oracle Clinical Remote Data Capture Version 5.4.0.2",
"product_id": "P-1041V-5.4.0.2"
}
}
],
"category": "product_name",
"name": "Oracle Clinical Remote Data Capture"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Health Sciences InForm Version Prior to 6.3.1.3",
"product": {
"name": "Oracle Health Sciences InForm Version Prior to 6.3.1.3",
"product_id": "P-9636V-Prior to 6.3.1.3"
}
},
{
"category": "product_version_range",
"name": "Oracle Health Sciences InForm Version Prior to 7.0.0.1",
"product": {
"name": "Oracle Health Sciences InForm Version Prior to 7.0.0.1",
"product_id": "P-9636V-Prior to 7.0.0.1"
}
}
],
"category": "product_name",
"name": "Oracle Health Sciences InForm"
}
],
"category": "product_family",
"name": "Oracle Health Sciences Applications"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Healthcare Foundation Version 8.1.0",
"product": {
"name": "Oracle Healthcare Foundation Version 8.1.0",
"product_id": "P-12950V-8.1.0"
}
},
{
"category": "product_version",
"name": "Oracle Healthcare Foundation Version 8.1.1",
"product": {
"name": "Oracle Healthcare Foundation Version 8.1.1",
"product_id": "P-12950V-8.1.1"
}
},
{
"category": "product_version",
"name": "Oracle Healthcare Foundation Version 8.2.0",
"product": {
"name": "Oracle Healthcare Foundation Version 8.2.0",
"product_id": "P-12950V-8.2.0"
}
},
{
"category": "product_version",
"name": "Oracle Healthcare Foundation Version 8.2.1",
"product": {
"name": "Oracle Healthcare Foundation Version 8.2.1",
"product_id": "P-12950V-8.2.1"
}
},
{
"category": "product_version",
"name": "Oracle Healthcare Foundation Version 8.2.2",
"product": {
"name": "Oracle Healthcare Foundation Version 8.2.2",
"product_id": "P-12950V-8.2.2"
}
}
],
"category": "product_name",
"name": "Oracle Healthcare Foundation"
},
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle Healthcare Master Person Index Version 5.0.0-5.0.4",
"product": {
"name": "Oracle Healthcare Master Person Index Version 5.0.0-5.0.4",
"product_id": "P-8575V-5.0.0-5.0.4"
}
}
],
"category": "product_name",
"name": "Oracle Healthcare Master Person Index"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Healthcare Translational Research Version 4.1.0",
"product": {
"name": "Oracle Healthcare Translational Research Version 4.1.0",
"product_id": "P-9427V-4.1.0"
}
},
{
"category": "product_version",
"name": "Oracle Healthcare Translational Research Version 4.1.1",
"product": {
"name": "Oracle Healthcare Translational Research Version 4.1.1",
"product_id": "P-9427V-4.1.1"
}
}
],
"category": "product_name",
"name": "Oracle Healthcare Translational Research"
}
],
"category": "product_family",
"name": "Oracle HealthCare Applications"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Hospitality OPERA 5 Property Services Version 5.6",
"product": {
"name": "Oracle Hospitality OPERA 5 Property Services Version 5.6",
"product_id": "P-11580V-5.6"
}
}
],
"category": "product_name",
"name": "Oracle Hospitality OPERA 5 Property Services"
}
],
"category": "product_family",
"name": "Oracle Hospitality Applications"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Hyperion Financial Reporting Version 11.2.12",
"product": {
"name": "Oracle Hyperion Financial Reporting Version 11.2.12",
"product_id": "P-8776V-11.2.12"
}
}
],
"category": "product_name",
"name": "Oracle Hyperion Financial Reporting"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Hyperion Infrastructure Technology Version 11.2.12",
"product": {
"name": "Oracle Hyperion Infrastructure Technology Version 11.2.12",
"product_id": "P-4392V-11.2.12"
}
}
],
"category": "product_name",
"name": "Oracle Hyperion Infrastructure Technology"
}
],
"category": "product_family",
"name": "Oracle Hyperion"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Documaker Version 12.6.0.0.0",
"product": {
"name": "Oracle Documaker Version 12.6.0.0.0",
"product_id": "P-5477V-12.6.0.0.0"
}
},
{
"category": "product_version_range",
"name": "Oracle Documaker Version 12.6.2.0.0-12.6.4.0.0",
"product": {
"name": "Oracle Documaker Version 12.6.2.0.0-12.6.4.0.0",
"product_id": "P-5477V-12.6.2.0.0-12.6.4.0.0"
}
},
{
"category": "product_version",
"name": "Oracle Documaker Version 12.7.0.0.0",
"product": {
"name": "Oracle Documaker Version 12.7.0.0.0",
"product_id": "P-5477V-12.7.0.0.0"
}
},
{
"category": "product_version",
"name": "Oracle Documaker Version 12.7.1.0.0",
"product": {
"name": "Oracle Documaker Version 12.7.1.0.0",
"product_id": "P-5477V-12.7.1.0.0"
}
}
],
"category": "product_name",
"name": "Oracle Documaker"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Insurance Policy Administration Operational Data Store for Life and Annuity Version 1.0.1.8",
"product": {
"name": "Oracle Insurance Policy Administration Operational Data Store for Life and Annuity Version 1.0.1.8",
"product_id": "P-13339V-1.0.1.8"
}
}
],
"category": "product_name",
"name": "Oracle Insurance Policy Administration Operational Data Store for Life and Annuity"
}
],
"category": "product_family",
"name": "Oracle Insurance Applications"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "JD Edwards EnterpriseOne Orchestrator Version Prior to 9.2.7.3",
"product": {
"name": "JD Edwards EnterpriseOne Orchestrator Version Prior to 9.2.7.3",
"product_id": "P-11681V-Prior to 9.2.7.3"
}
}
],
"category": "product_name",
"name": "JD Edwards EnterpriseOne Orchestrator"
},
{
"branches": [
{
"category": "product_version_range",
"name": "JD Edwards EnterpriseOne Tools Version Prior to 9.2.7.2",
"product": {
"name": "JD Edwards EnterpriseOne Tools Version Prior to 9.2.7.2",
"product_id": "P-4781V-Prior to 9.2.7.2"
}
},
{
"category": "product_version_range",
"name": "JD Edwards EnterpriseOne Tools Version Prior to 9.2.7.3",
"product": {
"name": "JD Edwards EnterpriseOne Tools Version Prior to 9.2.7.3",
"product_id": "P-4781V-Prior to 9.2.7.3"
}
}
],
"category": "product_name",
"name": "JD Edwards EnterpriseOne Tools"
},
{
"branches": [
{
"category": "product_version",
"name": "JD Edwards World Security Version A9.4",
"product": {
"name": "JD Edwards World Security Version A9.4",
"product_id": "P-4839V-A9.4"
}
}
],
"category": "product_name",
"name": "JD Edwards World Security"
}
],
"category": "product_family",
"name": "Oracle JD Edwards"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:20.3.8",
"product": {
"name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:20.3.8",
"product_id": "P-13497V-Oracle GraalVM Enterprise Edition:20.3.8"
}
},
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:20.3.9",
"product": {
"name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:20.3.9",
"product_id": "P-13497V-Oracle GraalVM Enterprise Edition:20.3.9"
}
},
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:21.3.4",
"product": {
"name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:21.3.4",
"product_id": "P-13497V-Oracle GraalVM Enterprise Edition:21.3.4"
}
},
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:21.3.5",
"product": {
"name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:21.3.5",
"product_id": "P-13497V-Oracle GraalVM Enterprise Edition:21.3.5"
}
},
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:22.3.0",
"product": {
"name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:22.3.0",
"product_id": "P-13497V-Oracle GraalVM Enterprise Edition:22.3.0"
}
},
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:22.3.1",
"product": {
"name": "Oracle Java SE Version Oracle GraalVM Enterprise Edition:22.3.1",
"product_id": "P-13497V-Oracle GraalVM Enterprise Edition:22.3.1"
}
},
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle Java SE:11.0.18",
"product": {
"name": "Oracle Java SE Version Oracle Java SE:11.0.18",
"product_id": "P-856V-Oracle Java SE:11.0.18"
}
},
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle Java SE:17.0.6",
"product": {
"name": "Oracle Java SE Version Oracle Java SE:17.0.6",
"product_id": "P-856V-Oracle Java SE:17.0.6"
}
},
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle Java SE:20",
"product": {
"name": "Oracle Java SE Version Oracle Java SE:20",
"product_id": "P-856V-Oracle Java SE:20"
}
},
{
"category": "product_version",
"name": "Oracle Java SE Version Oracle Java SE:8u361",
"product": {
"name": "Oracle Java SE Version Oracle Java SE:8u361",
"product_id": "P-856V-Oracle Java SE:8u361"
}
},
{
"category": "product_version_range",
"name": "Oracle Java SE Version Oracle Java SE:8u361-perf",
"product": {
"name": "Oracle Java SE Version Oracle Java SE:8u361-perf",
"product_id": "P-856V-Oracle Java SE:8u361-perf"
}
}
],
"category": "product_name",
"name": "Oracle Java SE"
}
],
"category": "product_family",
"name": "Oracle Java SE"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "MySQL Cluster Version 7.5.29 and prior",
"product": {
"name": "MySQL Cluster Version 7.5.29 and prior",
"product_id": "P-8479V-7.5.29 and prior"
}
},
{
"category": "product_version_range",
"name": "MySQL Cluster Version 7.6.25 and prior",
"product": {
"name": "MySQL Cluster Version 7.6.25 and prior",
"product_id": "P-8479V-7.6.25 and prior"
}
},
{
"category": "product_version_range",
"name": "MySQL Cluster Version 8.0.31 and prior",
"product": {
"name": "MySQL Cluster Version 8.0.31 and prior",
"product_id": "P-8479V-8.0.31 and prior"
}
},
{
"category": "product_version_range",
"name": "MySQL Cluster Version 8.0.32 and prior",
"product": {
"name": "MySQL Cluster Version 8.0.32 and prior",
"product_id": "P-8479V-8.0.32 and prior"
}
}
],
"category": "product_name",
"name": "MySQL Cluster"
},
{
"branches": [
{
"category": "product_version_range",
"name": "MySQL Connectors(Connector/C++) Version 8.0.32 and prior",
"product": {
"name": "MySQL Connectors(Connector/C++) Version 8.0.32 and prior",
"product_id": "P-8576(Connector/C++)V-8.0.32 and prior"
}
},
{
"category": "product_version_range",
"name": "MySQL Connectors(Connector/ODBC) Version 8.0.32 and prior",
"product": {
"name": "MySQL Connectors(Connector/ODBC) Version 8.0.32 and prior",
"product_id": "P-8576(Connector/ODBC)V-8.0.32 and prior"
}
},
{
"category": "product_version_range",
"name": "MySQL Connectors Version 8.0.32 and prior",
"product": {
"name": "MySQL Connectors Version 8.0.32 and prior",
"product_id": "P-8576V-8.0.32 and prior"
}
}
],
"category": "product_name",
"name": "MySQL Connectors"
},
{
"branches": [
{
"category": "product_version_range",
"name": "MySQL Enterprise Monitor Version 8.0.33 and prior",
"product": {
"name": "MySQL Enterprise Monitor Version 8.0.33 and prior",
"product_id": "P-8480V-8.0.33 and prior"
}
}
],
"category": "product_name",
"name": "MySQL Enterprise Monitor"
},
{
"branches": [
{
"category": "product_version_range",
"name": "MySQL Server Version 5.7.40 and prior",
"product": {
"name": "MySQL Server Version 5.7.40 and prior",
"product_id": "P-8478V-5.7.40 and prior"
}
},
{
"category": "product_version_range",
"name": "MySQL Server Version 5.7.41 and prior",
"product": {
"name": "MySQL Server Version 5.7.41 and prior",
"product_id": "P-8478V-5.7.41 and prior"
}
},
{
"category": "product_version_range",
"name": "MySQL Server Version 8.0.30 and prior",
"product": {
"name": "MySQL Server Version 8.0.30 and prior",
"product_id": "P-8478V-8.0.30 and prior"
}
},
{
"category": "product_version_range",
"name": "MySQL Server Version 8.0.31 and prior",
"product": {
"name": "MySQL Server Version 8.0.31 and prior",
"product_id": "P-8478V-8.0.31 and prior"
}
},
{
"category": "product_version_range",
"name": "MySQL Server Version 8.0.32 and prior",
"product": {
"name": "MySQL Server Version 8.0.32 and prior",
"product_id": "P-8478V-8.0.32 and prior"
}
}
],
"category": "product_name",
"name": "MySQL Server"
},
{
"branches": [
{
"category": "product_version_range",
"name": "MySQL Workbench Version 8.0.32 and prior",
"product": {
"name": "MySQL Workbench Version 8.0.32 and prior",
"product_id": "P-4627V-8.0.32 and prior"
}
}
],
"category": "product_name",
"name": "MySQL Workbench"
}
],
"category": "product_family",
"name": "Oracle MySQL"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle NoSQL Database Version Prior to 19.5.32",
"product": {
"name": "Oracle NoSQL Database Version Prior to 19.5.32",
"product_id": "P-13373V-Prior to 19.5.32"
}
}
],
"category": "product_name",
"name": "Oracle NoSQL Database"
}
],
"category": "product_family",
"name": "Oracle NoSQL Database"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "PeopleSoft Enterprise HCM Human Resources Version 9.2",
"product": {
"name": "PeopleSoft Enterprise HCM Human Resources Version 9.2",
"product_id": "P-5071V-9.2"
}
}
],
"category": "product_name",
"name": "PeopleSoft Enterprise HCM Human Resources"
},
{
"branches": [
{
"category": "product_version",
"name": "PeopleSoft Enterprise PeopleTools Version 8.58",
"product": {
"name": "PeopleSoft Enterprise PeopleTools Version 8.58",
"product_id": "P-5085V-8.58"
}
},
{
"category": "product_version",
"name": "PeopleSoft Enterprise PeopleTools Version 8.59",
"product": {
"name": "PeopleSoft Enterprise PeopleTools Version 8.59",
"product_id": "P-5085V-8.59"
}
},
{
"category": "product_version",
"name": "PeopleSoft Enterprise PeopleTools Version 8.60",
"product": {
"name": "PeopleSoft Enterprise PeopleTools Version 8.60",
"product_id": "P-5085V-8.60"
}
}
],
"category": "product_name",
"name": "PeopleSoft Enterprise PeopleTools"
}
],
"category": "product_family",
"name": "Oracle PeopleSoft"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle REST Data Services Version Prior to 23.1.0",
"product": {
"name": "Oracle REST Data Services Version Prior to 23.1.0",
"product_id": "P-9456V-Prior to 23.1.0"
}
}
],
"category": "product_name",
"name": "Oracle REST Data Services"
}
],
"category": "product_family",
"name": "Oracle REST Data Services"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Retail Customer Management and Segmentation Foundation Version 18.0.0.12",
"product": {
"name": "Oracle Retail Customer Management and Segmentation Foundation Version 18.0.0.12",
"product_id": "P-13388V-18.0.0.12"
}
},
{
"category": "product_version",
"name": "Oracle Retail Customer Management and Segmentation Foundation Version 19.0.0.6",
"product": {
"name": "Oracle Retail Customer Management and Segmentation Foundation Version 19.0.0.6",
"product_id": "P-13388V-19.0.0.6"
}
}
],
"category": "product_name",
"name": "Oracle Retail Customer Management and Segmentation Foundation"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Retail Fiscal Management Version 14.2",
"product": {
"name": "Oracle Retail Fiscal Management Version 14.2",
"product_id": "P-9038V-14.2"
}
}
],
"category": "product_name",
"name": "Oracle Retail Fiscal Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Retail Invoice Matching Version 15.0.3",
"product": {
"name": "Oracle Retail Invoice Matching Version 15.0.3",
"product_id": "P-1810V-15.0.3"
}
},
{
"category": "product_version",
"name": "Oracle Retail Invoice Matching Version 16.0.3",
"product": {
"name": "Oracle Retail Invoice Matching Version 16.0.3",
"product_id": "P-1810V-16.0.3"
}
}
],
"category": "product_name",
"name": "Oracle Retail Invoice Matching"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Retail Merchandising System Version 15.0.3.1",
"product": {
"name": "Oracle Retail Merchandising System Version 15.0.3.1",
"product_id": "P-1816V-15.0.3.1"
}
},
{
"category": "product_version",
"name": "Oracle Retail Merchandising System Version 16.0.2",
"product": {
"name": "Oracle Retail Merchandising System Version 16.0.2",
"product_id": "P-1816V-16.0.2"
}
},
{
"category": "product_version",
"name": "Oracle Retail Merchandising System Version 16.0.3",
"product": {
"name": "Oracle Retail Merchandising System Version 16.0.3",
"product_id": "P-1816V-16.0.3"
}
}
],
"category": "product_name",
"name": "Oracle Retail Merchandising System"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Retail Predictive Application Server Version 15.0.3",
"product": {
"name": "Oracle Retail Predictive Application Server Version 15.0.3",
"product_id": "P-1823V-15.0.3"
}
},
{
"category": "product_version",
"name": "Oracle Retail Predictive Application Server Version 16.0.3",
"product": {
"name": "Oracle Retail Predictive Application Server Version 16.0.3",
"product_id": "P-1823V-16.0.3"
}
}
],
"category": "product_name",
"name": "Oracle Retail Predictive Application Server"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Retail Price Management Version 14.1.3.2",
"product": {
"name": "Oracle Retail Price Management Version 14.1.3.2",
"product_id": "P-1824V-14.1.3.2"
}
},
{
"category": "product_version",
"name": "Oracle Retail Price Management Version 15.0.3.1",
"product": {
"name": "Oracle Retail Price Management Version 15.0.3.1",
"product_id": "P-1824V-15.0.3.1"
}
},
{
"category": "product_version",
"name": "Oracle Retail Price Management Version 16.0.3",
"product": {
"name": "Oracle Retail Price Management Version 16.0.3",
"product_id": "P-1824V-16.0.3"
}
}
],
"category": "product_name",
"name": "Oracle Retail Price Management"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Retail Sales Audit Version 15.0.3.1",
"product": {
"name": "Oracle Retail Sales Audit Version 15.0.3.1",
"product_id": "P-1834V-15.0.3.1"
}
}
],
"category": "product_name",
"name": "Oracle Retail Sales Audit"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Retail Xstore Office Cloud Service Version 18.0.5",
"product": {
"name": "Oracle Retail Xstore Office Cloud Service Version 18.0.5",
"product_id": "P-13551V-18.0.5"
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Office Cloud Service Version 19.0.4",
"product": {
"name": "Oracle Retail Xstore Office Cloud Service Version 19.0.4",
"product_id": "P-13551V-19.0.4"
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Office Cloud Service Version 20.0.3",
"product": {
"name": "Oracle Retail Xstore Office Cloud Service Version 20.0.3",
"product_id": "P-13551V-20.0.3"
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Office Cloud Service Version 21.0.2",
"product": {
"name": "Oracle Retail Xstore Office Cloud Service Version 21.0.2",
"product_id": "P-13551V-21.0.2"
}
}
],
"category": "product_name",
"name": "Oracle Retail Xstore Office Cloud Service"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Retail Xstore Point of Service Version 17.0.6",
"product": {
"name": "Oracle Retail Xstore Point of Service Version 17.0.6",
"product_id": "P-11513V-17.0.6"
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Point of Service(Point of Sale) Version 18.0.5",
"product": {
"name": "Oracle Retail Xstore Point of Service(Point of Sale) Version 18.0.5",
"product_id": "P-11513(Point of Sale)V-18.0.5"
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Point of Service(Xenvironment) Version 18.0.5",
"product": {
"name": "Oracle Retail Xstore Point of Service(Xenvironment) Version 18.0.5",
"product_id": "P-11513(Xenvironment)V-18.0.5"
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Point of Service Version 18.0.5",
"product": {
"name": "Oracle Retail Xstore Point of Service Version 18.0.5",
"product_id": "P-11513V-18.0.5"
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Point of Service(Point of Sale) Version 19.0.4",
"product": {
"name": "Oracle Retail Xstore Point of Service(Point of Sale) Version 19.0.4",
"product_id": "P-11513(Point of Sale)V-19.0.4"
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Point of Service(Xenvironment) Version 19.0.4",
"product": {
"name": "Oracle Retail Xstore Point of Service(Xenvironment) Version 19.0.4",
"product_id": "P-11513(Xenvironment)V-19.0.4"
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Point of Service Version 19.0.4",
"product": {
"name": "Oracle Retail Xstore Point of Service Version 19.0.4",
"product_id": "P-11513V-19.0.4"
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Point of Service(Point of Sale) Version 20.0.3",
"product": {
"name": "Oracle Retail Xstore Point of Service(Point of Sale) Version 20.0.3",
"product_id": "P-11513(Point of Sale)V-20.0.3"
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Point of Service(Xenvironment) Version 20.0.3",
"product": {
"name": "Oracle Retail Xstore Point of Service(Xenvironment) Version 20.0.3",
"product_id": "P-11513(Xenvironment)V-20.0.3"
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Point of Service Version 20.0.3",
"product": {
"name": "Oracle Retail Xstore Point of Service Version 20.0.3",
"product_id": "P-11513V-20.0.3"
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Point of Service(Point of Sale) Version 21.0.2",
"product": {
"name": "Oracle Retail Xstore Point of Service(Point of Sale) Version 21.0.2",
"product_id": "P-11513(Point of Sale)V-21.0.2"
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Point of Service(Xenvironment) Version 21.0.2",
"product": {
"name": "Oracle Retail Xstore Point of Service(Xenvironment) Version 21.0.2",
"product_id": "P-11513(Xenvironment)V-21.0.2"
}
},
{
"category": "product_version",
"name": "Oracle Retail Xstore Point of Service Version 21.0.2",
"product": {
"name": "Oracle Retail Xstore Point of Service Version 21.0.2",
"product_id": "P-11513V-21.0.2"
}
}
],
"category": "product_name",
"name": "Oracle Retail Xstore Point of Service"
}
],
"category": "product_family",
"name": "Oracle Retail Applications"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle SQL Developer Version Prior to 22.4.0",
"product": {
"name": "Oracle SQL Developer Version Prior to 22.4.0",
"product_id": "P-1875V-Prior to 22.4.0"
}
},
{
"category": "product_version_range",
"name": "Oracle SQL Developer Version Prior to 23.1.0",
"product": {
"name": "Oracle SQL Developer Version Prior to 23.1.0",
"product_id": "P-1875V-Prior to 23.1.0"
}
}
],
"category": "product_name",
"name": "Oracle SQL Developer"
}
],
"category": "product_family",
"name": "Oracle SQL Developer"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Siebel CRM Version 21.10 and prior",
"product": {
"name": "Siebel CRM Version 21.10 and prior",
"product_id": "P-9011V-21.10 and prior"
}
},
{
"category": "product_version_range",
"name": "Siebel CRM Version 22.10 and prior",
"product": {
"name": "Siebel CRM Version 22.10 and prior",
"product_id": "P-9001V-22.10 and prior"
}
},
{
"category": "product_version_range",
"name": "Siebel CRM Version 22.5 and prior",
"product": {
"name": "Siebel CRM Version 22.5 and prior",
"product_id": "P-9001V-22.5 and prior"
}
},
{
"category": "product_version_range",
"name": "Siebel CRM Version 23.2 and prior",
"product": {
"name": "Siebel CRM Version 23.2 and prior",
"product_id": "P-9001V-23.2 and prior"
}
},
{
"category": "product_version_range",
"name": "Siebel CRM Version 23.2 and prior",
"product": {
"name": "Siebel CRM Version 23.2 and prior",
"product_id": "P-9011V-23.2 and prior"
}
},
{
"category": "product_version_range",
"name": "Siebel CRM Version 23.3 and prior",
"product": {
"name": "Siebel CRM Version 23.3 and prior",
"product_id": "P-9011V-23.3 and prior"
}
}
],
"category": "product_name",
"name": "Siebel CRM"
}
],
"category": "product_family",
"name": "Oracle Siebel CRM"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Agile PLM Version 9.3.6",
"product": {
"name": "Oracle Agile PLM Version 9.3.6",
"product_id": "P-4461V-9.3.6"
}
}
],
"category": "product_name",
"name": "Oracle Agile PLM"
}
],
"category": "product_family",
"name": "Oracle Supply Chain"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Solaris Version 10",
"product": {
"name": "Oracle Solaris Version 10",
"product_id": "P-10006V-10"
}
},
{
"category": "product_version",
"name": "Oracle Solaris Version 11",
"product": {
"name": "Oracle Solaris Version 11",
"product_id": "P-10006V-11"
}
}
],
"category": "product_name",
"name": "Oracle Solaris"
}
],
"category": "product_family",
"name": "Oracle Systems"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle TimesTen In-Memory Database Version Prior to 22.1.1.7.0",
"product": {
"name": "Oracle TimesTen In-Memory Database Version Prior to 22.1.1.7.0",
"product_id": "P-1870V-Prior to 22.1.1.7.0"
}
}
],
"category": "product_name",
"name": "Oracle TimesTen In-Memory Database"
}
],
"category": "product_family",
"name": "Oracle TimesTen In-Memory Database"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle Utilities Application Framework Version 4.2.0.3.0",
"product": {
"name": "Oracle Utilities Application Framework Version 4.2.0.3.0",
"product_id": "P-2245V-4.2.0.3.0"
}
},
{
"category": "product_version_range",
"name": "Oracle Utilities Application Framework Version 4.3.0.1.0-4.3.0.6.0",
"product": {
"name": "Oracle Utilities Application Framework Version 4.3.0.1.0-4.3.0.6.0",
"product_id": "P-2245V-4.3.0.1.0-4.3.0.6.0"
}
},
{
"category": "product_version",
"name": "Oracle Utilities Application Framework Version 4.4.0.0.0",
"product": {
"name": "Oracle Utilities Application Framework Version 4.4.0.0.0",
"product_id": "P-2245V-4.4.0.0.0"
}
},
{
"category": "product_version",
"name": "Oracle Utilities Application Framework Version 4.4.0.2.0",
"product": {
"name": "Oracle Utilities Application Framework Version 4.4.0.2.0",
"product_id": "P-2245V-4.4.0.2.0"
}
},
{
"category": "product_version",
"name": "Oracle Utilities Application Framework Version 4.4.0.3.0",
"product": {
"name": "Oracle Utilities Application Framework Version 4.4.0.3.0",
"product_id": "P-2245V-4.4.0.3.0"
}
},
{
"category": "product_version",
"name": "Oracle Utilities Application Framework Version 4.5.0.0.0",
"product": {
"name": "Oracle Utilities Application Framework Version 4.5.0.0.0",
"product_id": "P-2245V-4.5.0.0.0"
}
}
],
"category": "product_name",
"name": "Oracle Utilities Application Framework"
},
{
"branches": [
{
"category": "product_version",
"name": "Oracle Utilities Network Management System Version 2.3.0.2",
"product": {
"name": "Oracle Utilities Network Management System Version 2.3.0.2",
"product_id": "P-2241V-2.3.0.2"
}
},
{
"category": "product_version",
"name": "Oracle Utilities Network Management System Version 2.4.0.1",
"product": {
"name": "Oracle Utilities Network Management System Version 2.4.0.1",
"product_id": "P-2241V-2.4.0.1"
}
},
{
"category": "product_version",
"name": "Oracle Utilities Network Management System Version 2.5.0.0",
"product": {
"name": "Oracle Utilities Network Management System Version 2.5.0.0",
"product_id": "P-2241V-2.5.0.0"
}
},
{
"category": "product_version",
"name": "Oracle Utilities Network Management System Version 2.5.0.1",
"product": {
"name": "Oracle Utilities Network Management System Version 2.5.0.1",
"product_id": "P-2241V-2.5.0.1"
}
},
{
"category": "product_version",
"name": "Oracle Utilities Network Management System Version 2.5.0.2",
"product": {
"name": "Oracle Utilities Network Management System Version 2.5.0.2",
"product_id": "P-2241V-2.5.0.2"
}
}
],
"category": "product_name",
"name": "Oracle Utilities Network Management System"
}
],
"category": "product_family",
"name": "Oracle Utilities Applications"
},
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Oracle VM VirtualBox Version Prior to 6.1.44",
"product": {
"name": "Oracle VM VirtualBox Version Prior to 6.1.44",
"product_id": "P-8370V-Prior to 6.1.44"
}
},
{
"category": "product_version_range",
"name": "Oracle VM VirtualBox Version Prior to 7.0.8",
"product": {
"name": "Oracle VM VirtualBox Version Prior to 7.0.8",
"product_id": "P-8370V-Prior to 7.0.8"
}
}
],
"category": "product_name",
"name": "Oracle VM VirtualBox"
}
],
"category": "product_family",
"name": "Oracle Virtualization"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Oracle iLearning Version 6.3.1",
"product": {
"name": "Oracle iLearning Version 6.3.1",
"product_id": "P-902V-6.3.1"
}
}
],
"category": "product_name",
"name": "Oracle iLearning"
}
],
"category": "product_family",
"name": "Oracle iLearning"
}
],
"category": "vendor",
"name": "Oracle"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2018-1000656",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34659174"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Machine Learning (Flask)). The supported version that is affected is 6.4.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 4.8 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-6.4.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-6.4.0.0.0"
]
}
]
},
{
"cve": "CVE-2018-1311",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "34360012"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure (Apache Xerces-C++)). Supported versions that are affected are Prior to 9.2.7.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.3"
]
}
]
},
{
"cve": "CVE-2018-14371",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle JDeveloper",
"text": "34818890"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces (Eclipse Mojarra)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-807V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-807V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-807V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2018-18074",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Access Manager",
"text": "35008310"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Third Party (Jython)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Access Manager. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5565V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5565V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-5565V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2018-20060",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Access Manager",
"text": "35008310"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Third Party (Jython)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Access Manager. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5565V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5565V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-5565V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2018-20225",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Access Manager",
"text": "35008310"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Third Party (Jython)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Access Manager. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5565V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5565V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-5565V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2018-25032",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "33826352"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Python)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2019-10086",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "32054942"
},
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "32054842"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Apache Commons BeanUtils)). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (Apache Commons BeanUtils)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data as well as unauthorized read access to a subset of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8",
"P-2025V-6.4.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8",
"P-2025V-6.4.0.0.0"
]
}
]
},
{
"cve": "CVE-2019-10172",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "35016769"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BIInfer (Jackson-mapper-asl)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-2025V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2019-11287",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "35064710"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Pivotal RabbitMQ)). Supported versions that are affected are 5.5.0-5.5.10 and 6.0.0-6.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
]
}
]
},
{
"cve": "CVE-2019-12402",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34874507"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Content Storage Service (Apache Commons Compress)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2019-12415",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Revenue Management and Billing",
"text": "35278875"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Infrastructure (Apache POI)). Supported versions that are affected are 2.7, 2.8 and 2.9. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Financial Services Revenue Management and Billing executes to compromise Oracle Financial Services Revenue Management and Billing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financial Services Revenue Management and Billing accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.7"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.7"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938972.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.7"
]
}
]
},
{
"cve": "CVE-2019-17091",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle JDeveloper",
"text": "34818890"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces (Eclipse Mojarra)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-807V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-807V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-807V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2019-18935",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Argus Insight",
"text": "35202310"
},
{
"system_name": "Oracle Bug ID of Oracle Argus Safety",
"text": "35202295"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Argus Safety product of Oracle Health Sciences Applications (component: Core (Telerik UI for ASP.NET AJAX)). Supported versions that are affected are Prior to 8.2.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Argus Safety. Successful attacks of this vulnerability can result in takeover of Oracle Argus Safety. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Argus Insight product of Oracle Health Sciences Applications (component: Core (Telerik UI for ASP.NET AJAX)). Supported versions that are affected are Prior to 8.2.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Argus Insight. Successful attacks of this vulnerability can result in takeover of Oracle Argus Insight. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5710V-Prior to 8.2.3",
"P-5717V-Prior to 8.2.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5710V-Prior to 8.2.3",
"P-5717V-Prior to 8.2.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938697.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-5710V-Prior to 8.2.3",
"P-5717V-Prior to 8.2.3"
]
}
]
},
{
"cve": "CVE-2019-20388",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34878752"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (libxml2)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2019-20907",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Access Manager",
"text": "35008310"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Third Party (Jython)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Access Manager. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5565V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5565V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-5565V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2019-20916",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Access Manager",
"text": "35008310"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Third Party (Jython)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Access Manager. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5565V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5565V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-5565V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2020-10693",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "34749715"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core (JBoss Enterprise Application Platform)). The supported version that is affected is 14.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5242V-14.1.1.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-14.1.1.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-5242V-14.1.1.0.0"
]
}
]
},
{
"cve": "CVE-2020-10735",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "33826352"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Python)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2020-11979",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Application Testing Suite",
"text": "33176543"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Load Testing for Web Apps (Apache Ant)). The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Application Testing Suite executes to compromise Oracle Application Testing Suite. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Application Testing Suite. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4622V-13.3.0.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4622V-13.3.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923367.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-4622V-13.3.0.1"
]
}
]
},
{
"cve": "CVE-2020-11987",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
"text": "32627028"
},
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "32626911"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (Apache Batik)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data as well as unauthorized update, insert or delete access to some of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide (Apache Batik)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8"
],
"known_not_affected": [
"P-2241V-2.4.0.1",
"P-2241V-2.3.0.2",
"P-2241V-2.5.0.2",
"P-2241V-2.5.0.1",
"P-2241V-2.5.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2241V-2.4.0.1",
"P-2241V-2.3.0.2",
"P-2241V-2.5.0.2",
"P-2241V-2.5.0.1",
"P-2241V-2.5.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936478.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-2241V-2.4.0.1",
"P-2241V-2.3.0.2",
"P-2241V-2.5.0.2",
"P-2241V-2.5.0.1",
"P-2241V-2.5.0.0"
]
}
]
},
{
"cve": "CVE-2020-11988",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Revenue Management and Billing",
"text": "35278774"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Infrastructure (Apache XML Graphics Commons)). Supported versions that are affected are 2.7, 2.8 and 2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financial Services Revenue Management and Billing accessible data as well as unauthorized update, insert or delete access to some of Oracle Financial Services Revenue Management and Billing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.7"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.7"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938972.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
"version": "3.1"
},
"products": [
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.7"
]
}
]
},
{
"cve": "CVE-2020-13936",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
"text": "33519458"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General (Apache Velocity Engine)). Supported versions that are affected are 4.2.0.3.0, 4.3.0.1.0-4.3.0.6.0, 4.4.0.0.0 and 4.4.0.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Application Framework. Successful attacks of this vulnerability can result in takeover of Oracle Utilities Application Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2245V-4.2.0.3.0",
"P-2245V-4.3.0.1.0-4.3.0.6.0",
"P-2245V-4.4.0.0.0",
"P-2245V-4.4.0.2.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2245V-4.2.0.3.0",
"P-2245V-4.3.0.1.0-4.3.0.6.0",
"P-2245V-4.4.0.0.0",
"P-2245V-4.4.0.2.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936478.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-2245V-4.2.0.3.0",
"P-2245V-4.3.0.1.0-4.3.0.6.0",
"P-2245V-4.4.0.0.0",
"P-2245V-4.4.0.2.0"
]
}
]
},
{
"cve": "CVE-2020-13954",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebCenter Sites",
"text": "32229379"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: Samples (Apache CXF)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data as well as unauthorized read access to a subset of Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9617V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9617V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-9617V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2020-14343",
"ids": [
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "35028417"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Porting (PyYAML)). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5085V-8.58",
"P-5085V-8.59"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.58",
"P-5085V-8.59"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939793.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-5085V-8.58",
"P-5085V-8.59"
]
}
]
},
{
"cve": "CVE-2020-15250",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "34753911"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC (jUnit)). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.3"
]
}
]
},
{
"cve": "CVE-2020-15522",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Orchestrator",
"text": "34892526"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security (jruby)). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Orchestrator. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11681V-Prior to 9.2.7.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11681V-Prior to 9.2.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-11681V-Prior to 9.2.7.3"
]
}
]
},
{
"cve": "CVE-2020-17521",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle iLearning",
"text": "35253196"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle iLearning (component: Installation (Apache Groovy)). The supported version that is affected is 6.3.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle iLearning executes to compromise Oracle iLearning. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iLearning accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-902V-6.3.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-902V-6.3.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939823.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-902V-6.3.1"
]
}
]
},
{
"cve": "CVE-2020-1945",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Application Testing Suite",
"text": "33176543"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Load Testing for Web Apps (Apache Ant)). The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Application Testing Suite executes to compromise Oracle Application Testing Suite. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Application Testing Suite. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4622V-13.3.0.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4622V-13.3.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923367.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-4622V-13.3.0.1"
]
}
]
},
{
"cve": "CVE-2020-24977",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34878752"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (libxml2)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2020-25638",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "34749715"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core (JBoss Enterprise Application Platform)). The supported version that is affected is 14.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5242V-14.1.1.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-14.1.1.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-5242V-14.1.1.0.0"
]
}
]
},
{
"cve": "CVE-2020-25649",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "32532822"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (jackson-databind)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8"
]
}
]
},
{
"cve": "CVE-2020-28052",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Orchestrator",
"text": "34892526"
},
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "32573294"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General (Bouncy Castle Java Library)). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security (jruby)). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Orchestrator. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11681V-Prior to 9.2.7.3",
"P-2025V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11681V-Prior to 9.2.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-11681V-Prior to 9.2.7.3"
]
}
]
},
{
"cve": "CVE-2020-28500",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "32909428"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Lodash)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2020-29504",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34732241"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are Prior to 21.1.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Blockchain Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2020-29506",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34732241"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are Prior to 21.1.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Blockchain Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2020-29507",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34732241"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are Prior to 21.1.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Blockchain Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2020-29508",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Retail Predictive Application Server",
"text": "34732260"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34732241"
},
{
"system_name": "Oracle Bug ID of Oracle Communications IP Service Activator",
"text": "34732242"
},
{
"system_name": "Oracle Bug ID of Oracle Documaker",
"text": "34732245"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are Prior to 21.1.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Blockchain Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications IP Service Activator product of Oracle Communications Applications (component: Other (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are 7.4.0 and 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications IP Service Activator. Successful attacks of this vulnerability can result in takeover of Oracle Communications IP Service Activator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Development Tools (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are 12.6.0.0.0, 12.6.2.0.0-12.6.4.0.0, 12.7.0.0.0 and 12.7.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker. Successful attacks of this vulnerability can result in takeover of Oracle Documaker. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Predictive Application Server product of Oracle Retail Applications (component: RPAS Server (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are 15.0.3 and 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Predictive Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Retail Predictive Application Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-1823V-15.0.3",
"P-5477V-12.7.0.0.0",
"P-2261V-7.4.0",
"P-13444V-Prior to 21.1.3",
"P-2261V-7.5.0",
"P-1823V-16.0.3",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2261V-7.4.0",
"P-2261V-7.5.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936021.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-5477V-12.7.0.0.0",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1823V-15.0.3",
"P-1823V-16.0.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-1823V-15.0.3",
"P-5477V-12.7.0.0.0",
"P-2261V-7.4.0",
"P-2261V-7.5.0",
"P-1823V-16.0.3",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
]
}
]
},
{
"cve": "CVE-2020-35163",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Retail Predictive Application Server",
"text": "34732260"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34732241"
},
{
"system_name": "Oracle Bug ID of Oracle Communications IP Service Activator",
"text": "34732242"
},
{
"system_name": "Oracle Bug ID of Oracle Documaker",
"text": "34732245"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are Prior to 21.1.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Blockchain Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications IP Service Activator product of Oracle Communications Applications (component: Other (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are 7.4.0 and 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications IP Service Activator. Successful attacks of this vulnerability can result in takeover of Oracle Communications IP Service Activator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Development Tools (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are 12.6.0.0.0, 12.6.2.0.0-12.6.4.0.0, 12.7.0.0.0 and 12.7.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker. Successful attacks of this vulnerability can result in takeover of Oracle Documaker. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Predictive Application Server product of Oracle Retail Applications (component: RPAS Server (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are 15.0.3 and 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Predictive Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Retail Predictive Application Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-1823V-15.0.3",
"P-5477V-12.7.0.0.0",
"P-2261V-7.4.0",
"P-13444V-Prior to 21.1.3",
"P-2261V-7.5.0",
"P-1823V-16.0.3",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2261V-7.4.0",
"P-2261V-7.5.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936021.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-5477V-12.7.0.0.0",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1823V-15.0.3",
"P-1823V-16.0.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-1823V-15.0.3",
"P-5477V-12.7.0.0.0",
"P-2261V-7.4.0",
"P-2261V-7.5.0",
"P-1823V-16.0.3",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
]
}
]
},
{
"cve": "CVE-2020-35164",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Retail Predictive Application Server",
"text": "34732260"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34732241"
},
{
"system_name": "Oracle Bug ID of Oracle Communications IP Service Activator",
"text": "34732242"
},
{
"system_name": "Oracle Bug ID of Oracle Documaker",
"text": "34732245"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are Prior to 21.1.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Blockchain Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications IP Service Activator product of Oracle Communications Applications (component: Other (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are 7.4.0 and 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications IP Service Activator. Successful attacks of this vulnerability can result in takeover of Oracle Communications IP Service Activator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Development Tools (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are 12.6.0.0.0, 12.6.2.0.0-12.6.4.0.0, 12.7.0.0.0 and 12.7.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker. Successful attacks of this vulnerability can result in takeover of Oracle Documaker. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Predictive Application Server product of Oracle Retail Applications (component: RPAS Server (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are 15.0.3 and 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Predictive Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Retail Predictive Application Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-1823V-15.0.3",
"P-5477V-12.7.0.0.0",
"P-2261V-7.4.0",
"P-13444V-Prior to 21.1.3",
"P-2261V-7.5.0",
"P-1823V-16.0.3",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2261V-7.4.0",
"P-2261V-7.5.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936021.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-5477V-12.7.0.0.0",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1823V-15.0.3",
"P-1823V-16.0.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-1823V-15.0.3",
"P-5477V-12.7.0.0.0",
"P-2261V-7.4.0",
"P-2261V-7.5.0",
"P-1823V-16.0.3",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
]
}
]
},
{
"cve": "CVE-2020-35165",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34732241"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are Prior to 21.1.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Blockchain Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2020-35166",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Retail Predictive Application Server",
"text": "34732260"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34732241"
},
{
"system_name": "Oracle Bug ID of Oracle Communications IP Service Activator",
"text": "34732242"
},
{
"system_name": "Oracle Bug ID of Oracle Documaker",
"text": "34732245"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are Prior to 21.1.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Blockchain Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications IP Service Activator product of Oracle Communications Applications (component: Other (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are 7.4.0 and 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications IP Service Activator. Successful attacks of this vulnerability can result in takeover of Oracle Communications IP Service Activator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Development Tools (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are 12.6.0.0.0, 12.6.2.0.0-12.6.4.0.0, 12.7.0.0.0 and 12.7.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker. Successful attacks of this vulnerability can result in takeover of Oracle Documaker. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Predictive Application Server product of Oracle Retail Applications (component: RPAS Server (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are 15.0.3 and 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Predictive Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Retail Predictive Application Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-1823V-15.0.3",
"P-5477V-12.7.0.0.0",
"P-2261V-7.4.0",
"P-13444V-Prior to 21.1.3",
"P-2261V-7.5.0",
"P-1823V-16.0.3",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2261V-7.4.0",
"P-2261V-7.5.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936021.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-5477V-12.7.0.0.0",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1823V-15.0.3",
"P-1823V-16.0.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-1823V-15.0.3",
"P-5477V-12.7.0.0.0",
"P-2261V-7.4.0",
"P-2261V-7.5.0",
"P-1823V-16.0.3",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
]
}
]
},
{
"cve": "CVE-2020-35167",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Retail Predictive Application Server",
"text": "34732260"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34732241"
},
{
"system_name": "Oracle Bug ID of Oracle Communications IP Service Activator",
"text": "34732242"
},
{
"system_name": "Oracle Bug ID of Oracle Documaker",
"text": "34732245"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are Prior to 21.1.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Blockchain Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications IP Service Activator product of Oracle Communications Applications (component: Other (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are 7.4.0 and 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications IP Service Activator. Successful attacks of this vulnerability can result in takeover of Oracle Communications IP Service Activator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Development Tools (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are 12.6.0.0.0, 12.6.2.0.0-12.6.4.0.0, 12.7.0.0.0 and 12.7.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker. Successful attacks of this vulnerability can result in takeover of Oracle Documaker. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Predictive Application Server product of Oracle Retail Applications (component: RPAS Server (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are 15.0.3 and 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Predictive Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Retail Predictive Application Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-1823V-15.0.3",
"P-5477V-12.7.0.0.0",
"P-2261V-7.4.0",
"P-13444V-Prior to 21.1.3",
"P-2261V-7.5.0",
"P-1823V-16.0.3",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2261V-7.4.0",
"P-2261V-7.5.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936021.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-5477V-12.7.0.0.0",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1823V-15.0.3",
"P-1823V-16.0.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-1823V-15.0.3",
"P-5477V-12.7.0.0.0",
"P-2261V-7.4.0",
"P-2261V-7.5.0",
"P-1823V-16.0.3",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
]
}
]
},
{
"cve": "CVE-2020-35168",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Retail Predictive Application Server",
"text": "34732260"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34732241"
},
{
"system_name": "Oracle Bug ID of Oracle Communications IP Service Activator",
"text": "34732242"
},
{
"system_name": "Oracle Bug ID of Oracle Documaker",
"text": "34732245"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are Prior to 21.1.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Blockchain Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications IP Service Activator product of Oracle Communications Applications (component: Other (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are 7.4.0 and 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Communications IP Service Activator. Successful attacks of this vulnerability can result in takeover of Oracle Communications IP Service Activator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Development Tools (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are 12.6.0.0.0, 12.6.2.0.0-12.6.4.0.0, 12.7.0.0.0 and 12.7.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker. Successful attacks of this vulnerability can result in takeover of Oracle Documaker. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Predictive Application Server product of Oracle Retail Applications (component: RPAS Server (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are 15.0.3 and 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Predictive Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Retail Predictive Application Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-1823V-15.0.3",
"P-5477V-12.7.0.0.0",
"P-2261V-7.4.0",
"P-13444V-Prior to 21.1.3",
"P-2261V-7.5.0",
"P-1823V-16.0.3",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2261V-7.4.0",
"P-2261V-7.5.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936021.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-5477V-12.7.0.0.0",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1823V-15.0.3",
"P-1823V-16.0.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-1823V-15.0.3",
"P-5477V-12.7.0.0.0",
"P-2261V-7.4.0",
"P-2261V-7.5.0",
"P-1823V-16.0.3",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
]
}
]
},
{
"cve": "CVE-2020-35169",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34732241"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are Prior to 21.1.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Blockchain Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2020-35490",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "32532822"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (jackson-databind)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8"
]
}
]
},
{
"cve": "CVE-2020-35491",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "32532822"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (jackson-databind)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8"
]
}
]
},
{
"cve": "CVE-2020-35728",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "32532822"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (jackson-databind)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8"
]
}
]
},
{
"cve": "CVE-2020-36179",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "32532822"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (jackson-databind)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8"
]
}
]
},
{
"cve": "CVE-2020-36180",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "32532822"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (jackson-databind)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8"
]
}
]
},
{
"cve": "CVE-2020-36181",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "32532822"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (jackson-databind)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8"
]
}
]
},
{
"cve": "CVE-2020-36182",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "32532822"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (jackson-databind)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8"
]
}
]
},
{
"cve": "CVE-2020-36183",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "32532822"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (jackson-databind)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8"
]
}
]
},
{
"cve": "CVE-2020-36184",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "32532822"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (jackson-databind)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8"
]
}
]
},
{
"cve": "CVE-2020-36185",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "32532822"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (jackson-databind)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8"
]
}
]
},
{
"cve": "CVE-2020-36186",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "32532822"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (jackson-databind)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8"
]
}
]
},
{
"cve": "CVE-2020-36187",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "32532822"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (jackson-databind)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8"
]
}
]
},
{
"cve": "CVE-2020-36188",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "32532822"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (jackson-databind)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8"
]
}
]
},
{
"cve": "CVE-2020-36189",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "32532822"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (jackson-databind)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8"
]
}
]
},
{
"cve": "CVE-2020-36518",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34092800"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (jackson-databind)). Supported versions that are affected are Prior to 21.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Blockchain Platform. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2020-6950",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "34817386"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Third Party (Eclipse Mojarra)). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2020-7009",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "34810579"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Elasticsearch)). Supported versions that are affected are 5.5.0-5.5.9 and 6.0.0-6.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14597V-5.5.0-5.5.9",
"P-14597V-6.0.0-6.0.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-5.5.0-5.5.9",
"P-14597V-6.0.0-6.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14597V-5.5.0-5.5.9",
"P-14597V-6.0.0-6.0.1"
]
}
]
},
{
"cve": "CVE-2020-7595",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34878752"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (libxml2)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2020-7712",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "32810722"
},
{
"system_name": "Oracle Bug ID of Siebel CRM",
"text": "32810777"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Apache ZooKeeper)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: Loging (Apache ZooKeeper)). Supported versions that are affected are 22.5 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM. Successful attacks of this vulnerability can result in takeover of Siebel CRM. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9001V-22.5 and prior"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9001V-22.5 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939854.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 7.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-9001V-22.5 and prior"
]
}
]
},
{
"cve": "CVE-2020-8908",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Orchestrator",
"text": "34892130"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security (Google Guava)). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where JD Edwards EnterpriseOne Orchestrator executes to compromise JD Edwards EnterpriseOne Orchestrator. Successful attacks of this vulnerability can result in unauthorized read access to a subset of JD Edwards EnterpriseOne Orchestrator accessible data. CVSS 3.1 Base Score 3.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11681V-Prior to 9.2.7.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11681V-Prior to 9.2.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 3.3,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-11681V-Prior to 9.2.7.3"
]
}
]
},
{
"cve": "CVE-2021-21575",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34732241"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Dell BSAFE Micro Edition Suite)). Supported versions that are affected are Prior to 21.1.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Blockchain Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2021-22569",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "34190890"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Third Party (Google Protobuf-Java)). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2021-23017",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "33116050"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (nginx)). Supported versions that are affected are Prior to 21.1.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via UDP to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Blockchain Platform accessible data as well as unauthorized access to critical data or complete access to all Oracle Blockchain Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Blockchain Platform. CVSS 3.1 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2021-23337",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "32909428"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Lodash)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2021-23413",
"ids": [
{
"system_name": "Oracle Bug ID of Primavera Unifier",
"text": "34651798"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: User Interface (JSZip)). Supported versions that are affected are 18.8.0-18.8.18, 19.12.0-19.12.16, 20.12.0-20.12.16, 21.12.0-21.12.14 and 22.12.0-22.12.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Primavera Unifier. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10354V-20.12.0-20.12.16",
"P-10354V-19.12.0-19.12.16",
"P-10354V-21.12.0-21.12.14",
"P-10354V-22.12.0-22.12.3",
"P-10354V-18.8.0-18.8.18"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10354V-20.12.0-20.12.16",
"P-10354V-21.12.0-21.12.14",
"P-10354V-22.12.0-22.12.3",
"P-10354V-19.12.0-19.12.16",
"P-10354V-18.8.0-18.8.18"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936154.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-10354V-20.12.0-20.12.16",
"P-10354V-21.12.0-21.12.14",
"P-10354V-22.12.0-22.12.3",
"P-10354V-19.12.0-19.12.16",
"P-10354V-18.8.0-18.8.18"
]
}
]
},
{
"cve": "CVE-2021-2351",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle iLearning",
"text": "35252991"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle iLearning (component: Installation (JDBC)). The supported version that is affected is 6.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle iLearning. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iLearning, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle iLearning. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-902V-6.3.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-902V-6.3.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939823.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-902V-6.3.1"
]
}
]
},
{
"cve": "CVE-2021-23926",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "35017060"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Visual Analyzer (Apache POI)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.3 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2021-27568",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "35001442"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Application Archive (json-smart)). The supported version that is affected is 6.4.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-6.4.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-6.4.0.0.0"
]
}
]
},
{
"cve": "CVE-2021-28168",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "32995745"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Backend (Eclipse Jersey)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2021-29425",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Revenue Management and Billing",
"text": "34004708"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Infrastructure (Apache Commons IO)). Supported versions that are affected are 2.7, 2.8, 2.9, 3.0, 3.1, 3.2 and 4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Revenue Management and Billing accessible data as well as unauthorized read access to a subset of Oracle Financial Services Revenue Management and Billing accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5322V-3.0",
"P-5322V-3.1",
"P-5322V-4.0",
"P-5322V-3.2",
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.7"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5322V-3.0",
"P-5322V-3.1",
"P-5322V-4.0",
"P-5322V-3.2",
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.7"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938972.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-5322V-3.0",
"P-5322V-3.1",
"P-5322V-4.0",
"P-5322V-3.2",
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.7"
]
}
]
},
{
"cve": "CVE-2021-29921",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "33826352"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Python)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2021-30129",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "34752444"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Interoperability SEC (Apache Mina SSHD)). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.3"
]
}
]
},
{
"cve": "CVE-2021-31684",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "34918696"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Third Party (json-smart)). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2021-32808",
"ids": [
{
"system_name": "Oracle Bug ID of Siebel CRM",
"text": "33277680"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: Open UI (CKEditor)). Supported versions that are affected are 21.10 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel CRM accessible data as well as unauthorized read access to a subset of Siebel CRM accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9011V-21.10 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9011V-21.10 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939854.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-9011V-21.10 and prior"
]
}
]
},
{
"cve": "CVE-2021-32809",
"ids": [
{
"system_name": "Oracle Bug ID of Siebel CRM",
"text": "33277680"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: Open UI (CKEditor)). Supported versions that are affected are 21.10 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel CRM accessible data as well as unauthorized read access to a subset of Siebel CRM accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9011V-21.10 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9011V-21.10 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939854.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-9011V-21.10 and prior"
]
}
]
},
{
"cve": "CVE-2021-33560",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34493348"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (libgcrypt)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2021-34798",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle HTTP Server",
"text": "34844060"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (Apache HTTP Server)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1042V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1042V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-1042V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2021-35043",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "33211007"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (AntiSamy)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Insurance Policy Administration Operational Data Store for Life and Annuity, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data as well as unauthorized read access to a subset of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8"
]
}
]
},
{
"cve": "CVE-2021-3517",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34878752"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (libxml2)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2021-3518",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34878752"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (libxml2)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2021-3537",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34878752"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (libxml2)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2021-35515",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Revenue Management and Billing",
"text": "35278637"
},
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34874507"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "33196228"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Apache Commons Compress)). Supported versions that are affected are Prior to 21.1.3. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Blockchain Platform. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Content Storage Service (Apache Commons Compress)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Infrastructure (Apache Commons Compress)). Supported versions that are affected are 2.7, 2.8 and 2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Revenue Management and Billing. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5322V-2.8",
"P-5322V-2.9",
"P-2025V-12.2.1.4.0",
"P-5322V-2.7",
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.7"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938972.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0",
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.7"
]
}
]
},
{
"cve": "CVE-2021-35516",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Revenue Management and Billing",
"text": "35278637"
},
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34874507"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "33196228"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Apache Commons Compress)). Supported versions that are affected are Prior to 21.1.3. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Blockchain Platform. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Content Storage Service (Apache Commons Compress)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Infrastructure (Apache Commons Compress)). Supported versions that are affected are 2.7, 2.8 and 2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Revenue Management and Billing. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5322V-2.8",
"P-5322V-2.9",
"P-2025V-12.2.1.4.0",
"P-5322V-2.7",
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.7"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938972.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0",
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.7"
]
}
]
},
{
"cve": "CVE-2021-35517",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Revenue Management and Billing",
"text": "35278637"
},
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34874507"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "33196228"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Apache Commons Compress)). Supported versions that are affected are Prior to 21.1.3. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Blockchain Platform. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Content Storage Service (Apache Commons Compress)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Infrastructure (Apache Commons Compress)). Supported versions that are affected are 2.7, 2.8 and 2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Revenue Management and Billing. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5322V-2.8",
"P-5322V-2.9",
"P-2025V-12.2.1.4.0",
"P-5322V-2.7",
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.7"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938972.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0",
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.7"
]
}
]
},
{
"cve": "CVE-2021-36090",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Revenue Management and Billing",
"text": "35278637"
},
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "34469079"
},
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34874507"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "33196228"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Apache Commons Compress)). Supported versions that are affected are Prior to 21.1.3. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Blockchain Platform. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Third Party (Apache Commons Compress)). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Content Storage Service (Apache Commons Compress)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Infrastructure (Apache Commons Compress)). Supported versions that are affected are 2.7, 2.8 and 2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Revenue Management and Billing. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-12.2.1.4.0",
"P-5242V-14.1.1.0.0",
"P-13444V-Prior to 21.1.3",
"P-5322V-2.8",
"P-5242V-12.2.1.4.0",
"P-5322V-2.9",
"P-5322V-2.7"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.7"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938972.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0",
"P-5242V-14.1.1.0.0",
"P-5322V-2.8",
"P-5242V-12.2.1.4.0",
"P-5322V-2.9",
"P-5322V-2.7"
]
}
]
},
{
"cve": "CVE-2021-36373",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Application Testing Suite",
"text": "33176543"
},
{
"system_name": "Oracle Bug ID of Oracle Hyperion Infrastructure Technology",
"text": "33176563"
},
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "33597049"
},
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "34396262"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Load Testing for Web Apps (Apache Ant)). The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Application Testing Suite executes to compromise Oracle Application Testing Suite. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Application Testing Suite. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration (Apache Ant)). The supported version that is affected is 11.2.12. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Ant)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Middleware Common Libraries and Tools executes to compromise Oracle Middleware Common Libraries and Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Deployment SEC (Apache Ant)). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4622V-13.3.0.1",
"P-4647V-12.2.1.4.0",
"P-4392V-11.2.12",
"P-4781V-Prior to 9.2.7.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4622V-13.3.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923367.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4392V-11.2.12"
],
"url": "https://support.oracle.com/rs?type=doc&id=2775466.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4647V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-4622V-13.3.0.1",
"P-4647V-12.2.1.4.0",
"P-4392V-11.2.12",
"P-4781V-Prior to 9.2.7.3"
]
}
]
},
{
"cve": "CVE-2021-36374",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Application Testing Suite",
"text": "33176543"
},
{
"system_name": "Oracle Bug ID of Oracle Hyperion Infrastructure Technology",
"text": "33176563"
},
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "33597049"
},
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "34396262"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Load Testing for Web Apps (Apache Ant)). The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Application Testing Suite executes to compromise Oracle Application Testing Suite. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Application Testing Suite. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration (Apache Ant)). The supported version that is affected is 11.2.12. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hyperion Infrastructure Technology executes to compromise Oracle Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Infrastructure Technology. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Ant)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Middleware Common Libraries and Tools executes to compromise Oracle Middleware Common Libraries and Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Deployment SEC (Apache Ant)). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4622V-13.3.0.1",
"P-4647V-12.2.1.4.0",
"P-4392V-11.2.12",
"P-4781V-Prior to 9.2.7.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4622V-13.3.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923367.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4392V-11.2.12"
],
"url": "https://support.oracle.com/rs?type=doc&id=2775466.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4647V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-4622V-13.3.0.1",
"P-4647V-12.2.1.4.0",
"P-4392V-11.2.12",
"P-4781V-Prior to 9.2.7.3"
]
}
]
},
{
"cve": "CVE-2021-3712",
"ids": [
{
"system_name": "Oracle Bug ID of Siebel CRM",
"text": "34577693"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: Siebel Core - Server Infrastructure (OpenSSL)). Supported versions that are affected are 22.10 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Siebel CRM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM. CVSS 3.1 Base Score 7.4 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9001V-22.10 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9001V-22.10 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939854.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9001V-22.10 and prior"
]
}
]
},
{
"cve": "CVE-2021-37136",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "35042717"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Kafka)). Supported versions that are affected are 5.5.0-5.5.10 and 6.0.0-6.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
]
}
]
},
{
"cve": "CVE-2021-37137",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "35042717"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Kafka)). Supported versions that are affected are 5.5.0-5.5.10 and 6.0.0-6.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
]
}
]
},
{
"cve": "CVE-2021-37519",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications User Data Repository",
"text": "35098376"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications User Data Repository product of Oracle Communications (component: Patches (memcached)). The supported version that is affected is 12.6.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications User Data Repository executes to compromise Oracle Communications User Data Repository. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications User Data Repository. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11108V-12.6.1.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11108V-12.6.1.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938448.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-11108V-12.6.1.0.0"
]
}
]
},
{
"cve": "CVE-2021-37533",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "34889568"
},
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "35012295"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Remote Diagnostic Agent (Apache Commons Net)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker (Apache Commons Net)). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4647V-12.2.1.4.0",
"P-5085V-8.58",
"P-5085V-8.60",
"P-5085V-8.59"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4647V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.58",
"P-5085V-8.59",
"P-5085V-8.60"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939793.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5085V-8.58",
"P-5085V-8.59",
"P-4647V-12.2.1.4.0",
"P-5085V-8.60"
]
}
]
},
{
"cve": "CVE-2021-37695",
"ids": [
{
"system_name": "Oracle Bug ID of Siebel CRM",
"text": "33277680"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: Open UI (CKEditor)). Supported versions that are affected are 21.10 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Siebel CRM accessible data as well as unauthorized read access to a subset of Siebel CRM accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9011V-21.10 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9011V-21.10 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939854.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-9011V-21.10 and prior"
]
}
]
},
{
"cve": "CVE-2021-38604",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "33965075"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (glibc)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2021-3918",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34601076"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (JSON Schema)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2021-4048",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34610110"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Machine Learning (OpenBLAS)). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-6.4.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-6.4.0.0.0"
]
}
]
},
{
"cve": "CVE-2021-40528",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34493348"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (libgcrypt)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2021-40690",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "33775491"
},
{
"system_name": "Oracle Bug ID of Oracle Application Testing Suite",
"text": "33798136"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (Apache CXF)). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Load Testing for Web Apps (Apache Santuario XML Security For Java)). The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Application Testing Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4622V-13.3.0.1",
"P-2025V-6.4.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4622V-13.3.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923367.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-4622V-13.3.0.1",
"P-2025V-6.4.0.0.0"
]
}
]
},
{
"cve": "CVE-2021-4104",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
"text": "33681651"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General (Apache Log4j)). The supported version that is affected is 4.2.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework. Successful attacks of this vulnerability can result in takeover of Oracle Utilities Application Framework. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2245V-4.2.0.3.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2245V-4.2.0.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936478.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-2245V-4.2.0.3.0"
]
}
]
},
{
"cve": "CVE-2021-41182",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "33798021"
},
{
"system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
"text": "33798076"
},
{
"system_name": "Oracle Bug ID of Oracle Health Sciences InForm",
"text": "34380521"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
"text": "33798056"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "35052191"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (jQueryUI)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (jQueryUI)). Supported versions that are affected are 8.0.7.0, 8.0.8.0, 8.0.9.0, 8.1.0.0, 8.1.1.0, 8.1.2.0, 8.1.2.1 and 8.1.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Infrastructure accessible data as well as unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: User Interface (jQueryUI)). Supported versions that are affected are 2.3.0.2, 2.4.0.1, 2.5.0.0 and 2.5.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Utilities Network Management System, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Utilities Network Management System accessible data as well as unauthorized read access to a subset of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core (jQueryUI)). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Health Sciences InForm, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Health Sciences InForm accessible data as well as unauthorized read access to a subset of Oracle Health Sciences InForm accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Vision (jQueryUI)). Supported versions that are affected are 5.5.0-5.5.10 and 6.0.0-6.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-5680V-8.0.7.0",
"P-2241V-2.3.0.2",
"P-2241V-2.5.0.1",
"P-2241V-2.5.0.0",
"P-9636V-Prior to 6.3.1.3",
"P-2241V-2.4.0.1",
"P-14597V-5.5.0-5.5.10",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-9636V-Prior to 7.0.0.1",
"P-14597V-6.0.0-6.0.2",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5680V-8.1.2.2"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-5680V-8.0.7.0",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5680V-8.1.2.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939767.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2241V-2.4.0.1",
"P-2241V-2.3.0.2",
"P-2241V-2.5.0.1",
"P-2241V-2.5.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936478.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938697.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-5680V-8.0.7.0",
"P-2241V-2.3.0.2",
"P-2241V-2.5.0.1",
"P-2241V-2.5.0.0",
"P-9636V-Prior to 6.3.1.3",
"P-2241V-2.4.0.1",
"P-14597V-5.5.0-5.5.10",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-9636V-Prior to 7.0.0.1",
"P-14597V-6.0.0-6.0.2",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5680V-8.1.2.2"
]
}
]
},
{
"cve": "CVE-2021-41183",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "33798021"
},
{
"system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
"text": "33798076"
},
{
"system_name": "Oracle Bug ID of Oracle Health Sciences InForm",
"text": "34380521"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
"text": "33798056"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "35052191"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (jQueryUI)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (jQueryUI)). Supported versions that are affected are 8.0.7.0, 8.0.8.0, 8.0.9.0, 8.1.0.0, 8.1.1.0, 8.1.2.0, 8.1.2.1 and 8.1.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Infrastructure accessible data as well as unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: User Interface (jQueryUI)). Supported versions that are affected are 2.3.0.2, 2.4.0.1, 2.5.0.0 and 2.5.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Utilities Network Management System, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Utilities Network Management System accessible data as well as unauthorized read access to a subset of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core (jQueryUI)). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Health Sciences InForm, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Health Sciences InForm accessible data as well as unauthorized read access to a subset of Oracle Health Sciences InForm accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Vision (jQueryUI)). Supported versions that are affected are 5.5.0-5.5.10 and 6.0.0-6.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-5680V-8.0.7.0",
"P-2241V-2.3.0.2",
"P-2241V-2.5.0.1",
"P-2241V-2.5.0.0",
"P-9636V-Prior to 6.3.1.3",
"P-2241V-2.4.0.1",
"P-14597V-5.5.0-5.5.10",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-9636V-Prior to 7.0.0.1",
"P-14597V-6.0.0-6.0.2",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5680V-8.1.2.2"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-5680V-8.0.7.0",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5680V-8.1.2.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939767.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2241V-2.4.0.1",
"P-2241V-2.3.0.2",
"P-2241V-2.5.0.1",
"P-2241V-2.5.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936478.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938697.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-5680V-8.0.7.0",
"P-2241V-2.3.0.2",
"P-2241V-2.5.0.1",
"P-2241V-2.5.0.0",
"P-9636V-Prior to 6.3.1.3",
"P-2241V-2.4.0.1",
"P-14597V-5.5.0-5.5.10",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-9636V-Prior to 7.0.0.1",
"P-14597V-6.0.0-6.0.2",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5680V-8.1.2.2"
]
}
]
},
{
"cve": "CVE-2021-41184",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Funds Transfer Pricing",
"text": "35233062"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Data Governance for US Regulatory Reporting",
"text": "35283595"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Balance Sheet Planning",
"text": "35259152"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Asset Liability Management",
"text": "35247704"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "33798021"
},
{
"system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
"text": "33798076"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Balance Computation Engine",
"text": "35199458"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
"text": "33798056"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Reconciliation Framework",
"text": "35226260"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Loan Loss Forecasting and Provisioning",
"text": "35282640"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Profitability Management",
"text": "35222372"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Retail Performance Analytics",
"text": "35282753"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "35052191"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Data Integration Hub",
"text": "35249734"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Enterprise Financial Performance Analytics",
"text": "35282726"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Institutional Performance Analytics",
"text": "35282738"
},
{
"system_name": "Oracle Bug ID of Oracle Health Sciences InForm",
"text": "34380521"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Liquidity Risk Measurement and Management",
"text": "35221942"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Deposit Insurance Calculations for Liquidity Risk Management",
"text": "35221976"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (jQueryUI)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (jQueryUI)). Supported versions that are affected are 8.0.7.0, 8.0.8.0, 8.0.9.0, 8.1.0.0, 8.1.1.0, 8.1.2.0, 8.1.2.1 and 8.1.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Infrastructure accessible data as well as unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: User Interface (jQueryUI)). Supported versions that are affected are 2.3.0.2, 2.4.0.1, 2.5.0.0 and 2.5.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Utilities Network Management System, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Utilities Network Management System accessible data as well as unauthorized read access to a subset of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core (jQueryUI)). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Health Sciences InForm, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Health Sciences InForm accessible data as well as unauthorized read access to a subset of Oracle Health Sciences InForm accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Vision (jQueryUI)). Supported versions that are affected are 5.5.0-5.5.10 and 6.0.0-6.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Balance Computation Engine product of Oracle Financial Services Applications (component: Application (jQueryUI)). The supported version that is affected is 8.1.1.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Balance Computation Engine. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Balance Computation Engine, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Balance Computation Engine accessible data as well as unauthorized read access to a subset of Oracle Financial Services Balance Computation Engine accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Liquidity Risk Measurement and Management product of Oracle Financial Services Applications (component: Application (jQueryUI)). Supported versions that are affected are 8.0.7.3.1 and 8.0.8.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Liquidity Risk Measurement and Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Liquidity Risk Measurement and Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Liquidity Risk Measurement and Management accessible data as well as unauthorized read access to a subset of Oracle Financial Services Liquidity Risk Measurement and Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Deposit Insurance Calculations for Liquidity Risk Management product of Oracle Financial Services Applications (component: Application (jQueryUI)). Supported versions that are affected are 8.0.7.3.1 and 8.0.8.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Deposit Insurance Calculations for Liquidity Risk Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Deposit Insurance Calculations for Liquidity Risk Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Deposit Insurance Calculations for Liquidity Risk Management accessible data as well as unauthorized read access to a subset of Oracle Financial Services Deposit Insurance Calculations for Liquidity Risk Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Profitability Management product of Oracle Financial Services Applications (component: Application (jQueryUI)). The supported version that is affected is 8.0.7.8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Profitability Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Profitability Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Profitability Management accessible data as well as unauthorized read access to a subset of Oracle Financial Services Profitability Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Analytical Applications Reconciliation Framework product of Oracle Financial Services Applications (component: Application (jQueryUI)). Supported versions that are affected are 8.0.7.1.2 and 8.1.1.1.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Reconciliation Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Analytical Applications Reconciliation Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Reconciliation Framework accessible data as well as unauthorized read access to a subset of Oracle Financial Services Analytical Applications Reconciliation Framework accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Funds Transfer Pricing product of Oracle Financial Services Applications (component: Application (jQueryUI)). The supported version that is affected is 8.0.7.8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Funds Transfer Pricing. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Funds Transfer Pricing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Funds Transfer Pricing accessible data as well as unauthorized read access to a subset of Oracle Financial Services Funds Transfer Pricing accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Asset Liability Management product of Oracle Financial Services Applications (component: Application (jQueryUI)). The supported version that is affected is 8.0.7.8.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Asset Liability Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Asset Liability Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Asset Liability Management accessible data as well as unauthorized read access to a subset of Oracle Financial Services Asset Liability Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Data Integration Hub product of Oracle Financial Services Applications (component: Application (jQueryUI)). Supported versions that are affected are 8.1.0.1.4, 8.1.2.2.1 and 8.0.7.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Data Integration Hub. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Data Integration Hub, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Data Integration Hub accessible data as well as unauthorized read access to a subset of Oracle Financial Services Data Integration Hub accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Balance Sheet Planning product of Oracle Financial Services Applications (component: Application (jQueryUI)). The supported version that is affected is 8.0.8.1.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Balance Sheet Planning. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Balance Sheet Planning, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Balance Sheet Planning accessible data as well as unauthorized read access to a subset of Oracle Financial Services Balance Sheet Planning accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning product of Oracle Financial Services Applications (component: Application (jQueryUI)). Supported versions that are affected are 8.0.7.8.1 and 8.0.8.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Loan Loss Forecasting and Provisioning. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Loan Loss Forecasting and Provisioning, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Loan Loss Forecasting and Provisioning accessible data as well as unauthorized read access to a subset of Oracle Financial Services Loan Loss Forecasting and Provisioning accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Enterprise Financial Performance Analytics product of Oracle Financial Services Applications (component: Application (jQueryUI)). The supported version that is affected is 8.0.7.8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Enterprise Financial Performance Analytics. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Enterprise Financial Performance Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Enterprise Financial Performance Analytics accessible data as well as unauthorized read access to a subset of Oracle Financial Services Enterprise Financial Performance Analytics accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Institutional Performance Analytics product of Oracle Financial Services Applications (component: Application (jQueryUI)). The supported version that is affected is 8.0.7.8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Institutional Performance Analytics. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Institutional Performance Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Institutional Performance Analytics accessible data as well as unauthorized read access to a subset of Oracle Financial Services Institutional Performance Analytics accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Retail Performance Analytics product of Oracle Financial Services Applications (component: Application (jQueryUI)). The supported version that is affected is 8.0.7.8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Retail Performance Analytics. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Retail Performance Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Retail Performance Analytics accessible data as well as unauthorized read access to a subset of Oracle Financial Services Retail Performance Analytics accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Data Governance for US Regulatory Reporting product of Oracle Financial Services Applications (component: Application (jQueryUI)). Supported versions that are affected are 8.1.2.0 and 8.1.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Data Governance for US Regulatory Reporting. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Data Governance for US Regulatory Reporting, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Data Governance for US Regulatory Reporting accessible data as well as unauthorized read access to a subset of Oracle Financial Services Data Governance for US Regulatory Reporting accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-14246V-8.1.1.1.1",
"P-9332V-8.0.7.8.1",
"P-5680V-8.0.7.0",
"P-5658V-8.0.7.8.1",
"P-13802V-8.0.8.3.1",
"P-5748V-8.0.7.1.2",
"P-10216V-8.0.7.8.1",
"P-5663V-8.0.8.1.4",
"P-2241V-2.5.0.1",
"P-13797V-8.0.8.3.1",
"P-11289V-8.1.2.2.1",
"P-2241V-2.5.0.0",
"P-9636V-Prior to 6.3.1.3",
"P-13802V-8.0.7.3.1",
"P-14597V-5.5.0-5.5.10",
"P-11669V-8.1.2.1",
"P-9636V-Prior to 7.0.0.1",
"P-14597V-6.0.0-6.0.2",
"P-11669V-8.1.2.0",
"P-13797V-8.0.7.3.1",
"P-10215V-8.0.7.8.1",
"P-11289V-8.1.0.1.4",
"P-11289V-8.0.7.3.1",
"P-5662V-8.0.7.8.0",
"P-2241V-2.3.0.2",
"P-9332V-8.0.8.2.1",
"P-5659V-8.0.7.8.1",
"P-2241V-2.4.0.1",
"P-5748V-8.1.1.1.7",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-4279V-8.0.7.8.1",
"P-5680V-8.1.2.2"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-5680V-8.0.7.0",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5680V-8.1.2.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939767.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2241V-2.4.0.1",
"P-2241V-2.3.0.2",
"P-2241V-2.5.0.1",
"P-2241V-2.5.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936478.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938697.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14246V-8.1.1.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2942325.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13802V-8.0.7.3.1",
"P-13802V-8.0.8.3.1",
"P-13797V-8.0.7.3.1",
"P-13797V-8.0.8.3.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939725.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5658V-8.0.7.8.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940039.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5748V-8.0.7.1.2",
"P-5748V-8.1.1.1.7"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939780.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5659V-8.0.7.8.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940037.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5662V-8.0.7.8.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940045.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11289V-8.1.0.1.4",
"P-11289V-8.0.7.3.1",
"P-11289V-8.1.2.2.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939782.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5663V-8.0.8.1.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940043.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9332V-8.0.8.2.1",
"P-9332V-8.0.7.8.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939932.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4279V-8.0.7.8.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940042.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10215V-8.0.7.8.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940040.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10216V-8.0.7.8.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940041.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11669V-8.1.2.1",
"P-11669V-8.1.2.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940075.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-14246V-8.1.1.1.1",
"P-9332V-8.0.7.8.1",
"P-5680V-8.0.7.0",
"P-5658V-8.0.7.8.1",
"P-13802V-8.0.8.3.1",
"P-5748V-8.0.7.1.2",
"P-10216V-8.0.7.8.1",
"P-5663V-8.0.8.1.4",
"P-2241V-2.5.0.1",
"P-13797V-8.0.8.3.1",
"P-11289V-8.1.2.2.1",
"P-2241V-2.5.0.0",
"P-9636V-Prior to 6.3.1.3",
"P-13802V-8.0.7.3.1",
"P-14597V-5.5.0-5.5.10",
"P-11669V-8.1.2.1",
"P-9636V-Prior to 7.0.0.1",
"P-14597V-6.0.0-6.0.2",
"P-11669V-8.1.2.0",
"P-13797V-8.0.7.3.1",
"P-10215V-8.0.7.8.1",
"P-11289V-8.1.0.1.4",
"P-11289V-8.0.7.3.1",
"P-5662V-8.0.7.8.0",
"P-2241V-2.3.0.2",
"P-9332V-8.0.8.2.1",
"P-5659V-8.0.7.8.1",
"P-2241V-2.4.0.1",
"P-5748V-8.1.1.1.7",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-4279V-8.0.7.8.1",
"P-5680V-8.1.2.2"
]
}
]
},
{
"cve": "CVE-2021-41973",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "34700867"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Interoperability SEC (Apache Mina)). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.3"
]
}
]
},
{
"cve": "CVE-2021-42575",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Commerce Platform",
"text": "35186203"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Platform (OWASP Java HTML Sanitizer )). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9348V-11.3.1",
"P-9348V-11.3.2",
"P-9348V-11.3.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9348V-11.3.1",
"P-9348V-11.3.2",
"P-9348V-11.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939844.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-9348V-11.3.1",
"P-9348V-11.3.2",
"P-9348V-11.3.0"
]
}
]
},
{
"cve": "CVE-2021-43396",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "33965075"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (glibc)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2021-43859",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Enterprise Manager Ops Center",
"text": "35001975"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Revenue Management and Billing",
"text": "35282540"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Enterprise Manager Ops Center product of Oracle Enterprise Manager (component: Networking (XStream)). The supported version that is affected is 12.4.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Ops Center. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Manager Ops Center. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Infrastructure (XStream)). Supported versions that are affected are 2.7, 2.7.1, 2.8, 2.9, 2.9, 2.9.1, 3.0, 3.1, 3.2 and 4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Revenue Management and Billing. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5322V-3.0",
"P-9835V-12.4.0.0",
"P-5322V-3.1",
"P-5322V-4.0",
"P-5322V-3.2",
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.9.1",
"P-5322V-2.7",
"P-5322V-2.7.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9835V-12.4.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923367.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5322V-3.0",
"P-5322V-3.1",
"P-5322V-4.0",
"P-5322V-3.2",
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.9.1",
"P-5322V-2.7",
"P-5322V-2.7.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938972.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-5322V-3.0",
"P-9835V-12.4.0.0",
"P-5322V-3.1",
"P-5322V-4.0",
"P-5322V-3.2",
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.9.1",
"P-5322V-2.7",
"P-5322V-2.7.1"
]
}
]
},
{
"cve": "CVE-2021-44531",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "33974632"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud Manager (Node.js)). Supported versions that are affected are Prior to 9.2.7.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.2"
]
}
]
},
{
"cve": "CVE-2021-44532",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "33974632"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud Manager (Node.js)). Supported versions that are affected are Prior to 9.2.7.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.2"
]
}
]
},
{
"cve": "CVE-2021-44533",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "33974632"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud Manager (Node.js)). Supported versions that are affected are Prior to 9.2.7.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.2"
]
}
]
},
{
"cve": "CVE-2021-44832",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Retail Invoice Matching",
"text": "33735284"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Price Management",
"text": "33735294"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Invoice Matching product of Oracle Retail Applications (component: Security (Apache Log4j)). Supported versions that are affected are 15.0.3 and 16.0.3. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Retail Invoice Matching. Successful attacks of this vulnerability can result in takeover of Oracle Retail Invoice Matching. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Price Management product of Oracle Retail Applications (component: Security (Apache Log4j)). Supported versions that are affected are 14.1.3.2, 15.0.3.1 and 16.0.3. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Retail Price Management. Successful attacks of this vulnerability can result in takeover of Oracle Retail Price Management. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1824V-15.0.3.1",
"P-1810V-15.0.3",
"P-1810V-16.0.3",
"P-1824V-14.1.3.2",
"P-1824V-16.0.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1824V-15.0.3.1",
"P-1810V-15.0.3",
"P-1810V-16.0.3",
"P-1824V-14.1.3.2",
"P-1824V-16.0.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.6,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-1824V-15.0.3.1",
"P-1810V-15.0.3",
"P-1810V-16.0.3",
"P-1824V-14.1.3.2",
"P-1824V-16.0.3"
]
}
]
},
{
"cve": "CVE-2021-46848",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "35196462"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (GNU Libtasn1)). Supported versions that are affected are 22.4.0-22.4.4 and 23.1.0-23.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938436.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
]
}
]
},
{
"cve": "CVE-2022-1292",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards World Security",
"text": "34434388"
},
{
"system_name": "Oracle Bug ID of Oracle SD-WAN Edge",
"text": "34724754"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards World Security product of Oracle JD Edwards (component: World Software Security (OpenSSL)). The supported version that is affected is A9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards World Security. Successful attacks of this vulnerability can result in takeover of JD Edwards World Security. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Management (OpenSSL)). The supported version that is affected is 9.1.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle SD-WAN Edge. Successful attacks of this vulnerability can result in takeover of Oracle SD-WAN Edge. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4839V-A9.4",
"P-13940V-9.1.1.3.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4839V-A9.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13940V-9.1.1.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938444.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-13940V-9.1.1.3.0",
"P-4839V-A9.4"
]
}
]
},
{
"cve": "CVE-2022-1471",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle SD-WAN Edge",
"text": "35156502"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "34957478"
},
{
"system_name": "Oracle Bug ID of Oracle SQL Developer",
"text": "35156521"
},
{
"system_name": "Oracle Bug ID of Oracle Healthcare Translational Research",
"text": "35156480"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
"text": "35097354"
},
{
"system_name": "Oracle Bug ID of Oracle SQLcl (SnakeYAML)",
"text": "35156504"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Vision (SnakeYAML)). Supported versions that are affected are 5.5.0-5.5.10 and 6.0.0-6.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: TMF APIs (SnakeYAML)). Supported versions that are affected are 7.4.1, 7.4.2 and 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management. Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Translational Research product of Oracle HealthCare Applications (component: DataStudio (SnakeYAML)). Supported versions that are affected are 4.1.0 and 4.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Translational Research. Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Translational Research. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Core (SnakeYAML)). The supported version that is affected is 9.1.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SD-WAN Edge. Successful attacks of this vulnerability can result in takeover of Oracle SD-WAN Edge. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle SQLcl (SnakeYAML) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle SQL Developer (component: Installation (SnakeYAML)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9427V-4.1.0",
"P-13940V-9.1.1.4.0",
"P-9427V-4.1.1",
"P-14597V-5.5.0-5.5.10",
"P-4516V-7.4.1",
"P-4516V-7.5.0",
"P-14597V-6.0.0-6.0.2",
"P-4516V-7.4.2"
],
"known_not_affected": [
"P-1875V-Prior to 23.1.0",
"P-13824V-21c"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4516V-7.4.1",
"P-4516V-7.5.0",
"P-4516V-7.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936066.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939153.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13940V-9.1.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938444.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1875V-Prior to 23.1.0",
"P-13824V-21c"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-9427V-4.1.0",
"P-13940V-9.1.1.4.0",
"P-9427V-4.1.1",
"P-14597V-5.5.0-5.5.10",
"P-4516V-7.4.1",
"P-4516V-7.5.0",
"P-14597V-6.0.0-6.0.2",
"P-4516V-7.4.2"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-1875V-Prior to 23.1.0",
"P-13824V-21c"
]
}
]
},
{
"cve": "CVE-2022-1586",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34363210"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (PCRE2)). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-6.4.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-6.4.0.0.0"
]
}
]
},
{
"cve": "CVE-2022-1587",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34363210"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (PCRE2)). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-6.4.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-6.4.0.0.0"
]
}
]
},
{
"cve": "CVE-2022-2047",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34457280"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
"text": "34457270"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Eclipse Jetty)). Supported versions that are affected are 14.4-14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Eclipse Jetty)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13701V-14.4-14.7"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13701V-14.4-14.7"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-13701V-14.4-14.7"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-2048",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34457280"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
"text": "34457270"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Eclipse Jetty)). Supported versions that are affected are 14.4-14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Eclipse Jetty)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13701V-14.4-14.7"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13701V-14.4-14.7"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-13701V-14.4-14.7"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-2068",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "34414690"
},
{
"system_name": "Oracle Bug ID of JD Edwards World Security",
"text": "34434388"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure SEC (OpenSSL)). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the JD Edwards World Security product of Oracle JD Edwards (component: World Software Security (OpenSSL)). The supported version that is affected is A9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards World Security. Successful attacks of this vulnerability can result in takeover of JD Edwards World Security. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.3",
"P-4839V-A9.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.3",
"P-4839V-A9.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.3",
"P-4839V-A9.4"
]
}
]
},
{
"cve": "CVE-2022-2097",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "34414690"
},
{
"system_name": "Oracle Bug ID of JD Edwards World Security",
"text": "34434388"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure SEC (OpenSSL)). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the JD Edwards World Security product of Oracle JD Edwards (component: World Software Security (OpenSSL)). The supported version that is affected is A9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards World Security. Successful attacks of this vulnerability can result in takeover of JD Edwards World Security. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.3",
"P-4839V-A9.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.3",
"P-4839V-A9.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.3",
"P-4839V-A9.4"
]
}
]
},
{
"cve": "CVE-2022-21824",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "33974632"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud Manager (Node.js)). Supported versions that are affected are Prior to 9.2.7.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.2"
]
}
]
},
{
"cve": "CVE-2022-2191",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34457280"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
"text": "34457270"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Eclipse Jetty)). Supported versions that are affected are 14.4-14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Eclipse Jetty)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13701V-14.4-14.7"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13701V-14.4-14.7"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-13701V-14.4-14.7"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-2274",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "34414690"
},
{
"system_name": "Oracle Bug ID of JD Edwards World Security",
"text": "34434388"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure SEC (OpenSSL)). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the JD Edwards World Security product of Oracle JD Edwards (component: World Software Security (OpenSSL)). The supported version that is affected is A9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards World Security. Successful attacks of this vulnerability can result in takeover of JD Edwards World Security. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.3",
"P-4839V-A9.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.3",
"P-4839V-A9.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.3",
"P-4839V-A9.4"
]
}
]
},
{
"cve": "CVE-2022-22950",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Commerce Platform",
"text": "35186203"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Platform (OWASP Java HTML Sanitizer )). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9348V-11.3.1",
"P-9348V-11.3.2",
"P-9348V-11.3.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9348V-11.3.1",
"P-9348V-11.3.2",
"P-9348V-11.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939844.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-9348V-11.3.1",
"P-9348V-11.3.2",
"P-9348V-11.3.0"
]
}
]
},
{
"cve": "CVE-2022-22965",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Data Integrator",
"text": "34414923"
},
{
"system_name": "Oracle Bug ID of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity",
"text": "34028544"
},
{
"system_name": "Oracle Bug ID of Oracle Managed File Transfer",
"text": "34098087"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Insurance Policy Administration Operational Data Store for Life and Annuity product of Oracle Insurance Applications (component: Logger (Spring Framework)). The supported version that is affected is 1.0.1.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. Successful attacks of this vulnerability can result in takeover of Oracle Insurance Policy Administration Operational Data Store for Life and Annuity. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server (Spring Framework)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Managed File Transfer. Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Third Party (Spring Framework)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13339V-1.0.1.8",
"P-10198V-12.2.1.4.0",
"P-2196V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13339V-1.0.1.8"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10198V-12.2.1.4.0",
"P-2196V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-13339V-1.0.1.8",
"P-10198V-12.2.1.4.0",
"P-2196V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-22970",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
"text": "34362885"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Fiscal Management",
"text": "34362957"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
"text": "34362963"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Spring Framework)). Supported versions that are affected are 14.4-14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Fiscal Management product of Oracle Retail Applications (component: Security (Spring Framework)). The supported version that is affected is 14.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Fiscal Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Fiscal Management. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Spring Framework)). Supported versions that are affected are 17.0.6, 18.0.5, 19.0.4, 20.0.3 and 21.0.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-11513V-17.0.6",
"P-11513V-21.0.2",
"P-11513V-18.0.5",
"P-9038V-14.2",
"P-13701V-14.4-14.7"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13701V-14.4-14.7"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-11513V-17.0.6",
"P-11513V-21.0.2",
"P-11513V-18.0.5",
"P-9038V-14.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-11513V-17.0.6",
"P-11513V-21.0.2",
"P-11513V-18.0.5",
"P-9038V-14.2",
"P-13701V-14.4-14.7"
]
}
]
},
{
"cve": "CVE-2022-22971",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
"text": "34362885"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Customer Management and Segmentation Foundation",
"text": "35126381"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Fiscal Management",
"text": "34362957"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
"text": "34362963"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Spring Framework)). Supported versions that are affected are 14.4-14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Fiscal Management product of Oracle Retail Applications (component: Security (Spring Framework)). The supported version that is affected is 14.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Fiscal Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Fiscal Management. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Spring Framework)). Supported versions that are affected are 17.0.6, 18.0.5, 19.0.4, 20.0.3 and 21.0.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Internal Operations (Spring Framework)). Supported versions that are affected are 18.0.0.12 and 19.0.0.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Customer Management and Segmentation Foundation. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-13388V-19.0.0.6",
"P-11513V-17.0.6",
"P-11513V-21.0.2",
"P-11513V-18.0.5",
"P-9038V-14.2",
"P-13701V-14.4-14.7",
"P-13388V-18.0.0.12"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13701V-14.4-14.7"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-13388V-19.0.0.6",
"P-11513V-17.0.6",
"P-11513V-21.0.2",
"P-11513V-18.0.5",
"P-9038V-14.2",
"P-13388V-18.0.0.12"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-13388V-19.0.0.6",
"P-11513V-17.0.6",
"P-11513V-21.0.2",
"P-11513V-18.0.5",
"P-9038V-14.2",
"P-13701V-14.4-14.7",
"P-13388V-18.0.0.12"
]
}
]
},
{
"cve": "CVE-2022-22976",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
"text": "34366876"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Spring Security)). Supported versions that are affected are 14.4-14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management. Successful attacks of this vulnerability can result in takeover of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13701V-14.4-14.7"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13701V-14.4-14.7"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-13701V-14.4-14.7"
]
}
]
},
{
"cve": "CVE-2022-22978",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
"text": "34366876"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Spring Security)). Supported versions that are affected are 14.4-14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management. Successful attacks of this vulnerability can result in takeover of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13701V-14.4-14.7"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13701V-14.4-14.7"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-13701V-14.4-14.7"
]
}
]
},
{
"cve": "CVE-2022-22979",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
"text": "34429905"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base (Spring Cloud Function)). Supported versions that are affected are 14.4-14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13701V-14.4-14.7"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13701V-14.4-14.7"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-13701V-14.4-14.7"
]
}
]
},
{
"cve": "CVE-2022-23181",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
"text": "34211320"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Tomcat)). Supported versions that are affected are 17.0.6, 18.0.5, 19.0.4, 20.0.3 and 21.0.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Xstore Point of Service executes to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in takeover of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-11513V-17.0.6",
"P-11513V-21.0.2",
"P-11513V-18.0.5"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-11513V-17.0.6",
"P-11513V-21.0.2",
"P-11513V-18.0.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.0,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-11513V-17.0.6",
"P-11513V-21.0.2",
"P-11513V-18.0.5"
]
}
]
},
{
"cve": "CVE-2022-23218",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "33965075"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (glibc)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-23219",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "33965075"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (glibc)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-23221",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34534873"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (H2 Database)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-23302",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
"text": "33681651"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General (Apache Log4j)). The supported version that is affected is 4.2.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework. Successful attacks of this vulnerability can result in takeover of Oracle Utilities Application Framework. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2245V-4.2.0.3.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2245V-4.2.0.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936478.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-2245V-4.2.0.3.0"
]
}
]
},
{
"cve": "CVE-2022-23305",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
"text": "33681651"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General (Apache Log4j)). The supported version that is affected is 4.2.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework. Successful attacks of this vulnerability can result in takeover of Oracle Utilities Application Framework. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2245V-4.2.0.3.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2245V-4.2.0.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936478.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-2245V-4.2.0.3.0"
]
}
]
},
{
"cve": "CVE-2022-23307",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
"text": "33681651"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General (Apache Log4j)). The supported version that is affected is 4.2.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework. Successful attacks of this vulnerability can result in takeover of Oracle Utilities Application Framework. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2245V-4.2.0.3.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2245V-4.2.0.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936478.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-2245V-4.2.0.3.0"
]
}
]
},
{
"cve": "CVE-2022-23308",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34878752"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (libxml2)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-23437",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
"text": "33876495"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Revenue Management and Billing",
"text": "35282581"
},
{
"system_name": "Oracle Bug ID of Oracle Application Testing Suite",
"text": "33876452"
},
{
"system_name": "Oracle Bug ID of Oracle iLearning",
"text": "35252968"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
"text": "33876597"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Load Testing for Web Apps (Apache Xerces2 Java)). The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Application Testing Suite. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Application Testing Suite. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System, Workbench (Apache Xerces2 Java)). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Xerces2 Java)). The supported version that is affected is 17.0.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle iLearning (component: Installation (Apache Xerces2 Java)). The supported version that is affected is 6.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iLearning. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle iLearning. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Infrastructure (Apache Xerces2 Java)). Supported versions that are affected are 2.7, 2.7.1, 2.8, 2.9, 2.9.1, 3.0, 3.1, 3.2 and 4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Revenue Management and Billing. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4622V-13.3.0.1",
"P-5322V-3.0",
"P-11513V-17.0.6",
"P-5322V-3.1",
"P-5322V-4.0",
"P-5322V-3.2",
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.7",
"P-9633V-11.3.2",
"P-902V-6.3.1",
"P-5322V-2.9.1",
"P-5322V-2.7.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4622V-13.3.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923367.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9633V-11.3.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939844.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11513V-17.0.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-902V-6.3.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939823.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5322V-3.0",
"P-5322V-3.1",
"P-5322V-4.0",
"P-5322V-3.2",
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.9.1",
"P-5322V-2.7",
"P-5322V-2.7.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938972.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-4622V-13.3.0.1",
"P-5322V-3.0",
"P-11513V-17.0.6",
"P-5322V-3.1",
"P-5322V-4.0",
"P-5322V-3.2",
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.7",
"P-9633V-11.3.2",
"P-902V-6.3.1",
"P-5322V-2.9.1",
"P-5322V-2.7.1"
]
}
]
},
{
"cve": "CVE-2022-23457",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle GoldenGate Studio",
"text": "34358424"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle GoldenGate Studio product of Oracle GoldenGate (component: GoldenGate Studio (Enterprise Security API)). The supported version that is affected is Fusion Middleware: 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GoldenGate Studio. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate Studio. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10945V-Fusion Middleware: 12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10945V-Fusion Middleware: 12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-10945V-Fusion Middleware: 12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-23491",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Automated Test Suite",
"text": "34982418"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Installation (Certifi)). Supported versions that are affected are 22.3.1 and 22.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Automated Test Suite accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14488V-22.3.1",
"P-14488V-22.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14488V-22.3.1",
"P-14488V-22.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938415.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-14488V-22.3.1",
"P-14488V-22.4.0"
]
}
]
},
{
"cve": "CVE-2022-24675",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34319366"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Golang Go)). Supported versions that are affected are Prior to 21.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Blockchain Platform. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-24728",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
"text": "34142633"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Workbench (CKEditor)). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9633V-11.3.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9633V-11.3.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939844.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9633V-11.3.2"
]
}
]
},
{
"cve": "CVE-2022-24729",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
"text": "34142633"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Workbench (CKEditor)). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9633V-11.3.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9633V-11.3.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939844.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9633V-11.3.2"
]
}
]
},
{
"cve": "CVE-2022-24823",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "35001708"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Netty)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-24839",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle FLEXCUBE Core Banking",
"text": "34696710"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle FLEXCUBE Core Banking product of Oracle Financial Services Applications (component: Securities (NekoHTML)). Supported versions that are affected are 11.6, 11.7, 11.8, 11.10 and 11.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Core Banking. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle FLEXCUBE Core Banking. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9101V-11.7",
"P-9101V-11.10",
"P-9101V-11.8",
"P-9101V-11.11",
"P-9101V-11.6"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9101V-11.7",
"P-9101V-11.10",
"P-9101V-11.8",
"P-9101V-11.11",
"P-9101V-11.6"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9101V-11.7",
"P-9101V-11.10",
"P-9101V-11.8",
"P-9101V-11.11",
"P-9101V-11.6"
]
}
]
},
{
"cve": "CVE-2022-24891",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle GoldenGate Studio",
"text": "34358424"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle GoldenGate Studio product of Oracle GoldenGate (component: GoldenGate Studio (Enterprise Security API)). The supported version that is affected is Fusion Middleware: 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GoldenGate Studio. Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate Studio. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10945V-Fusion Middleware: 12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10945V-Fusion Middleware: 12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-10945V-Fusion Middleware: 12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-25235",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
"text": "34189724"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34330630"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Platform (LibExpat)). The supported version that is affected is 8.6.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via XMPP to compromise Oracle Communications Diameter Signaling Router. Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (LibExpat)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10899V-8.6.0.0"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10899V-8.6.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938440.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-10899V-8.6.0.0"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-25236",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
"text": "34189724"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34330630"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Platform (LibExpat)). The supported version that is affected is 8.6.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via XMPP to compromise Oracle Communications Diameter Signaling Router. Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (LibExpat)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10899V-8.6.0.0"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10899V-8.6.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938440.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-10899V-8.6.0.0"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-25313",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34330630"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (LibExpat)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-25314",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34330630"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (LibExpat)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-25315",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
"text": "34189724"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34330630"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Platform (LibExpat)). The supported version that is affected is 8.6.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via XMPP to compromise Oracle Communications Diameter Signaling Router. Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (LibExpat)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10899V-8.6.0.0"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10899V-8.6.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938440.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-10899V-8.6.0.0"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-25647",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Digital Experience",
"text": "34315317"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34315330"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Trade Finance",
"text": "35194572"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Payments",
"text": "35194829"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Treasury Management",
"text": "35194690"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Corporate Lending",
"text": "34315313"
},
{
"system_name": "Oracle Bug ID of Oracle FLEXCUBE Universal Banking",
"text": "34315368"
},
{
"system_name": "Oracle Bug ID of Oracle Banking APIs",
"text": "34315311"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking APIs product of Oracle Financial Services Applications (component: IDM - Authentication (Google Gson)). Supported versions that are affected are 18.2, 18.3, 19.1, 19.2, 21.1, 22.1 and 22.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking APIs. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking APIs. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core (Google Gson)). Supported versions that are affected are 14.0-14.3 and 14.5-14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: UI General (Google Gson)). Supported versions that are affected are 18.2, 18.3, 19.1, 19.2, 21.1, 22.1 and 22.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Digital Experience. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Digital Experience. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Google Gson)). Supported versions that are affected are Prior to 21.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Blockchain Platform. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure (Google Gson)). Supported versions that are affected are 14.0-14.3 and 14.5-14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle FLEXCUBE Universal Banking. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure (Google Gson)). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Trade Finance. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Treasury Management product of Oracle Financial Services Applications (component: Infra Code (Google Gson)). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Treasury Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Treasury Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Infrastructure (Google Gson)). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Payments. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9052V-14.0-14.3",
"P-13676V-21.1",
"P-14133V-14.5",
"P-12605V-18.2",
"P-12605V-19.1",
"P-14133V-14.6",
"P-13011V-14.7",
"P-13676V-22.1",
"P-14133V-14.7",
"P-13011V-14.6",
"P-13676V-22.2",
"P-13444V-Prior to 21.1.3",
"P-13011V-14.5",
"P-12989V-14.0-14.3",
"P-12605V-18.3",
"P-12605V-19.2",
"P-12605V-22.2",
"P-9052V-14.5-14.7",
"P-12605V-21.1",
"P-12605V-22.1",
"P-12989V-14.5-14.7",
"P-14134V-14.5",
"P-14134V-14.6",
"P-14134V-14.7",
"P-13676V-18.2",
"P-13676V-19.1",
"P-13676V-18.3",
"P-13676V-19.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9052V-14.0-14.3",
"P-13676V-21.1",
"P-14133V-14.5",
"P-12605V-18.2",
"P-12605V-19.1",
"P-14133V-14.6",
"P-13011V-14.7",
"P-13676V-22.1",
"P-14133V-14.7",
"P-13011V-14.6",
"P-13676V-22.2",
"P-13011V-14.5",
"P-12989V-14.0-14.3",
"P-12605V-18.3",
"P-12605V-19.2",
"P-12605V-22.2",
"P-9052V-14.5-14.7",
"P-12605V-21.1",
"P-12605V-22.1",
"P-12989V-14.5-14.7",
"P-14134V-14.5",
"P-14134V-14.6",
"P-14134V-14.7",
"P-13676V-18.2",
"P-13676V-19.1",
"P-13676V-18.3",
"P-13676V-19.2"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9052V-14.0-14.3",
"P-13676V-21.1",
"P-14133V-14.5",
"P-12605V-18.2",
"P-12605V-19.1",
"P-14133V-14.6",
"P-13011V-14.7",
"P-13676V-22.1",
"P-14133V-14.7",
"P-13011V-14.6",
"P-13676V-22.2",
"P-13444V-Prior to 21.1.3",
"P-13011V-14.5",
"P-12989V-14.0-14.3",
"P-12605V-18.3",
"P-12605V-19.2",
"P-12605V-22.2",
"P-9052V-14.5-14.7",
"P-12605V-21.1",
"P-12605V-22.1",
"P-12989V-14.5-14.7",
"P-14134V-14.5",
"P-14134V-14.6",
"P-14134V-14.7",
"P-13676V-18.2",
"P-13676V-19.1",
"P-13676V-18.3",
"P-13676V-19.2"
]
}
]
},
{
"cve": "CVE-2022-25857",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle SD-WAN Edge",
"text": "34739043"
},
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Orchestrator",
"text": "34892526"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34738980"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
"text": "34738986"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (SnakeYAML)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install/Upgrade (SnakeYAML)). Supported versions that are affected are 22.3.0 and 22.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Internal tools (SnakeYAML)). The supported version that is affected is 9.1.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SD-WAN Edge. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Edge. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security (jruby)). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Orchestrator. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14117V-22.4.0",
"P-13940V-9.1.1.4.0",
"P-14117V-22.3.0",
"P-11681V-Prior to 9.2.7.3"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14117V-22.4.0",
"P-14117V-22.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2942394.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13940V-9.1.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938444.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11681V-Prior to 9.2.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14117V-22.4.0",
"P-13940V-9.1.1.4.0",
"P-14117V-22.3.0"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-11681V-Prior to 9.2.7.3"
]
}
]
},
{
"cve": "CVE-2022-26336",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle SQL Developer",
"text": "34892754"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle SQL Developer (component: General Infrastructure (Apache POI)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-1875V-Prior to 23.1.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1875V-Prior to 23.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-1875V-Prior to 23.1.0"
]
}
]
},
{
"cve": "CVE-2022-27404",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34665845"
},
{
"system_name": "Oracle Bug ID of Oracle Hyperion Financial Reporting",
"text": "34665867"
},
{
"system_name": "Oracle Bug ID of Primavera Unifier",
"text": "34665899"
},
{
"system_name": "Oracle Bug ID of Oracle Documaker",
"text": "34665865"
},
{
"system_name": "Oracle Bug ID of Primavera P6 Enterprise Project Portfolio Management",
"text": "34665898"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (FreeType)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Development Tools (FreeType)). Supported versions that are affected are 12.6.0.0.0, 12.6.2.0.0-12.6.4.0.0, 12.7.0.0.0 and 12.7.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker. Successful attacks of this vulnerability can result in takeover of Oracle Documaker. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Installation (FreeType)). The supported version that is affected is 11.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Document Viewing using Outside In technology (FreeType)). Supported versions that are affected are 18.8.0-18.8.26, 19.12.0-19.12.21, 20.12.0-20.12.18, 21.12.0-21.12.12 and 22.12.0-22.12.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. Successful attacks of this vulnerability can result in takeover of Primavera P6 Enterprise Project Portfolio Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Document Management (FreeType)). Supported versions that are affected are 18.8.0-18.8.18, 19.12.0-19.12.16, 20.12.0-20.12.16, 21.12.0-21.12.14 and 22.12.0-22.12.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks of this vulnerability can result in takeover of Primavera Unifier. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5477V-12.7.1.0.0",
"P-5579V-22.12.0-22.12.3",
"P-5579V-20.12.0-20.12.18",
"P-10354V-19.12.0-19.12.16",
"P-5579V-21.12.0-21.12.12",
"P-10354V-20.12.0-20.12.16",
"P-5477V-12.6.0.0.0",
"P-5579V-19.12.0-19.12.21",
"P-10354V-21.12.0-21.12.14",
"P-5477V-12.7.0.0.0",
"P-10354V-22.12.0-22.12.3",
"P-8776V-11.2.12",
"P-5579V-18.8.0-18.8.26",
"P-5477V-12.6.2.0.0-12.6.4.0.0",
"P-10354V-18.8.0-18.8.18"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-5477V-12.7.0.0.0",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8776V-11.2.12"
],
"url": "https://support.oracle.com/rs?type=doc&id=2775466.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10354V-20.12.0-20.12.16",
"P-5579V-22.12.0-22.12.3",
"P-5579V-19.12.0-19.12.21",
"P-5579V-20.12.0-20.12.18",
"P-10354V-21.12.0-21.12.14",
"P-10354V-22.12.0-22.12.3",
"P-10354V-19.12.0-19.12.16",
"P-5579V-21.12.0-21.12.12",
"P-5579V-18.8.0-18.8.26",
"P-10354V-18.8.0-18.8.18"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936154.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-5477V-12.7.1.0.0",
"P-5579V-22.12.0-22.12.3",
"P-5579V-20.12.0-20.12.18",
"P-10354V-19.12.0-19.12.16",
"P-5579V-21.12.0-21.12.12",
"P-10354V-20.12.0-20.12.16",
"P-5477V-12.6.0.0.0",
"P-5579V-19.12.0-19.12.21",
"P-10354V-21.12.0-21.12.14",
"P-5477V-12.7.0.0.0",
"P-10354V-22.12.0-22.12.3",
"P-8776V-11.2.12",
"P-5579V-18.8.0-18.8.26",
"P-5477V-12.6.2.0.0-12.6.4.0.0",
"P-10354V-18.8.0-18.8.18"
]
}
]
},
{
"cve": "CVE-2022-27405",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34665845"
},
{
"system_name": "Oracle Bug ID of Oracle Hyperion Financial Reporting",
"text": "34665867"
},
{
"system_name": "Oracle Bug ID of Primavera Unifier",
"text": "34665899"
},
{
"system_name": "Oracle Bug ID of Oracle Documaker",
"text": "34665865"
},
{
"system_name": "Oracle Bug ID of Primavera P6 Enterprise Project Portfolio Management",
"text": "34665898"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (FreeType)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Development Tools (FreeType)). Supported versions that are affected are 12.6.0.0.0, 12.6.2.0.0-12.6.4.0.0, 12.7.0.0.0 and 12.7.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker. Successful attacks of this vulnerability can result in takeover of Oracle Documaker. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Installation (FreeType)). The supported version that is affected is 11.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Document Viewing using Outside In technology (FreeType)). Supported versions that are affected are 18.8.0-18.8.26, 19.12.0-19.12.21, 20.12.0-20.12.18, 21.12.0-21.12.12 and 22.12.0-22.12.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. Successful attacks of this vulnerability can result in takeover of Primavera P6 Enterprise Project Portfolio Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Document Management (FreeType)). Supported versions that are affected are 18.8.0-18.8.18, 19.12.0-19.12.16, 20.12.0-20.12.16, 21.12.0-21.12.14 and 22.12.0-22.12.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks of this vulnerability can result in takeover of Primavera Unifier. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5477V-12.7.1.0.0",
"P-5579V-22.12.0-22.12.3",
"P-5579V-20.12.0-20.12.18",
"P-10354V-19.12.0-19.12.16",
"P-5579V-21.12.0-21.12.12",
"P-10354V-20.12.0-20.12.16",
"P-5477V-12.6.0.0.0",
"P-5579V-19.12.0-19.12.21",
"P-10354V-21.12.0-21.12.14",
"P-5477V-12.7.0.0.0",
"P-10354V-22.12.0-22.12.3",
"P-8776V-11.2.12",
"P-5579V-18.8.0-18.8.26",
"P-5477V-12.6.2.0.0-12.6.4.0.0",
"P-10354V-18.8.0-18.8.18"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-5477V-12.7.0.0.0",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8776V-11.2.12"
],
"url": "https://support.oracle.com/rs?type=doc&id=2775466.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10354V-20.12.0-20.12.16",
"P-5579V-22.12.0-22.12.3",
"P-5579V-19.12.0-19.12.21",
"P-5579V-20.12.0-20.12.18",
"P-10354V-21.12.0-21.12.14",
"P-10354V-22.12.0-22.12.3",
"P-10354V-19.12.0-19.12.16",
"P-5579V-21.12.0-21.12.12",
"P-5579V-18.8.0-18.8.26",
"P-10354V-18.8.0-18.8.18"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936154.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-5477V-12.7.1.0.0",
"P-5579V-22.12.0-22.12.3",
"P-5579V-20.12.0-20.12.18",
"P-10354V-19.12.0-19.12.16",
"P-5579V-21.12.0-21.12.12",
"P-10354V-20.12.0-20.12.16",
"P-5477V-12.6.0.0.0",
"P-5579V-19.12.0-19.12.21",
"P-10354V-21.12.0-21.12.14",
"P-5477V-12.7.0.0.0",
"P-10354V-22.12.0-22.12.3",
"P-8776V-11.2.12",
"P-5579V-18.8.0-18.8.26",
"P-5477V-12.6.2.0.0-12.6.4.0.0",
"P-10354V-18.8.0-18.8.18"
]
}
]
},
{
"cve": "CVE-2022-27406",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34665845"
},
{
"system_name": "Oracle Bug ID of Oracle Hyperion Financial Reporting",
"text": "34665867"
},
{
"system_name": "Oracle Bug ID of Primavera Unifier",
"text": "34665899"
},
{
"system_name": "Oracle Bug ID of Oracle Documaker",
"text": "34665865"
},
{
"system_name": "Oracle Bug ID of Primavera P6 Enterprise Project Portfolio Management",
"text": "34665898"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (FreeType)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Development Tools (FreeType)). Supported versions that are affected are 12.6.0.0.0, 12.6.2.0.0-12.6.4.0.0, 12.7.0.0.0 and 12.7.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker. Successful attacks of this vulnerability can result in takeover of Oracle Documaker. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Installation (FreeType)). The supported version that is affected is 11.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Hyperion Financial Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Reporting. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Document Viewing using Outside In technology (FreeType)). Supported versions that are affected are 18.8.0-18.8.26, 19.12.0-19.12.21, 20.12.0-20.12.18, 21.12.0-21.12.12 and 22.12.0-22.12.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management. Successful attacks of this vulnerability can result in takeover of Primavera P6 Enterprise Project Portfolio Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Document Management (FreeType)). Supported versions that are affected are 18.8.0-18.8.18, 19.12.0-19.12.16, 20.12.0-20.12.16, 21.12.0-21.12.14 and 22.12.0-22.12.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks of this vulnerability can result in takeover of Primavera Unifier. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5477V-12.7.1.0.0",
"P-5579V-22.12.0-22.12.3",
"P-5579V-20.12.0-20.12.18",
"P-10354V-19.12.0-19.12.16",
"P-5579V-21.12.0-21.12.12",
"P-10354V-20.12.0-20.12.16",
"P-5477V-12.6.0.0.0",
"P-5579V-19.12.0-19.12.21",
"P-10354V-21.12.0-21.12.14",
"P-5477V-12.7.0.0.0",
"P-10354V-22.12.0-22.12.3",
"P-8776V-11.2.12",
"P-5579V-18.8.0-18.8.26",
"P-5477V-12.6.2.0.0-12.6.4.0.0",
"P-10354V-18.8.0-18.8.18"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-5477V-12.7.0.0.0",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8776V-11.2.12"
],
"url": "https://support.oracle.com/rs?type=doc&id=2775466.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10354V-20.12.0-20.12.16",
"P-5579V-22.12.0-22.12.3",
"P-5579V-19.12.0-19.12.21",
"P-5579V-20.12.0-20.12.18",
"P-10354V-21.12.0-21.12.14",
"P-10354V-22.12.0-22.12.3",
"P-10354V-19.12.0-19.12.16",
"P-5579V-21.12.0-21.12.12",
"P-5579V-18.8.0-18.8.26",
"P-10354V-18.8.0-18.8.18"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936154.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-5477V-12.7.1.0.0",
"P-5579V-22.12.0-22.12.3",
"P-5579V-20.12.0-20.12.18",
"P-10354V-19.12.0-19.12.16",
"P-5579V-21.12.0-21.12.12",
"P-10354V-20.12.0-20.12.16",
"P-5477V-12.6.0.0.0",
"P-5579V-19.12.0-19.12.21",
"P-10354V-21.12.0-21.12.14",
"P-5477V-12.7.0.0.0",
"P-10354V-22.12.0-22.12.3",
"P-8776V-11.2.12",
"P-5579V-18.8.0-18.8.26",
"P-5477V-12.6.2.0.0-12.6.4.0.0",
"P-10354V-18.8.0-18.8.18"
]
}
]
},
{
"cve": "CVE-2022-27778",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34343534"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (cURL)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-27779",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34343534"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (cURL)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-27780",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34343534"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (cURL)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-27781",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34343534"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (cURL)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-27782",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34343534"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (cURL)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-28199",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Session Border Controller",
"text": "34634280"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Third Party (Dpdk)). Supported versions that are affected are 9.0 and 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications Session Border Controller. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Border Controller as well as unauthorized update, insert or delete access to some of Oracle Communications Session Border Controller accessible data and unauthorized read access to a subset of Oracle Communications Session Border Controller accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10750V-9.1",
"P-10750V-9.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10750V-9.1",
"P-10750V-9.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938613.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.6,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
"version": "3.1"
},
"products": [
"P-10750V-9.1",
"P-10750V-9.0"
]
}
]
},
{
"cve": "CVE-2022-28327",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34319366"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Golang Go)). Supported versions that are affected are Prior to 21.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Blockchain Platform. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-28614",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle HTTP Server",
"text": "34844060"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (Apache HTTP Server)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1042V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1042V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-1042V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-28738",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "34413987"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud Manager (Ruby)). Supported versions that are affected are Prior to 9.2.7.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.2"
]
}
]
},
{
"cve": "CVE-2022-28739",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "34413987"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud Manager (Ruby)). Supported versions that are affected are Prior to 9.2.7.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.2"
]
}
]
},
{
"cve": "CVE-2022-2879",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle TimesTen In-Memory Database",
"text": "34807532"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle TimesTen In-Memory Database (component: Oracle TimesTen In-Memory Database (Go)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-1870V-Prior to 22.1.1.7.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1870V-Prior to 22.1.1.7.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-1870V-Prior to 22.1.1.7.0"
]
}
]
},
{
"cve": "CVE-2022-2880",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle TimesTen In-Memory Database",
"text": "34807532"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle TimesTen In-Memory Database (component: Oracle TimesTen In-Memory Database (Go)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-1870V-Prior to 22.1.1.7.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1870V-Prior to 22.1.1.7.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-1870V-Prior to 22.1.1.7.0"
]
}
]
},
{
"cve": "CVE-2022-29078",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "35035931"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Vision (Embedded JavaScript Templates)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-14597V-5.5.0-5.5.9",
"P-14597V-6.0.0-6.0.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-5.5.0-5.5.9",
"P-14597V-6.0.0-6.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-14597V-5.5.0-5.5.9",
"P-14597V-6.0.0-6.0.1"
]
}
]
},
{
"cve": "CVE-2022-29577",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Regulatory Reporting with AgileREPORTER",
"text": "34171336"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Regulatory Reporting with AgileREPORTER product of Oracle Financial Services Applications (component: Application (AntiSamy)). The supported version that is affected is 8.1.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Regulatory Reporting with AgileREPORTER. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Regulatory Reporting with AgileREPORTER, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Regulatory Reporting with AgileREPORTER accessible data as well as unauthorized read access to a subset of Oracle Financial Services Regulatory Reporting with AgileREPORTER accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13077V-8.1.1.2.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13077V-8.1.1.2.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940025.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-13077V-8.1.1.2.0"
]
}
]
},
{
"cve": "CVE-2022-29599",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "34495552"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Maven)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools. Successful attacks of this vulnerability can result in takeover of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4647V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4647V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-4647V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-29824",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34878752"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (libxml2)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-30115",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34343534"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (cURL)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-31081",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "35098149"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (HTTP::Daemon)). Supported versions that are affected are 5.5.0-5.5.10 and 6.0.0-6.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
]
}
]
},
{
"cve": "CVE-2022-31123",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
"text": "34732885"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Policy Management",
"text": "34732887"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Convergent Charging Controller",
"text": "34732884"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications Applications (component: Common fns (Grafana)). Supported versions that are affected are 12.0.4-12.0.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Convergent Charging Controller executes to compromise Oracle Communications Convergent Charging Controller. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Convergent Charging Controller. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications Applications (component: Common fns (Grafana)). Supported versions that are affected are 12.0.4-12.0.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Network Charging and Control executes to compromise Oracle Communications Network Charging and Control. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Charging and Control. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Core (Grafana)). The supported version that is affected is 12.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Policy Management executes to compromise Oracle Communications Policy Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-12985V-12.0.4-12.0.6",
"P-4623V-12.0.4-12.0.6",
"P-10900V-12.6.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12985V-12.0.4-12.0.6",
"P-4623V-12.0.4-12.0.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936023.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10900V-12.6.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938443.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-12985V-12.0.4-12.0.6",
"P-4623V-12.0.4-12.0.6",
"P-10900V-12.6.0.0.0"
]
}
]
},
{
"cve": "CVE-2022-31129",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Services Gatekeeper",
"text": "34462348"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34462341"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Moment.js)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Services Gatekeeper product of Oracle Communications (component: Third Party (Moment.js)). The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Services Gatekeeper. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Services Gatekeeper. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5381V-7.0.0.0.0"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5381V-7.0.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938446.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-5381V-7.0.0.0.0"
]
}
]
},
{
"cve": "CVE-2022-31130",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
"text": "34732885"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Policy Management",
"text": "34732887"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Convergent Charging Controller",
"text": "34732884"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications Applications (component: Common fns (Grafana)). Supported versions that are affected are 12.0.4-12.0.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Convergent Charging Controller executes to compromise Oracle Communications Convergent Charging Controller. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Convergent Charging Controller. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications Applications (component: Common fns (Grafana)). Supported versions that are affected are 12.0.4-12.0.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Network Charging and Control executes to compromise Oracle Communications Network Charging and Control. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Charging and Control. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Core (Grafana)). The supported version that is affected is 12.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Policy Management executes to compromise Oracle Communications Policy Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-12985V-12.0.4-12.0.6",
"P-4623V-12.0.4-12.0.6",
"P-10900V-12.6.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12985V-12.0.4-12.0.6",
"P-4623V-12.0.4-12.0.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936023.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10900V-12.6.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938443.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-12985V-12.0.4-12.0.6",
"P-4623V-12.0.4-12.0.6",
"P-10900V-12.6.0.0.0"
]
}
]
},
{
"cve": "CVE-2022-31160",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34432192"
},
{
"system_name": "Oracle Bug ID of MySQL Enterprise Monitor",
"text": "35182335"
},
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "34814295"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "35052191"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Pod Admin (jQueryUI)). Supported versions that are affected are 5.9.0.0.0 and 6.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console (jQueryUI)). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle WebLogic Server executes to compromise Oracle WebLogic Server. While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 3.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Vision (jQueryUI)). Supported versions that are affected are 5.5.0-5.5.10 and 6.0.0-6.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: Server (jQueryUI)). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MySQL Enterprise Monitor, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Enterprise Monitor accessible data as well as unauthorized read access to a subset of MySQL Enterprise Monitor accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-5.9.0.0.0",
"P-5242V-14.1.1.0.0",
"P-14597V-5.5.0-5.5.10",
"P-5242V-12.2.1.4.0",
"P-2025V-6.4.0.0.0",
"P-14597V-6.0.0-6.0.2",
"P-8480V-8.0.33 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-5.9.0.0.0",
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8480V-8.0.33 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-2025V-5.9.0.0.0",
"P-14597V-5.5.0-5.5.10",
"P-2025V-6.4.0.0.0",
"P-14597V-6.0.0-6.0.2",
"P-8480V-8.0.33 and prior"
]
},
{
"cvss_v3": {
"baseScore": 3.9,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-31630",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
"text": "35043773"
},
{
"system_name": "Oracle Bug ID of Oracle SD-WAN Aware",
"text": "35043775"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Platform (PHP)). The supported version that is affected is 8.6.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Diameter Signaling Router executes to compromise Oracle Communications Diameter Signaling Router. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle SD-WAN Aware product of Oracle Communications (component: Management (PHP)). The supported version that is affected is 9.0.1.6.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle SD-WAN Aware executes to compromise Oracle SD-WAN Aware. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle SD-WAN Aware accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Aware. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13941V-9.0.1.6.0",
"P-10899V-8.6.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10899V-8.6.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938440.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13941V-9.0.1.6.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938423.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"products": [
"P-10899V-8.6.0.0",
"P-13941V-9.0.1.6.0"
]
}
]
},
{
"cve": "CVE-2022-31690",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle SD-WAN Edge",
"text": "34780023"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
"text": "34780008"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Element Manager",
"text": "34780007"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Authentication (Spring Security)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Communications Element Manager. Successful attacks of this vulnerability can result in takeover of Oracle Communications Element Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: Authentication (Spring Security)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Communications Session Report Manager. Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Internal tools (Spring Security)). The supported version that is affected is 9.1.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SD-WAN Edge. Successful attacks of this vulnerability can result in takeover of Oracle SD-WAN Edge. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13940V-9.1.1.4.0",
"P-11052V-9.0.1",
"P-10770V-9.0.1",
"P-11052V-9.0.0",
"P-10770V-9.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11052V-9.0.1",
"P-11052V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938441.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10770V-9.0.1",
"P-10770V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938447.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13940V-9.1.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938444.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-13940V-9.1.1.4.0",
"P-11052V-9.0.1",
"P-10770V-9.0.1",
"P-11052V-9.0.0",
"P-10770V-9.0.0"
]
}
]
},
{
"cve": "CVE-2022-31692",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle SD-WAN Edge",
"text": "34780023"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
"text": "34780008"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Element Manager",
"text": "34780007"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Authentication (Spring Security)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Communications Element Manager. Successful attacks of this vulnerability can result in takeover of Oracle Communications Element Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: Authentication (Spring Security)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Communications Session Report Manager. Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Internal tools (Spring Security)). The supported version that is affected is 9.1.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SD-WAN Edge. Successful attacks of this vulnerability can result in takeover of Oracle SD-WAN Edge. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13940V-9.1.1.4.0",
"P-11052V-9.0.1",
"P-10770V-9.0.1",
"P-11052V-9.0.0",
"P-10770V-9.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11052V-9.0.1",
"P-11052V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938441.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10770V-9.0.1",
"P-10770V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938447.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13940V-9.1.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938444.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-13940V-9.1.1.4.0",
"P-11052V-9.0.1",
"P-10770V-9.0.1",
"P-11052V-9.0.0",
"P-10770V-9.0.0"
]
}
]
},
{
"cve": "CVE-2022-3171",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Trade Finance",
"text": "35194602"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34859650"
},
{
"system_name": "Oracle Bug ID of Oracle FLEXCUBE Universal Banking",
"text": "34859672"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Customer Management and Segmentation Foundation",
"text": "34859694"
},
{
"system_name": "Oracle Bug ID of Oracle Healthcare Translational Research",
"text": "34859684"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Corporate Lending",
"text": "34859639"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Treasury Management",
"text": "35194728"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Policy Management",
"text": "34859664"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Payments",
"text": "34859643"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "34859665"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core (Google Protobuf-Java)). Supported versions that are affected are 14.0-14.3 and 14.5-14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Corporate Lending. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Infrastructure (Google Protobuf-Java)). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Payments. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Google Protobuf-Java)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Core (Google Protobuf-Java)). The supported version that is affected is 12.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Policy Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Google Protobuf-Java)). Supported versions that are affected are 5.5.0-5.5.9 and 6.0.0-6.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure (Google Protobuf-Java)). Supported versions that are affected are 14.0-14.3 and 14.5-14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle FLEXCUBE Universal Banking. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Translational Research product of Oracle HealthCare Applications (component: DataStudio (Google Protobuf-Java)). Supported versions that are affected are 4.1.0 and 4.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Translational Research. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Healthcare Translational Research. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Internal Operations (Google Protobuf-Java)). Supported versions that are affected are 18.0.0.12 and 19.0.0.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Customer Management and Segmentation Foundation. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure (Google Protobuf-Java)). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Trade Finance. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Treasury Management product of Oracle Financial Services Applications (component: Infra Code (Google Protobuf-Java)). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Treasury Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Treasury Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-12989V-14.0-14.3",
"P-9052V-14.0-14.3",
"P-14597V-5.5.0-5.5.9",
"P-10900V-12.6.0.0.0",
"P-9427V-4.1.0",
"P-14133V-14.5",
"P-13011V-14.7",
"P-13388V-19.0.0.6",
"P-14133V-14.6",
"P-9427V-4.1.1",
"P-13011V-14.6",
"P-14133V-14.7",
"P-13011V-14.5",
"P-9052V-14.5-14.7",
"P-12989V-14.5-14.7",
"P-14597V-6.0.0-6.0.1",
"P-14134V-14.5",
"P-14134V-14.6",
"P-14134V-14.7",
"P-13388V-18.0.0.12"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12989V-14.0-14.3",
"P-9052V-14.0-14.3",
"P-14133V-14.5",
"P-13011V-14.7",
"P-14133V-14.6",
"P-13011V-14.6",
"P-14133V-14.7",
"P-13011V-14.5",
"P-9052V-14.5-14.7",
"P-12989V-14.5-14.7",
"P-14134V-14.5",
"P-14134V-14.6",
"P-14134V-14.7"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10900V-12.6.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938443.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-5.5.0-5.5.9",
"P-14597V-6.0.0-6.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939153.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13388V-19.0.0.6",
"P-13388V-18.0.0.12"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-12989V-14.0-14.3",
"P-9052V-14.0-14.3",
"P-14597V-5.5.0-5.5.9",
"P-10900V-12.6.0.0.0",
"P-9427V-4.1.0",
"P-14133V-14.5",
"P-13011V-14.7",
"P-13388V-19.0.0.6",
"P-14133V-14.6",
"P-9427V-4.1.1",
"P-13011V-14.6",
"P-14133V-14.7",
"P-13011V-14.5",
"P-9052V-14.5-14.7",
"P-12989V-14.5-14.7",
"P-14597V-6.0.0-6.0.1",
"P-14134V-14.5",
"P-14134V-14.6",
"P-14134V-14.7",
"P-13388V-18.0.0.12"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-32212",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34797516"
},
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "33974632"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34797529"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud Manager (Node.js)). Supported versions that are affected are Prior to 9.2.7.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Lifecycle (Node.js)). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Node.js)). Supported versions that are affected are Prior to 21.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Blockchain Platform accessible data as well as unauthorized read access to a subset of Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.2",
"P-2025V-6.4.0.0.0",
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.2"
]
},
{
"cvss_v3": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-2025V-6.4.0.0.0"
]
},
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-32213",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34797516"
},
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "33974632"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34797529"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud Manager (Node.js)). Supported versions that are affected are Prior to 9.2.7.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Lifecycle (Node.js)). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Node.js)). Supported versions that are affected are Prior to 21.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Blockchain Platform accessible data as well as unauthorized read access to a subset of Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.2",
"P-2025V-6.4.0.0.0",
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.2"
]
},
{
"cvss_v3": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-2025V-6.4.0.0.0"
]
},
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-32215",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34797516"
},
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "33974632"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34797529"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud Manager (Node.js)). Supported versions that are affected are Prior to 9.2.7.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Lifecycle (Node.js)). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Node.js)). Supported versions that are affected are Prior to 21.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Blockchain Platform accessible data as well as unauthorized read access to a subset of Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.2",
"P-2025V-6.4.0.0.0",
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.2"
]
},
{
"cvss_v3": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-2025V-6.4.0.0.0"
]
},
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-32222",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34797516"
},
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "33974632"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34797529"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: E1 Dev Platform Tech - Cloud Manager (Node.js)). Supported versions that are affected are Prior to 9.2.7.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Lifecycle (Node.js)). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle Blockchain Platform (component: BCS Console (Node.js)). Supported versions that are affected are Prior to 21.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Blockchain Platform. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Blockchain Platform accessible data as well as unauthorized read access to a subset of Oracle Blockchain Platform accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.2",
"P-2025V-6.4.0.0.0",
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.2"
]
},
{
"cvss_v3": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-2025V-6.4.0.0.0"
]
},
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-3358",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards World Security",
"text": "34434388"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards World Security product of Oracle JD Edwards (component: World Software Security (OpenSSL)). The supported version that is affected is A9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards World Security. Successful attacks of this vulnerability can result in takeover of JD Edwards World Security. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4839V-A9.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4839V-A9.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-4839V-A9.4"
]
}
]
},
{
"cve": "CVE-2022-33980",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
"text": "34436491"
},
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "34666403"
},
{
"system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
"text": "34436493"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Commons Configuration)). Supported versions that are affected are 18.0.5, 19.0.4, 20.0.3 and 21.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in takeover of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide (Apache Commons Configuration)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Commons Configuration)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools. Successful attacks of this vulnerability can result in takeover of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11513V-20.0.3",
"P-4647V-12.2.1.4.0",
"P-11513V-19.0.4",
"P-11513V-21.0.2",
"P-11513V-18.0.5"
],
"known_not_affected": [
"P-2241V-2.4.0.1",
"P-2241V-2.3.0.2",
"P-2241V-2.5.0.2",
"P-2241V-2.5.0.1",
"P-2241V-2.5.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-11513V-21.0.2",
"P-11513V-18.0.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2241V-2.4.0.1",
"P-2241V-2.3.0.2",
"P-2241V-2.5.0.2",
"P-2241V-2.5.0.1",
"P-2241V-2.5.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936478.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4647V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-11513V-21.0.2",
"P-11513V-18.0.5",
"P-4647V-12.2.1.4.0"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-2241V-2.4.0.1",
"P-2241V-2.3.0.2",
"P-2241V-2.5.0.2",
"P-2241V-2.5.0.1",
"P-2241V-2.5.0.0"
]
}
]
},
{
"cve": "CVE-2022-34169",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34874285"
},
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "35016515"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Revenue Management and Billing",
"text": "35282620"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: JAXP (Apache Xalan-J)). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition and unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker (Apache Xalan-Java)). The supported version that is affected is 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Infrastructure (Apache Xalan-Java)). Supported versions that are affected are 2.7, 2.7.1, 2.8, 2.9, 2.9.1, 3.0, 3.1, 3.2 and 4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Revenue Management and Billing accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5322V-3.0",
"P-2025V-12.2.1.4.0",
"P-5085V-8.58",
"P-5322V-3.1",
"P-5322V-4.0",
"P-5322V-3.2",
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.9.1",
"P-5322V-2.7",
"P-5322V-2.7.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.58"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939793.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5322V-3.0",
"P-5322V-3.1",
"P-5322V-4.0",
"P-5322V-3.2",
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.9.1",
"P-5322V-2.7",
"P-5322V-2.7.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938972.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-5322V-3.0",
"P-5085V-8.58",
"P-5322V-3.1",
"P-5322V-4.0",
"P-5322V-3.2",
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.9.1",
"P-5322V-2.7",
"P-5322V-2.7.1"
]
}
]
},
{
"cve": "CVE-2022-34305",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Managed File Transfer",
"text": "34552164"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server (Apache Tomcat)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Managed File Transfer. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Managed File Transfer, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Managed File Transfer accessible data as well as unauthorized read access to a subset of Oracle Managed File Transfer accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10198V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10198V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-10198V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-3479",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Healthcare Translational Research",
"text": "35166346"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Translational Research product of Oracle HealthCare Applications (component: DataStudio (NSS)). Supported versions that are affected are 4.1.0 and 4.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Translational Research. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Healthcare Translational Research. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939153.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
]
}
]
},
{
"cve": "CVE-2022-34917",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle SQL Developer",
"text": "35127365"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34676524"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Apache Kafka)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle SQL Developer (component: Installation (Apache Kafka)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-1875V-Prior to 23.1.0",
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3",
"P-1875V-Prior to 23.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-1875V-Prior to 23.1.0"
]
}
]
},
{
"cve": "CVE-2022-35737",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "35196452"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (SQLite)). Supported versions that are affected are 22.4.0-22.4.4 and 23.1.0-23.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938436.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
]
}
]
},
{
"cve": "CVE-2022-3602",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards World Security",
"text": "34434388"
},
{
"system_name": "Oracle Bug ID of MySQL Cluster",
"text": "35095122"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards World Security product of Oracle JD Edwards (component: World Software Security (OpenSSL)). The supported version that is affected is A9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards World Security. Successful attacks of this vulnerability can result in takeover of JD Edwards World Security. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: JS module (Node.js)). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8479V-8.0.32 and prior",
"P-4839V-A9.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4839V-A9.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8479V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-4839V-A9.4"
]
},
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-8479V-8.0.32 and prior"
]
}
]
},
{
"cve": "CVE-2022-36033",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Digital Experience",
"text": "34897685"
},
{
"system_name": "Oracle Bug ID of Primavera Unifier",
"text": "34897728"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Trade Finance",
"text": "35194597"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Customer Management and Segmentation Foundation",
"text": "34897714"
},
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "34914573"
},
{
"system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
"text": "34897715"
},
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "34897726"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Treasury Management",
"text": "35194708"
},
{
"system_name": "Oracle Bug ID of Oracle WebCenter Portal",
"text": "34897731"
},
{
"system_name": "Oracle Bug ID of Oracle FLEXCUBE Universal Banking",
"text": "34760436"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure (jsoup)). Supported versions that are affected are 14.0-14.3 and 14.5-14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Universal Banking, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data as well as unauthorized read access to a subset of Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: UI General (jsoup)). Supported versions that are affected are 18.2, 18.3, 19.1, 19.2, 21.1, 22.1 and 22.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Digital Experience. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Digital Experience, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Digital Experience accessible data as well as unauthorized read access to a subset of Oracle Banking Digital Experience accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Internal Operations (jsoup)). Supported versions that are affected are 18.0.0.12 and 19.0.0.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Customer Management and Segmentation Foundation, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Retail Customer Management and Segmentation Foundation accessible data as well as unauthorized read access to a subset of Oracle Retail Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Installer (jsoup)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Process Management Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Business Process Management Suite accessible data as well as unauthorized read access to a subset of Oracle Business Process Management Suite accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search (jsoup)). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: User Interface (jsoup)). Supported versions that are affected are 18.8.0-18.8.18, 19.12.0-19.12.16, 20.12.0-20.12.16, 21.12.0-21.12.14 and 22.12.0-22.12.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Unifier, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Primavera Unifier accessible data as well as unauthorized read access to a subset of Primavera Unifier accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (jsoup)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data as well as unauthorized read access to a subset of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (jsoup)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Middleware Common Libraries and Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Middleware Common Libraries and Tools accessible data as well as unauthorized read access to a subset of Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure (jsoup)). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Trade Finance. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Trade Finance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Trade Finance accessible data as well as unauthorized read access to a subset of Oracle Banking Trade Finance accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Treasury Management product of Oracle Financial Services Applications (component: Infrastructure (jsoup)). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Treasury Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Treasury Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Treasury Management accessible data as well as unauthorized read access to a subset of Oracle Banking Treasury Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9052V-14.0-14.3",
"P-10354V-19.12.0-19.12.16",
"P-5325V-12.2.1.4.0",
"P-1696V-12.2.1.4.0",
"P-14133V-14.5",
"P-12605V-18.2",
"P-12605V-19.1",
"P-14133V-14.6",
"P-14133V-14.7",
"P-10354V-18.8.0-18.8.18",
"P-5085V-8.58",
"P-5085V-8.59",
"P-12605V-18.3",
"P-12605V-19.2",
"P-10354V-20.12.0-20.12.16",
"P-13388V-19.0.0.6",
"P-10354V-21.12.0-21.12.14",
"P-12605V-22.2",
"P-10354V-22.12.0-22.12.3",
"P-9052V-14.5-14.7",
"P-12605V-21.1",
"P-4647V-12.2.1.4.0",
"P-12605V-22.1",
"P-14134V-14.5",
"P-14134V-14.6",
"P-5085V-8.60",
"P-14134V-14.7",
"P-13388V-18.0.0.12"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9052V-14.0-14.3",
"P-12605V-18.3",
"P-12605V-19.2",
"P-14133V-14.5",
"P-12605V-18.2",
"P-12605V-19.1",
"P-14133V-14.6",
"P-12605V-22.2",
"P-14133V-14.7",
"P-9052V-14.5-14.7",
"P-12605V-21.1",
"P-12605V-22.1",
"P-14134V-14.5",
"P-14134V-14.6",
"P-14134V-14.7"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13388V-19.0.0.6",
"P-13388V-18.0.0.12"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4647V-12.2.1.4.0",
"P-5325V-12.2.1.4.0",
"P-1696V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.58",
"P-5085V-8.59",
"P-5085V-8.60"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939793.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10354V-20.12.0-20.12.16",
"P-10354V-21.12.0-21.12.14",
"P-10354V-22.12.0-22.12.3",
"P-10354V-19.12.0-19.12.16",
"P-10354V-18.8.0-18.8.18"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936154.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-9052V-14.0-14.3",
"P-10354V-19.12.0-19.12.16",
"P-5325V-12.2.1.4.0",
"P-1696V-12.2.1.4.0",
"P-14133V-14.5",
"P-12605V-18.2",
"P-12605V-19.1",
"P-14133V-14.6",
"P-14133V-14.7",
"P-10354V-18.8.0-18.8.18",
"P-5085V-8.58",
"P-5085V-8.59",
"P-12605V-18.3",
"P-12605V-19.2",
"P-10354V-20.12.0-20.12.16",
"P-13388V-19.0.0.6",
"P-10354V-21.12.0-21.12.14",
"P-12605V-22.2",
"P-10354V-22.12.0-22.12.3",
"P-9052V-14.5-14.7",
"P-12605V-21.1",
"P-4647V-12.2.1.4.0",
"P-12605V-22.1",
"P-14134V-14.5",
"P-14134V-14.6",
"P-5085V-8.60",
"P-14134V-14.7",
"P-13388V-18.0.0.12"
]
}
]
},
{
"cve": "CVE-2022-36760",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "35060217"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache HTTP Server)). Supported versions that are affected are 5.5.0-5.5.10 and 6.0.0-6.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. While the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.0,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
]
}
]
},
{
"cve": "CVE-2022-37434",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Cluster",
"text": "34711758"
},
{
"system_name": "Oracle Bug ID of Oracle Enterprise Session Router",
"text": "34711813"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Predictive Application Server",
"text": "34711847"
},
{
"system_name": "Oracle Bug ID of Oracle Enterprise Communications Broker",
"text": "34711749"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Session Border Controller",
"text": "34711798"
},
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34711766"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Session Router",
"text": "34711799"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Subscriber-Aware Load Balancer",
"text": "34711800"
},
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34711762"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
"text": "34711795"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Policy Management",
"text": "34711796"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Core Session Manager",
"text": "34711786"
},
{
"system_name": "Oracle Bug ID of Oracle HTTP Server",
"text": "34711830"
},
{
"system_name": "Oracle Bug ID of Oracle Communications IP Service Activator",
"text": "34711791"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Enterprise Communications Broker product of Oracle Communications (component: Routing (zlib)). Supported versions that are affected are 3.3 and 4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Communications Broker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Communications Broker as well as unauthorized update, insert or delete access to some of Oracle Enterprise Communications Broker accessible data and unauthorized read access to a subset of Oracle Enterprise Communications Broker accessible data. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the MySQL Cluster product of Oracle MySQL (component: Cluster: General (zlib)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB (zlib)). Supported versions that are affected are 5.7.41 and prior and 8.0.31 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (zlib)). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Core Session Manager product of Oracle Communications (component: Routing (zlib)). Supported versions that are affected are 8.45 and 9.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Core Session Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Core Session Manager as well as unauthorized update, insert or delete access to some of Oracle Communications Core Session Manager accessible data and unauthorized read access to a subset of Oracle Communications Core Session Manager accessible data. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Communications IP Service Activator product of Oracle Communications Applications (component: Other (zlib)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (glibc)). The supported version that is affected is 5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Communications Operations Monitor. Successful attacks of this vulnerability can result in takeover of Oracle Communications Operations Monitor. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Core (zlib)). The supported version that is affected is 12.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management. Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routing (zlib)). Supported versions that are affected are 9.0 and 9.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Session Border Controller. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Border Controller as well as unauthorized update, insert or delete access to some of Oracle Communications Session Border Controller accessible data and unauthorized read access to a subset of Oracle Communications Session Border Controller accessible data. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Session Router product of Oracle Communications (component: Routing (zlib)). Supported versions that are affected are 9.0 and 9.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Session Router. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Router as well as unauthorized update, insert or delete access to some of Oracle Communications Session Router accessible data and unauthorized read access to a subset of Oracle Communications Session Router accessible data. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Subscriber-Aware Load Balancer product of Oracle Communications (component: Routing (zlib)). Supported versions that are affected are 9.0 and 9.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Subscriber-Aware Load Balancer. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Subscriber-Aware Load Balancer as well as unauthorized update, insert or delete access to some of Oracle Communications Subscriber-Aware Load Balancer accessible data and unauthorized read access to a subset of Oracle Communications Subscriber-Aware Load Balancer accessible data. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Enterprise Session Router product of Oracle Communications (component: Routing (zlib)). The supported version that is affected is 9.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Session Router. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Session Router as well as unauthorized update, insert or delete access to some of Oracle Enterprise Session Router accessible data and unauthorized read access to a subset of Oracle Enterprise Session Router accessible data. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (zlib)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Predictive Application Server product of Oracle Retail Applications (component: RPAS Server (zlib)). Supported versions that are affected are 15.0.3 and 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Predictive Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Retail Predictive Application Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10758V-4.0",
"P-10752V-9.0",
"P-10752V-9.1",
"P-10758V-3.3",
"P-10766V-9.1",
"P-10754V-9.15",
"P-1042V-12.2.1.4.0",
"P-10754V-8.45",
"P-2025V-6.4.0.0.0",
"P-1823V-16.0.3",
"P-10766V-9.0",
"P-10900V-12.6.0.0.0",
"P-10750V-9.1",
"P-10761V-5.0",
"P-10750V-9.0",
"P-8478V-8.0.31 and prior",
"P-1823V-15.0.3",
"P-14615V-9.1",
"P-8478V-5.7.41 and prior"
],
"known_not_affected": [
"P-8479V-7.6.25 and prior",
"P-8479V-7.5.29 and prior",
"P-2261V-7.4.0",
"P-8479V-8.0.31 and prior",
"P-2261V-7.5.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10758V-4.0",
"P-10758V-3.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938617.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8479V-7.6.25 and prior",
"P-8479V-7.5.29 and prior",
"P-8478V-8.0.31 and prior",
"P-8479V-8.0.31 and prior",
"P-8478V-5.7.41 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10754V-9.15",
"P-10754V-8.45"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938621.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2261V-7.4.0",
"P-2261V-7.5.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936021.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10761V-5.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938442.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10900V-12.6.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938443.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10750V-9.1",
"P-10750V-9.0",
"P-10752V-9.0",
"P-14615V-9.1",
"P-10752V-9.1",
"P-10766V-9.1",
"P-10766V-9.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938613.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1042V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1823V-15.0.3",
"P-1823V-16.0.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.0,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H",
"version": "3.1"
},
"products": [
"P-10750V-9.1",
"P-10750V-9.0",
"P-10758V-4.0",
"P-10752V-9.0",
"P-14615V-9.1",
"P-10752V-9.1",
"P-10758V-3.3",
"P-10766V-9.1",
"P-10754V-9.15",
"P-10754V-8.45",
"P-10766V-9.0"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-8479V-7.6.25 and prior",
"P-8479V-7.5.29 and prior",
"P-8479V-8.0.31 and prior"
]
},
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-10761V-5.0",
"P-8478V-8.0.31 and prior",
"P-1823V-15.0.3",
"P-1042V-12.2.1.4.0",
"P-2025V-6.4.0.0.0",
"P-1823V-16.0.3",
"P-8478V-5.7.41 and prior",
"P-10900V-12.6.0.0.0"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-2261V-7.4.0",
"P-2261V-7.5.0"
]
}
]
},
{
"cve": "CVE-2022-37436",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "35060217"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache HTTP Server)). Supported versions that are affected are 5.5.0-5.5.10 and 6.0.0-6.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. While the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.0,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
]
}
]
},
{
"cve": "CVE-2022-37454",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
"text": "35043773"
},
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "34997341"
},
{
"system_name": "Oracle Bug ID of Oracle SD-WAN Aware",
"text": "35043775"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Database OML4PY (Python) component of Oracle Database Server. The supported version that is affected is 21c. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via HTTP to compromise Oracle Database OML4PY (Python). Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Database OML4PY (Python). CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Platform (PHP)). The supported version that is affected is 8.6.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Diameter Signaling Router executes to compromise Oracle Communications Diameter Signaling Router. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle SD-WAN Aware product of Oracle Communications (component: Management (PHP)). The supported version that is affected is 9.0.1.6.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle SD-WAN Aware executes to compromise Oracle SD-WAN Aware. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle SD-WAN Aware accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Aware. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13941V-9.0.1.6.0",
"P-5(Oracle Database OML4PY)V-21c",
"P-10899V-8.6.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Oracle Database OML4PY)V-21c"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10899V-8.6.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938440.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13941V-9.0.1.6.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938423.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-5(Oracle Database OML4PY)V-21c"
]
},
{
"cvss_v3": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"products": [
"P-10899V-8.6.0.0",
"P-13941V-9.0.1.6.0"
]
}
]
},
{
"cve": "CVE-2022-3786",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards World Security",
"text": "34434388"
},
{
"system_name": "Oracle Bug ID of MySQL Cluster",
"text": "35095122"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards World Security product of Oracle JD Edwards (component: World Software Security (OpenSSL)). The supported version that is affected is A9.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards World Security. Successful attacks of this vulnerability can result in takeover of JD Edwards World Security. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: JS module (Node.js)). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8479V-8.0.32 and prior",
"P-4839V-A9.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4839V-A9.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8479V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-4839V-A9.4"
]
},
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-8479V-8.0.32 and prior"
]
}
]
},
{
"cve": "CVE-2022-37865",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Automated Test Suite",
"text": "34982434"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Installation (Apache Ivy)). Supported versions that are affected are 22.3.1 and 22.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Automated Test Suite accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14488V-22.3.1",
"P-14488V-22.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14488V-22.3.1",
"P-14488V-22.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938415.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14488V-22.3.1",
"P-14488V-22.4.0"
]
}
]
},
{
"cve": "CVE-2022-37866",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Automated Test Suite",
"text": "34982434"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Installation (Apache Ivy)). Supported versions that are affected are 22.3.1 and 22.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Automated Test Suite accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14488V-22.3.1",
"P-14488V-22.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14488V-22.3.1",
"P-14488V-22.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938415.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14488V-22.3.1",
"P-14488V-22.4.0"
]
}
]
},
{
"cve": "CVE-2022-3821",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "35196440"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (systemd)). Supported versions that are affected are 22.4.0-22.4.4 and 23.1.0-23.1.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938436.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
]
}
]
},
{
"cve": "CVE-2022-38749",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle SD-WAN Edge",
"text": "34739043"
},
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Orchestrator",
"text": "34892526"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34738980"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
"text": "34738986"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (SnakeYAML)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install/Upgrade (SnakeYAML)). Supported versions that are affected are 22.3.0 and 22.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Internal tools (SnakeYAML)). The supported version that is affected is 9.1.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SD-WAN Edge. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Edge. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security (jruby)). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Orchestrator. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14117V-22.4.0",
"P-13940V-9.1.1.4.0",
"P-14117V-22.3.0",
"P-11681V-Prior to 9.2.7.3"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14117V-22.4.0",
"P-14117V-22.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2942394.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13940V-9.1.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938444.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11681V-Prior to 9.2.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14117V-22.4.0",
"P-13940V-9.1.1.4.0",
"P-14117V-22.3.0"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-11681V-Prior to 9.2.7.3"
]
}
]
},
{
"cve": "CVE-2022-38750",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle SD-WAN Edge",
"text": "34739043"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34738980"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
"text": "34738986"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (SnakeYAML)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install/Upgrade (SnakeYAML)). Supported versions that are affected are 22.3.0 and 22.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Internal tools (SnakeYAML)). The supported version that is affected is 9.1.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SD-WAN Edge. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Edge. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14117V-22.4.0",
"P-13940V-9.1.1.4.0",
"P-14117V-22.3.0"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14117V-22.4.0",
"P-14117V-22.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2942394.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13940V-9.1.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938444.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14117V-22.4.0",
"P-13940V-9.1.1.4.0",
"P-14117V-22.3.0"
]
}
]
},
{
"cve": "CVE-2022-38751",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle SD-WAN Edge",
"text": "34739043"
},
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Orchestrator",
"text": "34892526"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34738980"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
"text": "34738986"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (SnakeYAML)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install/Upgrade (SnakeYAML)). Supported versions that are affected are 22.3.0 and 22.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Internal tools (SnakeYAML)). The supported version that is affected is 9.1.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SD-WAN Edge. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Edge. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security (jruby)). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Orchestrator. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14117V-22.4.0",
"P-13940V-9.1.1.4.0",
"P-14117V-22.3.0",
"P-11681V-Prior to 9.2.7.3"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14117V-22.4.0",
"P-14117V-22.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2942394.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13940V-9.1.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938444.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11681V-Prior to 9.2.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14117V-22.4.0",
"P-13940V-9.1.1.4.0",
"P-14117V-22.3.0"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-11681V-Prior to 9.2.7.3"
]
}
]
},
{
"cve": "CVE-2022-38752",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle SD-WAN Edge",
"text": "34739043"
},
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Orchestrator",
"text": "34892526"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34738980"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
"text": "35276764"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
"text": "34738986"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (SnakeYAML)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install/Upgrade (SnakeYAML)). Supported versions that are affected are 22.3.0 and 22.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Internal tools (SnakeYAML)). The supported version that is affected is 9.1.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle SD-WAN Edge. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Edge. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security (jruby)). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Orchestrator. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Application (SnakeYAML)). Supported versions that are affected are 8.1.0.0 and 8.1.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Model Management and Governance. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14117V-22.4.0",
"P-13940V-9.1.1.4.0",
"P-14276V-8.1.2.0",
"P-14117V-22.3.0",
"P-11681V-Prior to 9.2.7.3",
"P-14276V-8.1.0.0"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14117V-22.4.0",
"P-14117V-22.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2942394.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13940V-9.1.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938444.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11681V-Prior to 9.2.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14276V-8.1.0.0",
"P-14276V-8.1.2.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939794.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14117V-22.4.0",
"P-13940V-9.1.1.4.0",
"P-14117V-22.3.0",
"P-14276V-8.1.0.0",
"P-14276V-8.1.2.0"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-11681V-Prior to 9.2.7.3"
]
}
]
},
{
"cve": "CVE-2022-39135",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "34944652"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Essbase (component: Build (Apache Calcite)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-4379V-21.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4379V-21.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-4379V-21.4"
]
}
]
},
{
"cve": "CVE-2022-39201",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
"text": "34732885"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Policy Management",
"text": "34732887"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Convergent Charging Controller",
"text": "34732884"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications Applications (component: Common fns (Grafana)). Supported versions that are affected are 12.0.4-12.0.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Convergent Charging Controller executes to compromise Oracle Communications Convergent Charging Controller. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Convergent Charging Controller. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications Applications (component: Common fns (Grafana)). Supported versions that are affected are 12.0.4-12.0.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Network Charging and Control executes to compromise Oracle Communications Network Charging and Control. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Charging and Control. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Core (Grafana)). The supported version that is affected is 12.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Policy Management executes to compromise Oracle Communications Policy Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-12985V-12.0.4-12.0.6",
"P-4623V-12.0.4-12.0.6",
"P-10900V-12.6.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12985V-12.0.4-12.0.6",
"P-4623V-12.0.4-12.0.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936023.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10900V-12.6.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938443.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-12985V-12.0.4-12.0.6",
"P-4623V-12.0.4-12.0.6",
"P-10900V-12.6.0.0.0"
]
}
]
},
{
"cve": "CVE-2022-39229",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
"text": "34732885"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Policy Management",
"text": "34732887"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Convergent Charging Controller",
"text": "34732884"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications Applications (component: Common fns (Grafana)). Supported versions that are affected are 12.0.4-12.0.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Convergent Charging Controller executes to compromise Oracle Communications Convergent Charging Controller. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Convergent Charging Controller. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications Applications (component: Common fns (Grafana)). Supported versions that are affected are 12.0.4-12.0.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Network Charging and Control executes to compromise Oracle Communications Network Charging and Control. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Charging and Control. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Core (Grafana)). The supported version that is affected is 12.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Policy Management executes to compromise Oracle Communications Policy Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-12985V-12.0.4-12.0.6",
"P-4623V-12.0.4-12.0.6",
"P-10900V-12.6.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12985V-12.0.4-12.0.6",
"P-4623V-12.0.4-12.0.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936023.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10900V-12.6.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938443.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-12985V-12.0.4-12.0.6",
"P-4623V-12.0.4-12.0.6",
"P-10900V-12.6.0.0.0"
]
}
]
},
{
"cve": "CVE-2022-39271",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Order and Service Management",
"text": "34769791"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Order and Service Management product of Oracle Communications Applications (component: Security (Traefik)). The supported version that is affected is 7.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Order and Service Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Order and Service Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2270V-7.4.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2270V-7.4.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936012.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2270V-7.4.1"
]
}
]
},
{
"cve": "CVE-2022-40146",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Revenue Management and Billing",
"text": "34708551"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: Infrastructure (Apache Batik)). Supported versions that are affected are 2.7, 2.7.1, 2.8, 2.9, 2.9.1, 3.0, 3.1, 3.2 and 4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Revenue Management and Billing. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financial Services Revenue Management and Billing accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5322V-3.0",
"P-5322V-3.1",
"P-5322V-4.0",
"P-5322V-3.2",
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.9.1",
"P-5322V-2.7",
"P-5322V-2.7.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5322V-3.0",
"P-5322V-3.1",
"P-5322V-4.0",
"P-5322V-3.2",
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.9.1",
"P-5322V-2.7",
"P-5322V-2.7.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938972.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5322V-3.0",
"P-5322V-3.1",
"P-5322V-4.0",
"P-5322V-3.2",
"P-5322V-2.8",
"P-5322V-2.9",
"P-5322V-2.9.1",
"P-5322V-2.7",
"P-5322V-2.7.1"
]
}
]
},
{
"cve": "CVE-2022-40149",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Access Manager",
"text": "35117017"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Build Scripts (Jettison)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Access Manager. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5565V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5565V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-5565V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-40150",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Identity Manager",
"text": "35032549"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Third Party (Jettison)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Identity Manager. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1980V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1980V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-1980V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-40151",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "35001989"
},
{
"system_name": "Oracle Bug ID of Oracle Enterprise Manager Ops Center",
"text": "35001975"
},
{
"system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
"text": "35002009"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "34787388"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Policy Management",
"text": "35001991"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
"text": "34974063"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
"text": "35002006"
},
{
"system_name": "Oracle Bug ID of Oracle SOA Suite",
"text": "35002007"
},
{
"system_name": "Oracle Bug ID of Oracle WebCenter Portal",
"text": "34994444"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
"text": "35001993"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (XStream)). Supported versions that are affected are 22.4.0-22.4.4 and 23.1.0-23.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (XStream)). Supported versions that are affected are 22.4.0 and 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (XStream)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Enterprise Manager Ops Center product of Oracle Enterprise Manager (component: Networking (XStream)). The supported version that is affected is 12.4.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Ops Center. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Manager Ops Center. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Policy (XStream)). Supported versions that are affected are 22.4.0-22.4.4 and 23.1.0-23.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Core (XStream)). The supported version that is affected is 12.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Policy Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security Component (XStream)). Supported versions that are affected are 7.4.0, 7.4.1, 7.4.2 and 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (XStream)). Supported versions that are affected are 17.0.6, 18.0.5, 19.0.4, 20.0.3 and 21.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Security (XStream)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SOA Suite. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General (XStream)). Supported versions that are affected are 4.2.0.3.0, 4.3.0.1.0-4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0 and 4.5.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Application Framework. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-11513V-17.0.6",
"P-9835V-12.4.0.0",
"P-14121V-22.4.0-22.4.4",
"P-1675V-12.2.1.4.0",
"P-4516V-7.4.0",
"P-4516V-7.4.1",
"P-4516V-7.5.0",
"P-2245V-4.5.0.0.0",
"P-1696V-12.2.1.4.0",
"P-4516V-7.4.2",
"P-2245V-4.4.0.0.0",
"P-10900V-12.6.0.0.0",
"P-2245V-4.4.0.2.0",
"P-2245V-4.4.0.3.0",
"P-11513V-21.0.2",
"P-11513V-18.0.5",
"P-14121V-23.1.0-23.1.1",
"P-2245V-4.2.0.3.0",
"P-14250V-22.3.0",
"P-2245V-4.3.0.1.0-4.3.0.6.0",
"P-14250V-22.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14121V-22.4.0-22.4.4",
"P-14121V-23.1.0-23.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938417.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14250V-22.3.0",
"P-14250V-22.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938418.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1675V-12.2.1.4.0",
"P-1696V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9835V-12.4.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923367.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10900V-12.6.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938443.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4516V-7.4.0",
"P-4516V-7.4.1",
"P-4516V-7.5.0",
"P-4516V-7.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936066.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-11513V-17.0.6",
"P-11513V-21.0.2",
"P-11513V-18.0.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2245V-4.2.0.3.0",
"P-2245V-4.3.0.1.0-4.3.0.6.0",
"P-2245V-4.5.0.0.0",
"P-2245V-4.4.0.0.0",
"P-2245V-4.4.0.2.0",
"P-2245V-4.4.0.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936478.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-11513V-17.0.6",
"P-9835V-12.4.0.0",
"P-14121V-22.4.0-22.4.4",
"P-1675V-12.2.1.4.0",
"P-4516V-7.4.0",
"P-4516V-7.4.1",
"P-4516V-7.5.0",
"P-2245V-4.5.0.0.0",
"P-1696V-12.2.1.4.0",
"P-4516V-7.4.2",
"P-2245V-4.4.0.0.0",
"P-10900V-12.6.0.0.0",
"P-2245V-4.4.0.2.0",
"P-2245V-4.4.0.3.0",
"P-11513V-21.0.2",
"P-11513V-18.0.5",
"P-14121V-23.1.0-23.1.1",
"P-2245V-4.2.0.3.0",
"P-14250V-22.3.0",
"P-2245V-4.3.0.1.0-4.3.0.6.0",
"P-14250V-22.4.0"
]
}
]
},
{
"cve": "CVE-2022-40152",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
"text": "34970148"
},
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "34903357"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples (XStream)). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System (Apache CXF)). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5242V-12.2.1.4.0",
"P-9633V-11.3.2",
"P-5242V-14.1.1.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9633V-11.3.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939844.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9633V-11.3.2",
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-40303",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle HTTP Server",
"text": "34878767"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34878752"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "34878753"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment",
"text": "34878754"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (libxml2)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (libxml2)). Supported versions that are affected are 22.4.0-22.4.4, 23.1.0 and 23.1.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Binding Support Function executes to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (libxml2)). The supported version that is affected is 22.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Function Cloud Native Environment executes to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (libxml2)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1042V-12.2.1.4.0",
"P-14125V-22.4.0",
"P-14121V-23.1.1",
"P-14121V-22.4.0-22.4.4",
"P-14121V-23.1.0"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14121V-22.4.0-22.4.4",
"P-14121V-23.1.1",
"P-14121V-23.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938417.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14125V-22.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938434.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1042V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14125V-22.4.0",
"P-14121V-22.4.0-22.4.4",
"P-1042V-12.2.1.4.0",
"P-14121V-23.1.1",
"P-14121V-23.1.0"
]
}
]
},
{
"cve": "CVE-2022-40304",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle HTTP Server",
"text": "34878767"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34878752"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "34878753"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Function Cloud Native Environment",
"text": "34878754"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (libxml2)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Install/Upgrade (libxml2)). Supported versions that are affected are 22.4.0-22.4.4, 23.1.0 and 23.1.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Binding Support Function executes to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Function Cloud Native Environment product of Oracle Communications (component: Configuration (libxml2)). The supported version that is affected is 22.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Network Function Cloud Native Environment executes to compromise Oracle Communications Cloud Native Core Network Function Cloud Native Environment. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Function Cloud Native Environment. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (libxml2)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle HTTP Server executes to compromise Oracle HTTP Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1042V-12.2.1.4.0",
"P-14125V-22.4.0",
"P-14121V-23.1.1",
"P-14121V-22.4.0-22.4.4",
"P-14121V-23.1.0"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14121V-22.4.0-22.4.4",
"P-14121V-23.1.1",
"P-14121V-23.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938417.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14125V-22.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938434.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1042V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
},
{
"cvss_v3": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14125V-22.4.0",
"P-14121V-22.4.0-22.4.4",
"P-1042V-12.2.1.4.0",
"P-14121V-23.1.1",
"P-14121V-23.1.0"
]
}
]
},
{
"cve": "CVE-2022-41704",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
"text": "34970695"
},
{
"system_name": "Oracle Bug ID of Oracle SQL Developer",
"text": "34892735"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Digital Experience",
"text": "34970644"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
"text": "34970658"
},
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "34841025"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Batik)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle SQL Developer (component: General Infrastructure (Apache Batik)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: UI General (Apache Batik)). Supported versions that are affected are 18.2, 18.3, 19.1, 19.2, 21.1, 22.1 and 22.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Digital Experience. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Banking Digital Experience accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (Apache Batik)). Supported versions that are affected are 8.0.7.0, 8.0.8.0, 8.0.9.0, 8.1.0.0, 8.1.1.0, 8.1.2.0, 8.1.2.1 and 8.1.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Installer (Apache Batik)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Process Management Suite accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-5680V-8.0.7.0",
"P-5325V-12.2.1.4.0",
"P-12605V-18.3",
"P-12605V-19.2",
"P-12605V-18.2",
"P-12605V-19.1",
"P-12605V-22.2",
"P-4647V-12.2.1.4.0",
"P-12605V-21.1",
"P-12605V-22.1",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5680V-8.1.2.2"
],
"known_not_affected": [
"P-1875V-Prior to 23.1.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4647V-12.2.1.4.0",
"P-5325V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1875V-Prior to 23.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12605V-18.2",
"P-12605V-19.1",
"P-12605V-22.2",
"P-12605V-21.1",
"P-12605V-22.1",
"P-12605V-18.3",
"P-12605V-19.2"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-5680V-8.0.7.0",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5680V-8.1.2.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939767.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-5680V-8.0.7.0",
"P-5325V-12.2.1.4.0",
"P-12605V-18.3",
"P-12605V-19.2",
"P-12605V-18.2",
"P-12605V-19.1",
"P-12605V-22.2",
"P-4647V-12.2.1.4.0",
"P-12605V-21.1",
"P-12605V-22.1",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5680V-8.1.2.2"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-1875V-Prior to 23.1.0"
]
}
]
},
{
"cve": "CVE-2022-41715",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle TimesTen In-Memory Database",
"text": "34807532"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle TimesTen In-Memory Database (component: Oracle TimesTen In-Memory Database (Go)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-1870V-Prior to 22.1.1.7.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1870V-Prior to 22.1.1.7.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-1870V-Prior to 22.1.1.7.0"
]
}
]
},
{
"cve": "CVE-2022-41881",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Coherence",
"text": "35001711"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "35001717"
},
{
"system_name": "Oracle Bug ID of Oracle WebCenter Portal",
"text": "35001680"
},
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "35001749"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "35001708"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Digital Experience",
"text": "35001698"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (Netty)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: UI General (Netty)). Supported versions that are affected are 18.2, 18.3, 19.1, 19.2, 21.1, 22.1 and 22.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Digital Experience. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Digital Experience. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Netty)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core (Netty)). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Policy (Netty)). Supported versions that are affected are 22.4.0-22.4.4 and 23.1.0-23.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search (Netty)). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2545V-12.2.1.4.0",
"P-5085V-8.58",
"P-14121V-22.4.0-22.4.4",
"P-5085V-8.59",
"P-1696V-12.2.1.4.0",
"P-2545V-14.1.1.0.0",
"P-12605V-18.3",
"P-12605V-19.2",
"P-12605V-18.2",
"P-12605V-19.1",
"P-12605V-22.2",
"P-14121V-23.1.0-23.1.1",
"P-12605V-21.1",
"P-12605V-22.1",
"P-5085V-8.60"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2545V-12.2.1.4.0",
"P-1696V-12.2.1.4.0",
"P-2545V-14.1.1.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12605V-18.2",
"P-12605V-19.1",
"P-12605V-22.2",
"P-12605V-21.1",
"P-12605V-22.1",
"P-12605V-18.3",
"P-12605V-19.2"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14121V-22.4.0-22.4.4",
"P-14121V-23.1.0-23.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938417.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.58",
"P-5085V-8.59",
"P-5085V-8.60"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939793.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2545V-12.2.1.4.0",
"P-5085V-8.58",
"P-14121V-22.4.0-22.4.4",
"P-5085V-8.59",
"P-1696V-12.2.1.4.0",
"P-2545V-14.1.1.0.0",
"P-12605V-18.3",
"P-12605V-19.2",
"P-12605V-18.2",
"P-12605V-19.1",
"P-12605V-22.2",
"P-14121V-23.1.0-23.1.1",
"P-12605V-21.1",
"P-12605V-22.1",
"P-5085V-8.60"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-41915",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Coherence",
"text": "35001711"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "35001717"
},
{
"system_name": "Oracle Bug ID of Oracle WebCenter Portal",
"text": "35001680"
},
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "35001749"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "35001708"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Digital Experience",
"text": "35001698"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (Netty)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: UI General (Netty)). Supported versions that are affected are 18.2, 18.3, 19.1, 19.2, 21.1, 22.1 and 22.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Digital Experience. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Digital Experience. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Netty)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core (Netty)). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Policy (Netty)). Supported versions that are affected are 22.4.0-22.4.4 and 23.1.0-23.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search (Netty)). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2545V-12.2.1.4.0",
"P-5085V-8.58",
"P-14121V-22.4.0-22.4.4",
"P-5085V-8.59",
"P-1696V-12.2.1.4.0",
"P-2545V-14.1.1.0.0",
"P-12605V-18.3",
"P-12605V-19.2",
"P-12605V-18.2",
"P-12605V-19.1",
"P-12605V-22.2",
"P-14121V-23.1.0-23.1.1",
"P-12605V-21.1",
"P-12605V-22.1",
"P-5085V-8.60"
],
"known_not_affected": [
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2545V-12.2.1.4.0",
"P-1696V-12.2.1.4.0",
"P-2545V-14.1.1.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12605V-18.2",
"P-12605V-19.1",
"P-12605V-22.2",
"P-12605V-21.1",
"P-12605V-22.1",
"P-12605V-18.3",
"P-12605V-19.2"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13444V-Prior to 21.1.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14121V-22.4.0-22.4.4",
"P-14121V-23.1.0-23.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938417.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.58",
"P-5085V-8.59",
"P-5085V-8.60"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939793.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-2545V-12.2.1.4.0",
"P-5085V-8.58",
"P-14121V-22.4.0-22.4.4",
"P-5085V-8.59",
"P-1696V-12.2.1.4.0",
"P-2545V-14.1.1.0.0",
"P-12605V-18.3",
"P-12605V-19.2",
"P-12605V-18.2",
"P-12605V-19.1",
"P-12605V-22.2",
"P-14121V-23.1.0-23.1.1",
"P-12605V-21.1",
"P-12605V-22.1",
"P-5085V-8.60"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13444V-Prior to 21.1.3"
]
}
]
},
{
"cve": "CVE-2022-41966",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "35001989"
},
{
"system_name": "Oracle Bug ID of Oracle Enterprise Manager Ops Center",
"text": "35001975"
},
{
"system_name": "Oracle Bug ID of Oracle Utilities Application Framework",
"text": "35002009"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Policy Management",
"text": "35001991"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Console",
"text": "34974063"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
"text": "35002006"
},
{
"system_name": "Oracle Bug ID of Oracle SOA Suite",
"text": "35002007"
},
{
"system_name": "Oracle Bug ID of Oracle WebCenter Portal",
"text": "34994444"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Inventory Management",
"text": "35001993"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Console product of Oracle Communications (component: Configuration (XStream)). Supported versions that are affected are 22.4.0 and 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Console. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Console. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (XStream)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Enterprise Manager Ops Center product of Oracle Enterprise Manager (component: Networking (XStream)). The supported version that is affected is 12.4.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Ops Center. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Manager Ops Center. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Policy (XStream)). Supported versions that are affected are 22.4.0-22.4.4 and 23.1.0-23.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Binding Support Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Core (XStream)). The supported version that is affected is 12.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Policy Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Security Component (XStream)). Supported versions that are affected are 7.4.0, 7.4.1, 7.4.2 and 7.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (XStream)). Supported versions that are affected are 17.0.6, 18.0.5, 19.0.4, 20.0.3 and 21.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Security (XStream)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SOA Suite. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General (XStream)). Supported versions that are affected are 4.2.0.3.0, 4.3.0.1.0-4.3.0.6.0, 4.4.0.0.0, 4.4.0.2.0, 4.4.0.3.0 and 4.5.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Application Framework. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Application Framework. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-11513V-17.0.6",
"P-9835V-12.4.0.0",
"P-14121V-22.4.0-22.4.4",
"P-1675V-12.2.1.4.0",
"P-4516V-7.4.0",
"P-4516V-7.4.1",
"P-4516V-7.5.0",
"P-2245V-4.5.0.0.0",
"P-1696V-12.2.1.4.0",
"P-4516V-7.4.2",
"P-2245V-4.4.0.0.0",
"P-10900V-12.6.0.0.0",
"P-2245V-4.4.0.2.0",
"P-2245V-4.4.0.3.0",
"P-11513V-21.0.2",
"P-11513V-18.0.5",
"P-14121V-23.1.0-23.1.1",
"P-2245V-4.2.0.3.0",
"P-14250V-22.3.0",
"P-2245V-4.3.0.1.0-4.3.0.6.0",
"P-14250V-22.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14250V-22.3.0",
"P-14250V-22.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938418.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1675V-12.2.1.4.0",
"P-1696V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9835V-12.4.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923367.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14121V-22.4.0-22.4.4",
"P-14121V-23.1.0-23.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938417.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10900V-12.6.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938443.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4516V-7.4.0",
"P-4516V-7.4.1",
"P-4516V-7.5.0",
"P-4516V-7.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936066.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-11513V-17.0.6",
"P-11513V-21.0.2",
"P-11513V-18.0.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2245V-4.2.0.3.0",
"P-2245V-4.3.0.1.0-4.3.0.6.0",
"P-2245V-4.5.0.0.0",
"P-2245V-4.4.0.0.0",
"P-2245V-4.4.0.2.0",
"P-2245V-4.4.0.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936478.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-11513V-17.0.6",
"P-9835V-12.4.0.0",
"P-14121V-22.4.0-22.4.4",
"P-1675V-12.2.1.4.0",
"P-4516V-7.4.0",
"P-4516V-7.4.1",
"P-4516V-7.5.0",
"P-2245V-4.5.0.0.0",
"P-1696V-12.2.1.4.0",
"P-4516V-7.4.2",
"P-2245V-4.4.0.0.0",
"P-10900V-12.6.0.0.0",
"P-2245V-4.4.0.2.0",
"P-2245V-4.4.0.3.0",
"P-11513V-21.0.2",
"P-11513V-18.0.5",
"P-14121V-23.1.0-23.1.1",
"P-2245V-4.2.0.3.0",
"P-14250V-22.3.0",
"P-2245V-4.3.0.1.0-4.3.0.6.0",
"P-14250V-22.4.0"
]
}
]
},
{
"cve": "CVE-2022-42003",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle NoSQL Database",
"text": "34811682"
},
{
"system_name": "Oracle Bug ID of Oracle Documaker",
"text": "34811640"
},
{
"system_name": "Oracle Bug ID of Oracle SQL Developer",
"text": "34732911"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Merchandising System",
"text": "34811686"
},
{
"system_name": "Oracle Bug ID of Oracle Identity Manager",
"text": "34811588"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
"text": "34811621"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Digital Experience",
"text": "34811600"
},
{
"system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
"text": "34879277"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Enterprise Case Management",
"text": "34811656"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Element Manager",
"text": "34811635"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
"text": "34811636"
},
{
"system_name": "Oracle Bug ID of Oracle Coherence",
"text": "34914140"
},
{
"system_name": "Oracle Bug ID of Oracle Graph Server and Client",
"text": "34811670"
},
{
"system_name": "Oracle Bug ID of Oracle SD-WAN Edge",
"text": "34811692"
},
{
"system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
"text": "34811693"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Behavior Detection Platform",
"text": "34811652"
},
{
"system_name": "Oracle Bug ID of Oracle Healthcare Translational Research",
"text": "34811675"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Policy Management",
"text": "34811633"
},
{
"system_name": "Oracle Bug ID of Oracle Agile PLM",
"text": "34811590"
},
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34811591"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
"text": "34811691"
},
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "34690517"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "35042717"
},
{
"system_name": "Oracle Bug ID of Oracle GoldenGate",
"text": "34811668"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Sales Audit",
"text": "34811723"
},
{
"system_name": "Oracle Bug ID of Siebel CRM",
"text": "34811724"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
"text": "34811648"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Customer Management and Segmentation Foundation",
"text": "35126366"
},
{
"system_name": "Oracle Bug ID of Oracle WebCenter Portal",
"text": "34811728"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC (jackson-databind)). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle SQL Developer (component: Infrastructure (jackson-databind)). Supported versions that are affected are Prior to 23.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SQL Developer. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SQL Developer. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Installer (jackson-databind)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Identity Manager. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security (jackson-databind)). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (jackson-databind)). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: UI General (jackson-databind)). Supported versions that are affected are 18.2, 18.3, 19.1, 19.2, 21.1, 22.1 and 22.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Digital Experience. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Digital Experience. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install/Upgrade (jackson-databind)). The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Core (jackson-databind)). The supported version that is affected is 12.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Policy Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: BEServer (jackson-databind)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Element Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Element Manager. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: BEServer (jackson-databind)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Session Report Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Development Tools (jackson-databind)). Supported versions that are affected are 12.6.0.0.0, 12.6.2.0.0-12.6.4.0.0, 12.7.0.0.0 and 12.7.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Documaker. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (jackson-databind)). Supported versions that are affected are 8.0.7.0, 8.0.8.0, 8.0.9.0, 8.1.0.0, 8.1.1.0, 8.1.2.0, 8.1.2.1 and 8.1.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Application (jackson-databind)). Supported versions that are affected are 8.0.8.1, 8.1.1.1, 8.1.2.3 and 8.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Application (jackson-databind)). Supported versions that are affected are 8.1.2.4, 8.1.2.3, 8.1.1.1 and 8.0.8.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Enterprise Case Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Enterprise Case Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle GoldenGate (component: Oracle GoldenGate (jackson-databind)). Supported versions that are affected are Prior to 19.1.0.0.230418 and Prior to 21.10.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle Graph Server and Client (component: Packaging (jackson-databind)). Supported versions that are affected are Prior to 23.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Graph Server and Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Graph Server and Client. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Translational Research product of Oracle HealthCare Applications (component: User Interface (jackson-databind)). Supported versions that are affected are 4.1.0 and 4.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Translational Research. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Healthcare Translational Research. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle NoSQL Database (component: Administration (jackson-databind)). Supported versions that are affected are Prior to 19.5.32. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle NoSQL Database. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle NoSQL Database. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Merchandising System product of Oracle Retail Applications (component: Foundation (jackson-databind)). The supported version that is affected is 15.0.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Merchandising System. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Merchandising System. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (jackson-databind)). Supported versions that are affected are 17.0.6, 18.0.5, 19.0.4, 20.0.3 and 21.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Internal tools (jackson-databind)). The supported version that is affected is 9.1.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle SD-WAN Edge. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Edge. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Installer (jackson-databind)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Process Management Suite. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Sales Audit product of Oracle Retail Applications (component: others (jackson-databind)). The supported version that is affected is 15.0.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Sales Audit. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Sales Audit. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: EAI (jackson-databind)). Supported versions that are affected are 23.2 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (jackson-databind)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System, Workbench (jackson-databind)). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core (jackson-databind)). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Kafka)). Supported versions that are affected are 5.5.0-5.5.10 and 6.0.0-6.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Internal Operations (jackson-databind)). Supported versions that are affected are 18.0.0.12 and 19.0.0.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Customer Management and Segmentation Foundation. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11513V-20.0.3",
"P-5680V-8.0.8.0",
"P-13545V-8.1.1.1",
"P-1875V-Prior to 23.1.0",
"P-5325V-12.2.1.4.0",
"P-2545V-14.1.1.0.0",
"P-10900V-12.6.0.0.0",
"P-13940V-9.1.1.4.0",
"P-12605V-19.1",
"P-14069V-Prior to 23.1.0",
"P-5477V-12.7.0.0.0",
"P-9190V-8.0.8.1",
"P-14597V-5.5.0-5.5.10",
"P-4781V-Prior to 9.2.7.3",
"P-9190V-8.1.1.1",
"P-9190V-8.1.2.3",
"P-9190V-8.1.2.4",
"P-9011V-23.2 and prior",
"P-12605V-18.3",
"P-5477V-12.6.0.0.0",
"P-11513V-21.0.2",
"P-14117V-22.3.0",
"P-9633V-11.3.2",
"P-10770V-9.0.1",
"P-10770V-9.0.0",
"P-12605V-21.1",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5477V-12.6.2.0.0-12.6.4.0.0",
"P-5680V-8.1.2.2",
"P-5680V-8.0.9.0",
"P-11513V-17.0.6",
"P-5680V-8.0.7.0",
"P-2025V-6.4.0.0.0",
"P-1696V-12.2.1.4.0",
"P-13545V-8.1.2.4",
"P-5757V-Prior to 19.1.0.0.230418",
"P-13545V-8.1.2.3",
"P-12605V-18.2",
"P-11513V-18.0.5",
"P-1980V-12.2.1.4.0",
"P-13545V-8.0.8.2",
"P-4461V-9.3.6",
"P-14597V-6.0.0-6.0.2",
"P-1816V-15.0.3.1",
"P-5477V-12.7.1.0.0",
"P-11513V-19.0.4",
"P-2545V-12.2.1.4.0",
"P-1834V-15.0.3.1",
"P-12605V-19.2",
"P-5757V-Prior to 21.10.0.0.0",
"P-9427V-4.1.0",
"P-13388V-19.0.0.6",
"P-9427V-4.1.1",
"P-11052V-9.0.1",
"P-11052V-9.0.0",
"P-12605V-22.2",
"P-13373V-Prior to 19.5.32",
"P-12605V-22.1",
"P-5680V-8.1.1.0",
"P-13388V-18.0.0.12"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14069V-Prior to 23.1.0",
"P-13373V-Prior to 19.5.32",
"P-1875V-Prior to 23.1.0",
"P-5757V-Prior to 19.1.0.0.230418",
"P-5757V-Prior to 21.10.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1980V-12.2.1.4.0",
"P-2545V-12.2.1.4.0",
"P-5325V-12.2.1.4.0",
"P-1696V-12.2.1.4.0",
"P-2545V-14.1.1.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4461V-9.3.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939856.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12605V-18.2",
"P-12605V-19.1",
"P-12605V-22.2",
"P-12605V-21.1",
"P-12605V-22.1",
"P-12605V-18.3",
"P-12605V-19.2"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14117V-22.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2942394.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10900V-12.6.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938443.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11052V-9.0.1",
"P-11052V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938441.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10770V-9.0.1",
"P-10770V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938447.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-5477V-12.7.0.0.0",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-5680V-8.0.7.0",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5680V-8.1.2.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939767.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9190V-8.1.2.3",
"P-9190V-8.1.2.4",
"P-9190V-8.0.8.1",
"P-9190V-8.1.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936356.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13545V-8.0.8.2",
"P-13545V-8.1.1.1",
"P-13545V-8.1.2.4",
"P-13545V-8.1.2.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936337.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939153.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-13388V-19.0.0.6",
"P-11513V-17.0.6",
"P-11513V-21.0.2",
"P-11513V-18.0.5",
"P-1834V-15.0.3.1",
"P-1816V-15.0.3.1",
"P-13388V-18.0.0.12"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13940V-9.1.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938444.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9011V-23.2 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939854.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9633V-11.3.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939844.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-11513V-20.0.3",
"P-5680V-8.0.8.0",
"P-13545V-8.1.1.1",
"P-5325V-12.2.1.4.0",
"P-2545V-14.1.1.0.0",
"P-10900V-12.6.0.0.0",
"P-13940V-9.1.1.4.0",
"P-12605V-19.1",
"P-5477V-12.7.0.0.0",
"P-9190V-8.0.8.1",
"P-14597V-5.5.0-5.5.10",
"P-4781V-Prior to 9.2.7.3",
"P-9190V-8.1.1.1",
"P-9190V-8.1.2.3",
"P-9190V-8.1.2.4",
"P-9011V-23.2 and prior",
"P-12605V-18.3",
"P-5477V-12.6.0.0.0",
"P-11513V-21.0.2",
"P-14117V-22.3.0",
"P-9633V-11.3.2",
"P-10770V-9.0.1",
"P-10770V-9.0.0",
"P-12605V-21.1",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5477V-12.6.2.0.0-12.6.4.0.0",
"P-5680V-8.1.2.2",
"P-5680V-8.0.9.0",
"P-11513V-17.0.6",
"P-5680V-8.0.7.0",
"P-2025V-6.4.0.0.0",
"P-1696V-12.2.1.4.0",
"P-13545V-8.1.2.4",
"P-13545V-8.1.2.3",
"P-12605V-18.2",
"P-11513V-18.0.5",
"P-1980V-12.2.1.4.0",
"P-13545V-8.0.8.2",
"P-4461V-9.3.6",
"P-14597V-6.0.0-6.0.2",
"P-1816V-15.0.3.1",
"P-5477V-12.7.1.0.0",
"P-11513V-19.0.4",
"P-2545V-12.2.1.4.0",
"P-1834V-15.0.3.1",
"P-12605V-19.2",
"P-9427V-4.1.0",
"P-13388V-19.0.0.6",
"P-9427V-4.1.1",
"P-11052V-9.0.1",
"P-11052V-9.0.0",
"P-12605V-22.2",
"P-12605V-22.1",
"P-5680V-8.1.1.0",
"P-13388V-18.0.0.12"
]
},
{
"cvss_v3": {
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-1875V-Prior to 23.1.0"
]
},
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14069V-Prior to 23.1.0",
"P-13373V-Prior to 19.5.32",
"P-5757V-Prior to 19.1.0.0.230418",
"P-5757V-Prior to 21.10.0.0.0"
]
}
]
},
{
"cve": "CVE-2022-42004",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle NoSQL Database",
"text": "34811682"
},
{
"system_name": "Oracle Bug ID of Oracle Documaker",
"text": "34811640"
},
{
"system_name": "Oracle Bug ID of Oracle SQL Developer",
"text": "34732911"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Merchandising System",
"text": "34811686"
},
{
"system_name": "Oracle Bug ID of Oracle Identity Manager",
"text": "34811588"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Service Communication Proxy",
"text": "34811621"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Digital Experience",
"text": "34811600"
},
{
"system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
"text": "34879277"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Enterprise Case Management",
"text": "34811656"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Element Manager",
"text": "34811635"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
"text": "34811636"
},
{
"system_name": "Oracle Bug ID of Oracle Graph Server and Client",
"text": "34811670"
},
{
"system_name": "Oracle Bug ID of Oracle SD-WAN Edge",
"text": "34811692"
},
{
"system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
"text": "34811693"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Behavior Detection Platform",
"text": "34811652"
},
{
"system_name": "Oracle Bug ID of Oracle Healthcare Translational Research",
"text": "34811675"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Policy Management",
"text": "34811633"
},
{
"system_name": "Oracle Bug ID of Oracle Agile PLM",
"text": "34811590"
},
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34811591"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
"text": "34811691"
},
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "34690517"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "35042717"
},
{
"system_name": "Oracle Bug ID of Oracle GoldenGate",
"text": "34811668"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Sales Audit",
"text": "34811723"
},
{
"system_name": "Oracle Bug ID of Siebel CRM",
"text": "34811724"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
"text": "34811648"
},
{
"system_name": "Oracle Bug ID of Oracle WebCenter Portal",
"text": "34811728"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC (jackson-databind)). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle SQL Developer (component: Infrastructure (jackson-databind)). Supported versions that are affected are Prior to 23.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SQL Developer. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SQL Developer. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Installer (jackson-databind)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Identity Manager. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security (jackson-databind)). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server (jackson-databind)). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: UI General (jackson-databind)). Supported versions that are affected are 18.2, 18.3, 19.1, 19.2, 21.1, 22.1 and 22.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Digital Experience. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Digital Experience. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Service Communication Proxy product of Oracle Communications (component: Install/Upgrade (jackson-databind)). The supported version that is affected is 22.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Service Communication Proxy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Service Communication Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Core (jackson-databind)). The supported version that is affected is 12.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Policy Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: BEServer (jackson-databind)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Element Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Element Manager. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: BEServer (jackson-databind)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Session Report Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Development Tools (jackson-databind)). Supported versions that are affected are 12.6.0.0.0, 12.6.2.0.0-12.6.4.0.0, 12.7.0.0.0 and 12.7.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Documaker. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (jackson-databind)). Supported versions that are affected are 8.0.7.0, 8.0.8.0, 8.0.9.0, 8.1.0.0, 8.1.1.0, 8.1.2.0, 8.1.2.1 and 8.1.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Application (jackson-databind)). Supported versions that are affected are 8.0.8.1, 8.1.1.1, 8.1.2.3 and 8.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Application (jackson-databind)). Supported versions that are affected are 8.1.2.4, 8.1.2.3, 8.1.1.1 and 8.0.8.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Enterprise Case Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Enterprise Case Management. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle GoldenGate (component: Oracle GoldenGate (jackson-databind)). Supported versions that are affected are Prior to 19.1.0.0.230418 and Prior to 21.10.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle Graph Server and Client (component: Packaging (jackson-databind)). Supported versions that are affected are Prior to 23.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Graph Server and Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Graph Server and Client. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Translational Research product of Oracle HealthCare Applications (component: User Interface (jackson-databind)). Supported versions that are affected are 4.1.0 and 4.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Translational Research. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Healthcare Translational Research. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle NoSQL Database (component: Administration (jackson-databind)). Supported versions that are affected are Prior to 19.5.32. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle NoSQL Database. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle NoSQL Database. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Merchandising System product of Oracle Retail Applications (component: Foundation (jackson-databind)). The supported version that is affected is 15.0.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Merchandising System. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Merchandising System. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (jackson-databind)). Supported versions that are affected are 17.0.6, 18.0.5, 19.0.4, 20.0.3 and 21.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Internal tools (jackson-databind)). The supported version that is affected is 9.1.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle SD-WAN Edge. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle SD-WAN Edge. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Installer (jackson-databind)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Process Management Suite. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Sales Audit product of Oracle Retail Applications (component: others (jackson-databind)). The supported version that is affected is 15.0.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Sales Audit. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Sales Audit. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: EAI (jackson-databind)). Supported versions that are affected are 23.2 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (jackson-databind)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System, Workbench (jackson-databind)). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (Apache Kafka)). Supported versions that are affected are 5.5.0-5.5.10 and 6.0.0-6.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11513V-20.0.3",
"P-5680V-8.0.8.0",
"P-13545V-8.1.1.1",
"P-1875V-Prior to 23.1.0",
"P-5325V-12.2.1.4.0",
"P-10900V-12.6.0.0.0",
"P-13940V-9.1.1.4.0",
"P-12605V-19.1",
"P-14069V-Prior to 23.1.0",
"P-5477V-12.7.0.0.0",
"P-9190V-8.0.8.1",
"P-14597V-5.5.0-5.5.10",
"P-4781V-Prior to 9.2.7.3",
"P-9190V-8.1.1.1",
"P-9190V-8.1.2.3",
"P-9190V-8.1.2.4",
"P-9011V-23.2 and prior",
"P-12605V-18.3",
"P-5477V-12.6.0.0.0",
"P-11513V-21.0.2",
"P-14117V-22.3.0",
"P-9633V-11.3.2",
"P-10770V-9.0.1",
"P-10770V-9.0.0",
"P-12605V-21.1",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5477V-12.6.2.0.0-12.6.4.0.0",
"P-5680V-8.1.2.2",
"P-5680V-8.0.9.0",
"P-11513V-17.0.6",
"P-5680V-8.0.7.0",
"P-2025V-6.4.0.0.0",
"P-1696V-12.2.1.4.0",
"P-13545V-8.1.2.4",
"P-5757V-Prior to 19.1.0.0.230418",
"P-13545V-8.1.2.3",
"P-12605V-18.2",
"P-11513V-18.0.5",
"P-1980V-12.2.1.4.0",
"P-13545V-8.0.8.2",
"P-4461V-9.3.6",
"P-14597V-6.0.0-6.0.2",
"P-1816V-15.0.3.1",
"P-5477V-12.7.1.0.0",
"P-11513V-19.0.4",
"P-1834V-15.0.3.1",
"P-12605V-19.2",
"P-5757V-Prior to 21.10.0.0.0",
"P-9427V-4.1.0",
"P-9427V-4.1.1",
"P-11052V-9.0.1",
"P-11052V-9.0.0",
"P-12605V-22.2",
"P-13373V-Prior to 19.5.32",
"P-12605V-22.1",
"P-5680V-8.1.1.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14069V-Prior to 23.1.0",
"P-13373V-Prior to 19.5.32",
"P-1875V-Prior to 23.1.0",
"P-5757V-Prior to 19.1.0.0.230418",
"P-5757V-Prior to 21.10.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1980V-12.2.1.4.0",
"P-5325V-12.2.1.4.0",
"P-1696V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4461V-9.3.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939856.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12605V-18.2",
"P-12605V-19.1",
"P-12605V-22.2",
"P-12605V-21.1",
"P-12605V-22.1",
"P-12605V-18.3",
"P-12605V-19.2"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14117V-22.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2942394.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10900V-12.6.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938443.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11052V-9.0.1",
"P-11052V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938441.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10770V-9.0.1",
"P-10770V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938447.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-5477V-12.7.0.0.0",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-5680V-8.0.7.0",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5680V-8.1.2.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939767.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9190V-8.1.2.3",
"P-9190V-8.1.2.4",
"P-9190V-8.0.8.1",
"P-9190V-8.1.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936356.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13545V-8.0.8.2",
"P-13545V-8.1.1.1",
"P-13545V-8.1.2.4",
"P-13545V-8.1.2.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936337.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939153.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11513V-20.0.3",
"P-11513V-19.0.4",
"P-11513V-17.0.6",
"P-11513V-21.0.2",
"P-11513V-18.0.5",
"P-1834V-15.0.3.1",
"P-1816V-15.0.3.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13940V-9.1.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938444.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9011V-23.2 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939854.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9633V-11.3.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939844.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-11513V-20.0.3",
"P-5680V-8.0.8.0",
"P-13545V-8.1.1.1",
"P-5325V-12.2.1.4.0",
"P-10900V-12.6.0.0.0",
"P-13940V-9.1.1.4.0",
"P-12605V-19.1",
"P-5477V-12.7.0.0.0",
"P-9190V-8.0.8.1",
"P-14597V-5.5.0-5.5.10",
"P-4781V-Prior to 9.2.7.3",
"P-9190V-8.1.1.1",
"P-9190V-8.1.2.3",
"P-9190V-8.1.2.4",
"P-9011V-23.2 and prior",
"P-12605V-18.3",
"P-5477V-12.6.0.0.0",
"P-11513V-21.0.2",
"P-14117V-22.3.0",
"P-9633V-11.3.2",
"P-10770V-9.0.1",
"P-10770V-9.0.0",
"P-12605V-21.1",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5477V-12.6.2.0.0-12.6.4.0.0",
"P-5680V-8.1.2.2",
"P-5680V-8.0.9.0",
"P-11513V-17.0.6",
"P-5680V-8.0.7.0",
"P-2025V-6.4.0.0.0",
"P-1696V-12.2.1.4.0",
"P-13545V-8.1.2.4",
"P-13545V-8.1.2.3",
"P-12605V-18.2",
"P-11513V-18.0.5",
"P-1980V-12.2.1.4.0",
"P-13545V-8.0.8.2",
"P-4461V-9.3.6",
"P-14597V-6.0.0-6.0.2",
"P-1816V-15.0.3.1",
"P-5477V-12.7.1.0.0",
"P-11513V-19.0.4",
"P-1834V-15.0.3.1",
"P-12605V-19.2",
"P-9427V-4.1.0",
"P-9427V-4.1.1",
"P-11052V-9.0.1",
"P-11052V-9.0.0",
"P-12605V-22.2",
"P-12605V-22.1",
"P-5680V-8.1.1.0"
]
},
{
"cvss_v3": {
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-1875V-Prior to 23.1.0"
]
},
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14069V-Prior to 23.1.0",
"P-13373V-Prior to 19.5.32",
"P-5757V-Prior to 19.1.0.0.230418",
"P-5757V-Prior to 21.10.0.0.0"
]
}
]
},
{
"cve": "CVE-2022-42252",
"ids": [
{
"system_name": "Oracle Bug ID of Siebel CRM",
"text": "34859012"
},
{
"system_name": "Oracle Bug ID of Management Cloud Engine",
"text": "34858979"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Model Management and Governance",
"text": "35231463"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Management Cloud Engine product of Oracle Communications (component: BEServer (Apache Tomcat)). The supported version that is affected is 22.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Management Cloud Engine. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Management Cloud Engine accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: Services (Apache Tomcat)). Supported versions that are affected are 23.2 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel CRM accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Model Management and Governance product of Oracle Financial Services Applications (component: Application (Apache Tomcat)). Supported versions that are affected are 8.1.0.0 and 8.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Model Management and Governance. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Model Management and Governance accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9001V-23.2 and prior",
"P-14276V-8.1.2.0",
"P-14252V-22.1.0.0.0",
"P-14276V-8.1.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14252V-22.1.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2942213.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9001V-23.2 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939854.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14276V-8.1.0.0",
"P-14276V-8.1.2.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939794.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-9001V-23.2 and prior",
"P-14252V-22.1.0.0.0",
"P-14276V-8.1.0.0",
"P-14276V-8.1.2.0"
]
}
]
},
{
"cve": "CVE-2022-42889",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Graph Server and Client",
"text": "34778248"
},
{
"system_name": "Oracle Bug ID of Oracle Blockchain Platform",
"text": "34705837"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
"text": "34705866"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Xstore Point of Service",
"text": "34821432"
},
{
"system_name": "Oracle Bug ID of Oracle Healthcare Master Person Index",
"text": "34705854"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Xstore Office Cloud Service",
"text": "34705865"
},
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34713985"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Merchandising System",
"text": "34736365"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
"text": "35232356"
},
{
"system_name": "Oracle Bug ID of Oracle Healthcare Foundation",
"text": "34705853"
},
{
"system_name": "Oracle Bug ID of Oracle SQL Developer",
"text": "34732037"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Blockchain Platform (component: BCS Console (Apache Commons Text)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Foundation product of Oracle HealthCare Applications (component: Self Service Analytics (Apache Commons Text)). Supported versions that are affected are 8.1.0, 8.1.1, 8.2.0, 8.2.1 and 8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Foundation. Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Foundation. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Master Person Index product of Oracle HealthCare Applications (component: Self Service Analytics (Apache Commons Text)). Supported versions that are affected are 5.0.0-5.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Master Person Index. Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Master Person Index. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Xstore Office Cloud Service product of Oracle Retail Applications (component: DB, Perf, etc (Apache Commons Text)). Supported versions that are affected are 18.0.5, 19.0.4, 20.0.3 and 21.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office Cloud Service. Successful attacks of this vulnerability can result in takeover of Oracle Retail Xstore Office Cloud Service. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (Apache Commons Text)). Supported versions that are affected are 18.0.5, 19.0.4, 20.0.3 and 21.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in takeover of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Application Archive (Apache Commons Text)). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle SQL Developer (component: Installation (Apache Commons Text)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Merchandising System product of Oracle Retail Applications (component: Security (Apache Commons Text)). Supported versions that are affected are 16.0.2 and 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Merchandising System. Successful attacks of this vulnerability can result in takeover of Oracle Retail Merchandising System. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Graph Server and Client (component: PGX Java Client (Apache Commons Text)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Point of Sale (Apache Commons Text)). Supported versions that are affected are 18.0.5, 19.0.4, 20.0.3 and 21.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service. Successful attacks of this vulnerability can result in takeover of Oracle Retail Xstore Point of Service. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Application (Apache Commons Text)). The supported version that is affected is 8.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Compliance Studio. Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Compliance Studio. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11513(Point of Sale)V-18.0.5",
"P-11513(Xenvironment)V-18.0.5",
"P-11513(Xenvironment)V-19.0.4",
"P-13551V-21.0.2",
"P-2025V-6.4.0.0.0",
"P-1816V-16.0.3",
"P-13551V-18.0.5",
"P-8575V-5.0.0-5.0.4",
"P-1816V-16.0.2",
"P-11513(Xenvironment)V-21.0.2",
"P-11513(Point of Sale)V-20.0.3",
"P-11513(Point of Sale)V-19.0.4",
"P-14392V-8.1.2.4",
"P-13551V-20.0.3",
"P-11513(Xenvironment)V-20.0.3",
"P-13551V-19.0.4",
"P-12950V-8.1.1",
"P-12950V-8.2.0",
"P-11513(Point of Sale)V-21.0.2",
"P-12950V-8.1.0",
"P-12950V-8.2.2",
"P-12950V-8.2.1"
],
"known_not_affected": [
"P-1875V-Prior to 22.4.0",
"P-14069V-Prior to 23.1.0",
"P-13444V-Prior to 21.1.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14069V-Prior to 23.1.0",
"P-13444V-Prior to 21.1.3",
"P-1875V-Prior to 22.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12950V-8.1.1",
"P-12950V-8.2.0",
"P-12950V-8.1.0",
"P-8575V-5.0.0-5.0.4",
"P-12950V-8.2.2",
"P-12950V-8.2.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939153.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11513(Point of Sale)V-18.0.5",
"P-11513(Xenvironment)V-18.0.5",
"P-11513(Xenvironment)V-19.0.4",
"P-13551V-21.0.2",
"P-1816V-16.0.3",
"P-13551V-18.0.5",
"P-1816V-16.0.2",
"P-11513(Xenvironment)V-21.0.2",
"P-11513(Point of Sale)V-20.0.3",
"P-11513(Point of Sale)V-19.0.4",
"P-13551V-20.0.3",
"P-11513(Xenvironment)V-20.0.3",
"P-13551V-19.0.4",
"P-11513(Point of Sale)V-21.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14392V-8.1.2.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936394.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-14069V-Prior to 23.1.0",
"P-13444V-Prior to 21.1.3",
"P-1875V-Prior to 22.4.0"
]
},
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-11513(Point of Sale)V-18.0.5",
"P-11513(Xenvironment)V-18.0.5",
"P-11513(Xenvironment)V-19.0.4",
"P-13551V-21.0.2",
"P-2025V-6.4.0.0.0",
"P-1816V-16.0.3",
"P-13551V-18.0.5",
"P-8575V-5.0.0-5.0.4",
"P-1816V-16.0.2",
"P-11513(Xenvironment)V-21.0.2",
"P-11513(Point of Sale)V-20.0.3",
"P-11513(Point of Sale)V-19.0.4",
"P-14392V-8.1.2.4",
"P-13551V-20.0.3",
"P-11513(Xenvironment)V-20.0.3",
"P-13551V-19.0.4",
"P-12950V-8.1.1",
"P-12950V-8.2.0",
"P-11513(Point of Sale)V-21.0.2",
"P-12950V-8.1.0",
"P-12950V-8.2.2",
"P-12950V-8.2.1"
]
}
]
},
{
"cve": "CVE-2022-42890",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
"text": "34970695"
},
{
"system_name": "Oracle Bug ID of Oracle SQL Developer",
"text": "34892735"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Digital Experience",
"text": "34970644"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
"text": "34970658"
},
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "34841025"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Batik)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Middleware Common Libraries and Tools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle SQL Developer (component: General Infrastructure (Apache Batik)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: UI General (Apache Batik)). Supported versions that are affected are 18.2, 18.3, 19.1, 19.2, 21.1, 22.1 and 22.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Digital Experience. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Banking Digital Experience accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (Apache Batik)). Supported versions that are affected are 8.0.7.0, 8.0.8.0, 8.0.9.0, 8.1.0.0, 8.1.1.0, 8.1.2.0, 8.1.2.1 and 8.1.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Installer (Apache Batik)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Process Management Suite accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-5680V-8.0.7.0",
"P-5325V-12.2.1.4.0",
"P-12605V-18.3",
"P-12605V-19.2",
"P-12605V-18.2",
"P-12605V-19.1",
"P-12605V-22.2",
"P-4647V-12.2.1.4.0",
"P-12605V-21.1",
"P-12605V-22.1",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5680V-8.1.2.2"
],
"known_not_affected": [
"P-1875V-Prior to 23.1.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4647V-12.2.1.4.0",
"P-5325V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1875V-Prior to 23.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12605V-18.2",
"P-12605V-19.1",
"P-12605V-22.2",
"P-12605V-21.1",
"P-12605V-22.1",
"P-12605V-18.3",
"P-12605V-19.2"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-5680V-8.0.7.0",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5680V-8.1.2.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939767.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-5680V-8.0.7.0",
"P-5325V-12.2.1.4.0",
"P-12605V-18.3",
"P-12605V-19.2",
"P-12605V-18.2",
"P-12605V-19.1",
"P-12605V-22.2",
"P-4647V-12.2.1.4.0",
"P-12605V-21.1",
"P-12605V-22.1",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5680V-8.1.2.2"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-1875V-Prior to 23.1.0"
]
}
]
},
{
"cve": "CVE-2022-42898",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Healthcare Translational Research",
"text": "35166345"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
"text": "35001943"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Installation and Configuration (Kerberos)). Supported versions that are affected are 23.1.0 and 22.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via Kerberos to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Translational Research product of Oracle HealthCare Applications (component: DataStudio (Kerberos)). Supported versions that are affected are 4.1.0 and 4.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Healthcare Translational Research. Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Translational Research. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9427V-4.1.0",
"P-14123V-23.1.0",
"P-9427V-4.1.1",
"P-14123V-22.4.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14123V-23.1.0",
"P-14123V-22.4.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938437.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939153.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-9427V-4.1.0",
"P-14123V-23.1.0",
"P-9427V-4.1.1",
"P-14123V-22.4.1"
]
}
]
},
{
"cve": "CVE-2022-42915",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle HTTP Server",
"text": "34765107"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (cURL)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1042V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1042V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-1042V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-42916",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle VM VirtualBox",
"text": "35032869"
},
{
"system_name": "Oracle Bug ID of Oracle HTTP Server",
"text": "34765107"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (cURL)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core (cURL)). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8370V-Prior to 7.0.8",
"P-1042V-12.2.1.4.0",
"P-8370V-Prior to 6.1.44"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1042V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940494.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44",
"P-1042V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2022-42919",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "34997341"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Database OML4PY (Python) component of Oracle Database Server. The supported version that is affected is 21c. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via HTTP to compromise Oracle Database OML4PY (Python). Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Database OML4PY (Python). CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5(Oracle Database OML4PY)V-21c"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Oracle Database OML4PY)V-21c"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-5(Oracle Database OML4PY)V-21c"
]
}
]
},
{
"cve": "CVE-2022-4304",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "35121425"
},
{
"system_name": "Oracle Bug ID of MySQL Connectors",
"text": "35136522"
},
{
"system_name": "Oracle Bug ID of MySQL Workbench",
"text": "35136526"
},
{
"system_name": "Oracle Bug ID of MySQL Enterprise Monitor",
"text": "35136525"
},
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "35136513"
},
{
"system_name": "Oracle Bug ID of MySQL Connectors",
"text": "35136523"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Essbase (component: Build (OpenSSL)). The supported version that is affected is 21.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Essbase. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Essbase. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging (OpenSSL)). Supported versions that are affected are 5.7.41 and prior and 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC (OpenSSL)). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++ (OpenSSL)). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (OpenSSL)). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Enterprise Monitor. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: Workbench (OpenSSL)). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4379V-21.4",
"P-8478V-8.0.32 and prior",
"P-8478V-5.7.41 and prior",
"P-8576V-8.0.32 and prior",
"P-4627V-8.0.32 and prior",
"P-8480V-8.0.33 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4379V-21.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8576V-8.0.32 and prior",
"P-8478V-8.0.32 and prior",
"P-8478V-5.7.41 and prior",
"P-4627V-8.0.32 and prior",
"P-8480V-8.0.33 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-4379V-21.4"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8576V-8.0.32 and prior",
"P-8478V-8.0.32 and prior",
"P-8478V-5.7.41 and prior",
"P-4627V-8.0.32 and prior",
"P-8480V-8.0.33 and prior"
]
}
]
},
{
"cve": "CVE-2022-43401",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Automated Test Suite",
"text": "34982761"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Installation (Jenkins Script Security)). Supported versions that are affected are 22.3.1 and 22.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite. While the vulnerability is in Oracle Communications Cloud Native Core Automated Test Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14488V-22.3.1",
"P-14488V-22.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14488V-22.3.1",
"P-14488V-22.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938415.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14488V-22.3.1",
"P-14488V-22.4.0"
]
}
]
},
{
"cve": "CVE-2022-43402",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Automated Test Suite",
"text": "34982770"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Installation (Jenkins)). Supported versions that are affected are 22.3.1 and 22.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite. While the vulnerability is in Oracle Communications Cloud Native Core Automated Test Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14488V-22.3.1",
"P-14488V-22.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14488V-22.3.1",
"P-14488V-22.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938415.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.9,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14488V-22.3.1",
"P-14488V-22.4.0"
]
}
]
},
{
"cve": "CVE-2022-43548",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Cluster",
"text": "35095122"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: JS module (Node.js)). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8479V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8479V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-8479V-8.0.32 and prior"
]
}
]
},
{
"cve": "CVE-2022-43551",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle VM VirtualBox",
"text": "35032869"
},
{
"system_name": "Oracle Bug ID of Oracle HTTP Server",
"text": "34765107"
},
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "35095010"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (cURL)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core (cURL)). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging (cURL)). Supported versions that are affected are 5.7.41 and prior and 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8370V-Prior to 7.0.8",
"P-1042V-12.2.1.4.0",
"P-8478V-8.0.32 and prior",
"P-8370V-Prior to 6.1.44",
"P-8478V-5.7.41 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1042V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940494.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior",
"P-8478V-5.7.41 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44",
"P-1042V-12.2.1.4.0",
"P-8478V-8.0.32 and prior",
"P-8478V-5.7.41 and prior"
]
}
]
},
{
"cve": "CVE-2022-43680",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Behavior Detection Platform",
"text": "34747803"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition",
"text": "34747805"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Currency Transaction Reporting",
"text": "34747794"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Currency Transaction Reporting product of Oracle Financial Services Applications (component: Application (LibExpat)). Supported versions that are affected are 8.0.8.1.0, 8.1.1.1.0, 8.1.2.3.0 and 8.1.2.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Currency Transaction Reporting. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Currency Transaction Reporting. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Third Party (LibExpat)). Supported versions that are affected are 8.0.8.1, 8.1.1.1, 8.1.2.3 and 8.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition product of Oracle Financial Services Applications (component: Application (LibExpat)). The supported version that is affected is 8.0.8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9190V-8.1.2.3",
"P-9784V-8.1.2.4.1",
"P-9784V-8.0.8.1.0",
"P-9784V-8.1.2.3.0",
"P-9190V-8.1.2.4",
"P-9190V-8.0.8.1",
"P-9784V-8.1.1.1.0",
"P-13789V-8.0.8.0.0",
"P-9190V-8.1.1.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9190V-8.1.2.3",
"P-9784V-8.1.2.4.1",
"P-9784V-8.0.8.1.0",
"P-9784V-8.1.2.3.0",
"P-9190V-8.1.2.4",
"P-9190V-8.0.8.1",
"P-9784V-8.1.1.1.0",
"P-9190V-8.1.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936356.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13789V-8.0.8.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936336.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-9190V-8.1.2.3",
"P-9784V-8.1.2.4.1",
"P-9784V-8.0.8.1.0",
"P-9784V-8.1.2.3.0",
"P-9190V-8.1.2.4",
"P-9190V-8.0.8.1",
"P-9784V-8.1.1.1.0",
"P-13789V-8.0.8.0.0",
"P-9190V-8.1.1.1"
]
}
]
},
{
"cve": "CVE-2022-4415",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "35196440"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (systemd)). Supported versions that are affected are 22.4.0-22.4.4 and 23.1.0-23.1.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Cloud Native Core Policy executes to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Policy accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938436.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
]
}
]
},
{
"cve": "CVE-2022-4450",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "35121425"
},
{
"system_name": "Oracle Bug ID of MySQL Connectors",
"text": "35136522"
},
{
"system_name": "Oracle Bug ID of MySQL Workbench",
"text": "35136526"
},
{
"system_name": "Oracle Bug ID of MySQL Enterprise Monitor",
"text": "35136525"
},
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "35136513"
},
{
"system_name": "Oracle Bug ID of MySQL Connectors",
"text": "35136523"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Essbase (component: Build (OpenSSL)). The supported version that is affected is 21.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Essbase. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Essbase. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging (OpenSSL)). Supported versions that are affected are 5.7.41 and prior and 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC (OpenSSL)). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++ (OpenSSL)). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (OpenSSL)). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Enterprise Monitor. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: Workbench (OpenSSL)). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4379V-21.4",
"P-8478V-8.0.32 and prior",
"P-8478V-5.7.41 and prior",
"P-8576V-8.0.32 and prior",
"P-4627V-8.0.32 and prior",
"P-8480V-8.0.33 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4379V-21.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8576V-8.0.32 and prior",
"P-8478V-8.0.32 and prior",
"P-8478V-5.7.41 and prior",
"P-4627V-8.0.32 and prior",
"P-8480V-8.0.33 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-4379V-21.4"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8576V-8.0.32 and prior",
"P-8478V-8.0.32 and prior",
"P-8478V-5.7.41 and prior",
"P-4627V-8.0.32 and prior",
"P-8480V-8.0.33 and prior"
]
}
]
},
{
"cve": "CVE-2022-45047",
"ids": [
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "34830525"
},
{
"system_name": "Oracle Bug ID of Oracle Retail Customer Management and Segmentation Foundation",
"text": "34830515"
},
{
"system_name": "Oracle Bug ID of Oracle SQL Developer",
"text": "34830527"
},
{
"system_name": "Oracle Bug ID of Oracle Business Process Management Suite",
"text": "34830522"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Automated Test Suite",
"text": "34982777"
},
{
"system_name": "Oracle Bug ID of Oracle NoSQL Database",
"text": "34830513"
},
{
"system_name": "Oracle Bug ID of Management Cloud Engine",
"text": "34830473"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Element Manager",
"text": "34830491"
},
{
"system_name": "Oracle Bug ID of Oracle GoldenGate",
"text": "34830507"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
"text": "34830492"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Management Cloud Engine product of Oracle Communications (component: BEServer (Apache Mina SSHD)). The supported version that is affected is 22.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSH to compromise Management Cloud Engine. Successful attacks of this vulnerability can result in takeover of Management Cloud Engine. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: BEServer (Apache Mina SSHD)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Communications Element Manager. Successful attacks of this vulnerability can result in takeover of Oracle Communications Element Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: BEServer (Apache Mina SSHD)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Communications Session Report Manager. Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle GoldenGate (component: Oracle GoldenGate (Apache Mina SSHD)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle NoSQL Database (component: Administration (Apache Mina SSHD)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Internal Operations (Apache Mina SSHD)). The supported version that is affected is 19.0.0.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in takeover of Oracle Retail Customer Management and Segmentation Foundation. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Installer (Apache Mina SSHD)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite. Successful attacks of this vulnerability can result in takeover of Oracle Business Process Management Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Webserver (Apache Mina SSHD)). The supported version that is affected is 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle SQL Developer (component: Installation (Apache Mina SSHD)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Automated Test Suite product of Oracle Communications (component: Installation (Apache Mina SSHD)). Supported versions that are affected are 22.3.1 and 22.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Automated Test Suite. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Automated Test Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13388V-19.0.0.6",
"P-14252V-22.1.0.0.0",
"P-11052V-9.0.1",
"P-10770V-9.0.1",
"P-11052V-9.0.0",
"P-10770V-9.0.0",
"P-14488V-22.3.1",
"P-14488V-22.4.0",
"P-5325V-12.2.1.4.0",
"P-5085V-8.60"
],
"known_not_affected": [
"P-1875V-Prior to 22.4.0",
"P-5757V-Prior to 19.1.0.0.230418",
"P-5757V-Prior to 21.10.0.0.0",
"P-13373V-Prior to 19.5.32"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14252V-22.1.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2942213.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11052V-9.0.1",
"P-11052V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938441.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10770V-9.0.1",
"P-10770V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938447.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13373V-Prior to 19.5.32",
"P-1875V-Prior to 22.4.0",
"P-5757V-Prior to 19.1.0.0.230418",
"P-5757V-Prior to 21.10.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13388V-19.0.0.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=2934131.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5325V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.60"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939793.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14488V-22.3.1",
"P-14488V-22.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938415.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-13388V-19.0.0.6",
"P-14252V-22.1.0.0.0",
"P-11052V-9.0.1",
"P-10770V-9.0.1",
"P-11052V-9.0.0",
"P-10770V-9.0.0",
"P-14488V-22.3.1",
"P-14488V-22.4.0",
"P-5325V-12.2.1.4.0",
"P-5085V-8.60"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13373V-Prior to 19.5.32",
"P-1875V-Prior to 22.4.0",
"P-5757V-Prior to 19.1.0.0.230418",
"P-5757V-Prior to 21.10.0.0.0"
]
}
]
},
{
"cve": "CVE-2022-45061",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "34997341"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Database OML4PY (Python) component of Oracle Database Server. The supported version that is affected is 21c. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via HTTP to compromise Oracle Database OML4PY (Python). Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Database OML4PY (Python). CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5(Oracle Database OML4PY)V-21c"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Oracle Database OML4PY)V-21c"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-5(Oracle Database OML4PY)V-21c"
]
}
]
},
{
"cve": "CVE-2022-45143",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "34970057"
},
{
"system_name": "Oracle Bug ID of Oracle Agile PLM",
"text": "34970397"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Binding Support Function",
"text": "35137264"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Element Manager",
"text": "35137272"
},
{
"system_name": "Oracle Bug ID of Oracle Graph Server and Client",
"text": "35137283"
},
{
"system_name": "Oracle Bug ID of Oracle Commerce Guided Search",
"text": "35137262"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
"text": "35137273"
},
{
"system_name": "Oracle Bug ID of Oracle SD-WAN Edge",
"text": "35137289"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
"text": "35137268"
},
{
"system_name": "Oracle Bug ID of MySQL Enterprise Monitor",
"text": "35137247"
},
{
"system_name": "Oracle Bug ID of Oracle Big Data Spatial and Graph",
"text": "35137258"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle Database (Apache Tomcat) component of Oracle Database Server. This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security (Apache Tomcat)). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (Apache Tomcat)). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Enterprise Monitor accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Big Data Spatial and Graph (component: Big Data Graph (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Content Acquisition System, Workbench (Apache Tomcat)). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Binding Support Function product of Oracle Communications (component: Policy (Apache Tomcat)). Supported versions that are affected are 22.4.0-22.4.4 and 23.1.0-23.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Binding Support Function. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Binding Support Function accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Platform (Apache Tomcat)). The supported version that is affected is 8.6.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Diameter Signaling Router accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: BEServer (Apache Tomcat)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Element Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Element Manager accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: BEServer (Apache Tomcat)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Report Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Session Report Manager accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Graph Server and Client (component: Packaging (Apache Tomcat)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle SD-WAN Edge product of Oracle Communications (component: Internal tools (Apache Tomcat)). The supported version that is affected is 9.1.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SD-WAN Edge. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle SD-WAN Edge accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13940V-9.1.1.4.0",
"P-9633V-11.3.2",
"P-11052V-9.0.1",
"P-10770V-9.0.1",
"P-11052V-9.0.0",
"P-10770V-9.0.0",
"P-14121V-22.4.0-22.4.4",
"P-14121V-23.1.0-23.1.1",
"P-4461V-9.3.6",
"P-10899V-8.6.0.0",
"P-8480V-8.0.33 and prior"
],
"known_not_affected": [
"P-14069V-Prior to 23.2.0",
"P-5(Oracle Database)V-21c",
"P-5(Oracle Database)V-19c",
"P-11528V-Prior to 23.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14069V-Prior to 23.2.0",
"P-5(Oracle Database)V-19c",
"P-11528V-Prior to 23.1",
"P-5(Oracle Database)V-21c"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4461V-9.3.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939856.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8480V-8.0.33 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9633V-11.3.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939844.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14121V-22.4.0-22.4.4",
"P-14121V-23.1.0-23.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938417.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10899V-8.6.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938440.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11052V-9.0.1",
"P-11052V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938441.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10770V-9.0.1",
"P-10770V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938447.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13940V-9.1.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938444.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-14069V-Prior to 23.2.0",
"P-5(Oracle Database)V-19c",
"P-11528V-Prior to 23.1",
"P-5(Oracle Database)V-21c"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13940V-9.1.1.4.0",
"P-9633V-11.3.2",
"P-11052V-9.0.1",
"P-10770V-9.0.1",
"P-11052V-9.0.0",
"P-10770V-9.0.0",
"P-14121V-22.4.0-22.4.4",
"P-14121V-23.1.0-23.1.1",
"P-4461V-9.3.6",
"P-10899V-8.6.0.0",
"P-8480V-8.0.33 and prior"
]
}
]
},
{
"cve": "CVE-2022-45685",
"ids": [
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "34997219"
},
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "34945769"
},
{
"system_name": "Oracle Bug ID of Oracle Identity Manager",
"text": "35032549"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Third Party (Jettison)). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security (Jettison)). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Third Party (Jettison)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Identity Manager. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5085V-8.58",
"P-1980V-12.2.1.4.0",
"P-5242V-14.1.1.0.0",
"P-5085V-8.59",
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0",
"P-5085V-8.60"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1980V-12.2.1.4.0",
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.58",
"P-5085V-8.59",
"P-5085V-8.60"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939793.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-5085V-8.58",
"P-1980V-12.2.1.4.0",
"P-5242V-14.1.1.0.0",
"P-5085V-8.59",
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0",
"P-5085V-8.60"
]
}
]
},
{
"cve": "CVE-2022-45693",
"ids": [
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "34997219"
},
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "34945769"
},
{
"system_name": "Oracle Bug ID of Oracle Identity Manager",
"text": "35032549"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Third Party (Jettison)). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security (Jettison)). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Third Party (Jettison)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Identity Manager. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5085V-8.58",
"P-1980V-12.2.1.4.0",
"P-5242V-14.1.1.0.0",
"P-5085V-8.59",
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0",
"P-5085V-8.60"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1980V-12.2.1.4.0",
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.58",
"P-5085V-8.59",
"P-5085V-8.60"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939793.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-5085V-8.58",
"P-1980V-12.2.1.4.0",
"P-5242V-14.1.1.0.0",
"P-5085V-8.59",
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0",
"P-5085V-8.60"
]
}
]
},
{
"cve": "CVE-2022-46363",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Element Manager",
"text": "35098684"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
"text": "35098685"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Digital Experience",
"text": "35166294"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
"text": "35098682"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Virtual Network Function Manager (Apache CXF)). The supported version that is affected is 8.6.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router. Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: SOAP (Apache CXF)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Element Manager. Successful attacks of this vulnerability can result in takeover of Oracle Communications Element Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: SOAP (Apache CXF)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Report Manager. Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: UI General (Apache CXF)). Supported versions that are affected are 21.1, 22.1 and 22.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Digital Experience. Successful attacks of this vulnerability can result in takeover of Oracle Banking Digital Experience. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11052V-9.0.1",
"P-10770V-9.0.1",
"P-11052V-9.0.0",
"P-10770V-9.0.0",
"P-12605V-22.2",
"P-12605V-21.1",
"P-12605V-22.1",
"P-10899V-8.6.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10899V-8.6.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938440.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11052V-9.0.1",
"P-11052V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938441.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10770V-9.0.1",
"P-10770V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938447.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12605V-22.2",
"P-12605V-21.1",
"P-12605V-22.1"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-11052V-9.0.1",
"P-10770V-9.0.1",
"P-11052V-9.0.0",
"P-10770V-9.0.0",
"P-12605V-22.2",
"P-12605V-21.1",
"P-12605V-22.1",
"P-10899V-8.6.0.0"
]
}
]
},
{
"cve": "CVE-2022-46364",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Element Manager",
"text": "35098684"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
"text": "35098685"
},
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "35136971"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Digital Experience",
"text": "35166294"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Diameter Signaling Router",
"text": "35098682"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Diameter Signaling Router product of Oracle Communications (component: Virtual Network Function Manager (Apache CXF)). The supported version that is affected is 8.6.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router. Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: SOAP (Apache CXF)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Element Manager. Successful attacks of this vulnerability can result in takeover of Oracle Communications Element Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: SOAP (Apache CXF)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Report Manager. Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Essbase (component: Essbase Web Platform (Apache CXF)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: UI General (Apache CXF)). Supported versions that are affected are 21.1, 22.1 and 22.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Digital Experience. Successful attacks of this vulnerability can result in takeover of Oracle Banking Digital Experience. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11052V-9.0.1",
"P-10770V-9.0.1",
"P-11052V-9.0.0",
"P-10770V-9.0.0",
"P-12605V-22.2",
"P-12605V-21.1",
"P-12605V-22.1",
"P-10899V-8.6.0.0"
],
"known_not_affected": [
"P-4379V-21.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10899V-8.6.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938440.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11052V-9.0.1",
"P-11052V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938441.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10770V-9.0.1",
"P-10770V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938447.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4379V-21.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12605V-22.2",
"P-12605V-21.1",
"P-12605V-22.1"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-11052V-9.0.1",
"P-10770V-9.0.1",
"P-11052V-9.0.0",
"P-10770V-9.0.0",
"P-12605V-22.2",
"P-12605V-21.1",
"P-12605V-22.1",
"P-10899V-8.6.0.0"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-4379V-21.4"
]
}
]
},
{
"cve": "CVE-2022-46908",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Healthcare Translational Research",
"text": "35166321"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Network Charging and Control",
"text": "35064960"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Convergent Charging Controller",
"text": "35064955"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Compliance Studio",
"text": "35064968"
},
{
"system_name": "Oracle Bug ID of Oracle Outside In Technology",
"text": "35064979"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications Applications (component: Common fns (SQLite)). Supported versions that are affected are 6.0.1.0.0 and 12.0.1.0.0-12.0.6.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Convergent Charging Controller executes to compromise Oracle Communications Convergent Charging Controller. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Convergent Charging Controller accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Convergent Charging Controller accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Convergent Charging Controller. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Network Charging and Control product of Oracle Communications Applications (component: Common fns (SQLite)). Supported versions that are affected are 6.0.1.0.0 and 12.0.1.0.0-12.0.6.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Network Charging and Control executes to compromise Oracle Communications Network Charging and Control. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Network Charging and Control accessible data as well as unauthorized access to critical data or complete access to all Oracle Communications Network Charging and Control accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Network Charging and Control. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Compliance Studio product of Oracle Financial Services Applications (component: Application (SQLite)). The supported version that is affected is 8.1.2.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Financial Services Compliance Studio executes to compromise Oracle Financial Services Compliance Studio. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financial Services Compliance Studio accessible data as well as unauthorized access to critical data or complete access to all Oracle Financial Services Compliance Studio accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financial Services Compliance Studio. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Third Party (SQLite)). The supported version that is affected is 8.5.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Outside In Technology accessible data as well as unauthorized access to critical data or complete access to all Oracle Outside In Technology accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Translational Research product of Oracle HealthCare Applications (component: DataStudio (SQLite)). Supported versions that are affected are 4.1.0 and 4.1.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Healthcare Translational Research executes to compromise Oracle Healthcare Translational Research. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Translational Research accessible data as well as unauthorized access to critical data or complete access to all Oracle Healthcare Translational Research accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Healthcare Translational Research. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-12985V-6.0.1.0.0",
"P-9427V-4.1.0",
"P-12985V-12.0.1.0.0-12.0.6.0.0",
"P-9427V-4.1.1",
"P-14392V-8.1.2.4",
"P-4623V-6.0.1.0.0",
"P-2276V-8.5.6",
"P-4623V-12.0.1.0.0-12.0.6.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-12985V-6.0.1.0.0",
"P-12985V-12.0.1.0.0-12.0.6.0.0",
"P-4623V-6.0.1.0.0",
"P-4623V-12.0.1.0.0-12.0.6.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936023.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14392V-8.1.2.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936394.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2276V-8.5.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939153.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
"version": "3.1"
},
"products": [
"P-12985V-6.0.1.0.0",
"P-9427V-4.1.0",
"P-12985V-12.0.1.0.0-12.0.6.0.0",
"P-9427V-4.1.1",
"P-14392V-8.1.2.4",
"P-4623V-6.0.1.0.0",
"P-2276V-8.5.6",
"P-4623V-12.0.1.0.0-12.0.6.0.0"
]
}
]
},
{
"cve": "CVE-2022-47629",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "35196472"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
"text": "35174820"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Configuration Console",
"text": "35190969"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
"text": "35191041"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
"text": "35184538"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Oracle Linux (libksba)). The supported version that is affected is 22.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (libksba)). The supported version that is affected is 22.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Configuration Console product of Oracle Communications (component: Configuration (libksba)). The supported version that is affected is 22.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Configuration Console. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Configuration Console. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Signaling (libksba)). Supported versions that are affected are 22.4.1 and 23.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (libksba)). Supported versions that are affected are 22.4.0-22.4.4 and 23.1.0-23.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14277V-22.4.0-22.4.4",
"P-14119V-22.4.1",
"P-14122V-22.4.2",
"P-14119V-23.1.0",
"P-14277V-23.1.0-23.1.1",
"P-14123V-22.4.0",
"P-14250V-22.4.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14122V-22.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938420.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14123V-22.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938437.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14250V-22.4.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938418.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14119V-22.4.1",
"P-14119V-23.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938438.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938436.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14277V-22.4.0-22.4.4",
"P-14119V-22.4.1",
"P-14122V-22.4.2",
"P-14119V-23.1.0",
"P-14277V-23.1.0-23.1.1",
"P-14123V-22.4.0",
"P-14250V-22.4.1"
]
}
]
},
{
"cve": "CVE-2023-0215",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "35121425"
},
{
"system_name": "Oracle Bug ID of MySQL Connectors",
"text": "35136522"
},
{
"system_name": "Oracle Bug ID of MySQL Workbench",
"text": "35136526"
},
{
"system_name": "Oracle Bug ID of MySQL Enterprise Monitor",
"text": "35136525"
},
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "35136513"
},
{
"system_name": "Oracle Bug ID of MySQL Connectors",
"text": "35136523"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Essbase (component: Build (OpenSSL)). The supported version that is affected is 21.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Essbase. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Essbase. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging (OpenSSL)). Supported versions that are affected are 5.7.41 and prior and 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC (OpenSSL)). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++ (OpenSSL)). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (OpenSSL)). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Enterprise Monitor. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: Workbench (OpenSSL)). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4379V-21.4",
"P-8576(Connector/ODBC)V-8.0.32 and prior",
"P-8478V-8.0.32 and prior",
"P-8478V-5.7.41 and prior",
"P-4627V-8.0.32 and prior",
"P-8480V-8.0.33 and prior",
"P-8576(Connector/C++)V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4379V-21.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8576(Connector/ODBC)V-8.0.32 and prior",
"P-8478V-8.0.32 and prior",
"P-8478V-5.7.41 and prior",
"P-4627V-8.0.32 and prior",
"P-8480V-8.0.33 and prior",
"P-8576(Connector/C++)V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-4379V-21.4"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8576(Connector/ODBC)V-8.0.32 and prior",
"P-8478V-8.0.32 and prior",
"P-8478V-5.7.41 and prior",
"P-4627V-8.0.32 and prior",
"P-8480V-8.0.33 and prior",
"P-8576(Connector/C++)V-8.0.32 and prior"
]
}
]
},
{
"cve": "CVE-2023-0286",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "35121425"
},
{
"system_name": "Oracle Bug ID of MySQL Connectors",
"text": "35136522"
},
{
"system_name": "Oracle Bug ID of MySQL Workbench",
"text": "35136526"
},
{
"system_name": "Oracle Bug ID of MySQL Enterprise Monitor",
"text": "35136525"
},
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "35136513"
},
{
"system_name": "Oracle Bug ID of MySQL Connectors",
"text": "35136523"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Essbase (component: Build (OpenSSL)). The supported version that is affected is 21.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Essbase. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Essbase. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging (OpenSSL)). Supported versions that are affected are 5.7.41 and prior and 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC (OpenSSL)). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++ (OpenSSL)). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (OpenSSL)). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Enterprise Monitor. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the MySQL Workbench product of Oracle MySQL (component: Workbench (OpenSSL)). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4379V-21.4",
"P-8478V-8.0.32 and prior",
"P-8478V-5.7.41 and prior",
"P-8576V-8.0.32 and prior",
"P-4627V-8.0.32 and prior",
"P-8480V-8.0.33 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4379V-21.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8576V-8.0.32 and prior",
"P-8478V-8.0.32 and prior",
"P-8478V-5.7.41 and prior",
"P-4627V-8.0.32 and prior",
"P-8480V-8.0.33 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-4379V-21.4"
]
},
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8576V-8.0.32 and prior",
"P-8478V-8.0.32 and prior",
"P-8478V-5.7.41 and prior",
"P-4627V-8.0.32 and prior",
"P-8480V-8.0.33 and prior"
]
}
]
},
{
"cve": "CVE-2023-0361",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Repository Function",
"text": "35156668"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Repository Function product of Oracle Communications (component: Installer (GnuTLS)). The supported version that is affected is 23.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Repository Function. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Network Repository Function accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14118V-23.1.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14118V-23.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938435.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-14118V-23.1.0"
]
}
]
},
{
"cve": "CVE-2023-0567",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "35112157"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (PHP)). Supported versions that are affected are 6.0.0-6.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14597V-6.0.0-6.0.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-6.0.0-6.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14597V-6.0.0-6.0.2"
]
}
]
},
{
"cve": "CVE-2023-0568",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "35112157"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (PHP)). Supported versions that are affected are 6.0.0-6.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14597V-6.0.0-6.0.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-6.0.0-6.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14597V-6.0.0-6.0.2"
]
}
]
},
{
"cve": "CVE-2023-0662",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "35112157"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Core (PHP)). Supported versions that are affected are 6.0.0-6.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14597V-6.0.0-6.0.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-6.0.0-6.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14597V-6.0.0-6.0.2"
]
}
]
},
{
"cve": "CVE-2023-1370",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
"text": "35022799"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications Applications (component: Vision (json-smart)). Supported versions that are affected are 5.5.0-5.5.10 and 6.0.0-6.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Unified Assurance. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936013.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14597V-5.5.0-5.5.10",
"P-14597V-6.0.0-6.0.2"
]
}
]
},
{
"cve": "CVE-2023-21896",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Solaris",
"text": "33948737"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: NSSwitch). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10006V-10",
"P-10006V-11"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10006V-10",
"P-10006V-11"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940069.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.0,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-10006V-10",
"P-10006V-11"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Khanh Nguyen"
]
}
],
"cve": "CVE-2023-21902",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Financial Services Behavior Detection Platform",
"text": "34852705"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Application). The supported version that is affected is 8.0.8.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Financial Services Behavior Detection Platform accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9190V-8.0.8.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9190V-8.0.8.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936356.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-9190V-8.0.8.1"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Nguyen Binh Minh"
],
"organization": "CSOC-FTEL"
}
],
"cve": "CVE-2023-21903",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
"text": "34045517"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Internal Tfr Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Banking Virtual Account Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Banking Virtual Account Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Virtual Account Management. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13487V-14.5",
"P-13487V-14.6",
"P-13487V-14.7"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13487V-14.5",
"P-13487V-14.6",
"P-13487V-14.7"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L",
"version": "3.1"
},
"products": [
"P-13487V-14.5",
"P-13487V-14.6",
"P-13487V-14.7"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Nguyen Binh Minh"
],
"organization": "CSOC-FTEL"
}
],
"cve": "CVE-2023-21904",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
"text": "34053558"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Banking Virtual Account Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Banking Virtual Account Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Banking Virtual Account Management. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13487V-14.5",
"P-13487V-14.6",
"P-13487V-14.7"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13487V-14.5",
"P-13487V-14.6",
"P-13487V-14.7"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L",
"version": "3.1"
},
"products": [
"P-13487V-14.5",
"P-13487V-14.6",
"P-13487V-14.7"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Nguyen Binh Minh"
],
"organization": "CSOC-FTEL"
}
],
"cve": "CVE-2023-21905",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
"text": "34045503"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Routing Hub). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Virtual Account Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Virtual Account Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13487V-14.5",
"P-13487V-14.6",
"P-13487V-14.7"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13487V-14.5",
"P-13487V-14.6",
"P-13487V-14.7"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13487V-14.5",
"P-13487V-14.6",
"P-13487V-14.7"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"CSOC-FTEL"
]
}
],
"cve": "CVE-2023-21906",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
"text": "34039676"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: SMS Module). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Banking Virtual Account Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Banking Virtual Account Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13487V-14.5",
"P-13487V-14.6",
"P-13487V-14.7"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13487V-14.5",
"P-13487V-14.6",
"P-13487V-14.7"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-13487V-14.5",
"P-13487V-14.6",
"P-13487V-14.7"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Nguyen Binh Yen"
],
"organization": "CSOC-FTEL"
}
],
"cve": "CVE-2023-21907",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
"text": "34054287"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Banking Virtual Account Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Banking Virtual Account Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management. CVSS 3.1 Base Score 6.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13487V-14.5",
"P-13487V-14.6",
"P-13487V-14.7"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13487V-14.5",
"P-13487V-14.6",
"P-13487V-14.7"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.0,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:H",
"version": "3.1"
},
"products": [
"P-13487V-14.5",
"P-13487V-14.6",
"P-13487V-14.7"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Nguyen Binh Yen"
],
"organization": "CSOC-FTEL"
}
],
"cve": "CVE-2023-21908",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Virtual Account Management",
"text": "34054298"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Banking Virtual Account Management accessible data as well as unauthorized update, insert or delete access to some of Oracle Banking Virtual Account Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Virtual Account Management. CVSS 3.1 Base Score 6.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13487V-14.5",
"P-13487V-14.6",
"P-13487V-14.7"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13487V-14.5",
"P-13487V-14.6",
"P-13487V-14.7"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.0,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:H",
"version": "3.1"
},
"products": [
"P-13487V-14.5",
"P-13487V-14.6",
"P-13487V-14.7"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Adam Willard"
]
}
],
"cve": "CVE-2023-21909",
"ids": [
{
"system_name": "Oracle Bug ID of Siebel CRM",
"text": "35066092"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: UI Framework). Supported versions that are affected are 23.3 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Siebel CRM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9011V-23.3 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9011V-23.3 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939854.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-9011V-23.3 and prior"
]
}
]
},
{
"cve": "CVE-2023-21910",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "33590589"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General). Supported versions that are affected are 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-12.2.1.4.0",
"P-2025V-6.4.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-12.2.1.4.0",
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-2025V-12.2.1.4.0",
"P-2025V-6.4.0.0.0"
]
}
]
},
{
"cve": "CVE-2023-21911",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "33700835"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Linrong Cao"
],
"organization": "Noah-Lab"
},
{
"names": [
"Zhangyi Chen"
],
"organization": "Noah-Lab"
}
],
"cve": "CVE-2023-21912",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "33723597"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 5.7.41 and prior and 8.0.30 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.30 and prior",
"P-8478V-5.7.41 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.30 and prior",
"P-8478V-5.7.41 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.30 and prior",
"P-8478V-5.7.41 and prior"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Jie Liang"
],
"organization": "WingTecher Lab"
},
{
"names": [
"Jingzhou Fu"
],
"organization": "WingTecher Lab"
},
{
"names": [
"Zhiyong Wu"
],
"organization": "WingTecher Lab"
}
],
"cve": "CVE-2023-21913",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "33725415"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.31 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.31 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.31 and prior"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"CSOC-FTEL"
]
}
],
"cve": "CVE-2023-21915",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Banking Payments",
"text": "34090519"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Book/Internal Transfer). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Banking Payments accessible data as well as unauthorized read access to a subset of Oracle Banking Payments accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13011V-14.7",
"P-13011V-14.6",
"P-13011V-14.5"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13011V-14.7",
"P-13011V-14.6",
"P-13011V-14.5"
],
"url": "https://support.oracle.com"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.6,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-13011V-14.7",
"P-13011V-14.6",
"P-13011V-14.5"
]
}
]
},
{
"cve": "CVE-2023-21916",
"ids": [
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "34257990"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Web Server). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5085V-8.58",
"P-5085V-8.60",
"P-5085V-8.59"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.58",
"P-5085V-8.59",
"P-5085V-8.60"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939793.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5085V-8.58",
"P-5085V-8.59",
"P-5085V-8.60"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Wang Ke"
],
"organization": "Zhejiang University"
}
],
"cve": "CVE-2023-21917",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34275055"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.30 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.30 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.30 and prior"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Emad Al-Mousa"
],
"organization": "Saudi Aramco"
}
],
"cve": "CVE-2023-21918",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "34363828"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Database Recovery Manager component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having Local SYSDBA privilege with network access via Oracle Net to compromise Oracle Database Recovery Manager. While the vulnerability is in Oracle Database Recovery Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Database Recovery Manager. CVSS 3.1 Base Score 6.8 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5(Oracle Database Recovery Manager)V-21c",
"P-5(Oracle Database Recovery Manager)V-19c"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Oracle Database Recovery Manager)V-19c",
"P-5(Oracle Database Recovery Manager)V-21c"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-5(Oracle Database Recovery Manager)V-19c",
"P-5(Oracle Database Recovery Manager)V-21c"
]
}
]
},
{
"cve": "CVE-2023-21919",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34369580"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior"
]
}
]
},
{
"cve": "CVE-2023-21920",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34370673"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior"
]
}
]
},
{
"cve": "CVE-2023-21921",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Health Sciences InForm",
"text": "34378402"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Health Sciences InForm accessible data as well as unauthorized read access to a subset of Oracle Health Sciences InForm accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938697.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
]
}
]
},
{
"cve": "CVE-2023-21922",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Health Sciences InForm",
"text": "34379437"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Health Sciences InForm accessible data as well as unauthorized access to critical data or complete access to all Oracle Health Sciences InForm accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938697.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
]
}
]
},
{
"cve": "CVE-2023-21923",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Health Sciences InForm",
"text": "34379470"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Health Sciences InForm accessible data as well as unauthorized access to critical data or complete access to all Oracle Health Sciences InForm accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Health Sciences InForm. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938697.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
"version": "3.1"
},
"products": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
]
}
]
},
{
"cve": "CVE-2023-21924",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Health Sciences InForm",
"text": "34379672"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Health Sciences InForm, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Health Sciences InForm accessible data as well as unauthorized read access to a subset of Oracle Health Sciences InForm accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Health Sciences InForm. CVSS 3.1 Base Score 5.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938697.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L",
"version": "3.1"
},
"products": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
]
}
]
},
{
"cve": "CVE-2023-21925",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Health Sciences InForm",
"text": "34379718"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences InForm. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Health Sciences InForm. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938697.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
]
}
]
},
{
"cve": "CVE-2023-21926",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Health Sciences InForm",
"text": "34380365"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Health Sciences InForm executes to compromise Oracle Health Sciences InForm. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Health Sciences InForm accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938697.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-9636V-Prior to 6.3.1.3",
"P-9636V-Prior to 7.0.0.1"
]
}
]
},
{
"cve": "CVE-2023-21927",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "34383684"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Interoperability SEC). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.3"
]
}
]
},
{
"cve": "CVE-2023-21928",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Solaris",
"text": "34459738"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: IPS repository daemon). The supported version that is affected is 11. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Solaris accessible data. CVSS 3.1 Base Score 1.8 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10006V-11"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10006V-11"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940069.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 1.8,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"P-10006V-11"
]
}
]
},
{
"cve": "CVE-2023-21929",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34463652"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Ben Smyth"
]
}
],
"cve": "CVE-2023-21930",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Java SE",
"text": "34476467"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-856V-Oracle Java SE:20",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1",
"P-856V-Oracle Java SE:11.0.18"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-856V-Oracle Java SE:20",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1",
"P-856V-Oracle Java SE:11.0.18"
],
"url": "https://support.oracle.com/rs?type=doc&id=2935948.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.4,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-856V-Oracle Java SE:20",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1",
"P-856V-Oracle Java SE:11.0.18"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"0xrumbe, zd"
],
"organization": "ThreatBook Labs"
},
{
"names": [
"4ra1n"
],
"organization": "Chaitin Tech"
},
{
"names": [
"ADLab"
],
"organization": "Venustech"
},
{
"names": [
"bluE0"
]
},
{
"names": [
"Lai Han"
]
},
{
"names": [
"Liboheng"
],
"organization": "Tophant Starlight laboratory"
},
{
"names": [
"P1ay2win"
],
"organization": "Qianxin Wuji Lab"
},
{
"names": [
"thiscodecc"
],
"organization": "MoyunSec TopBreaker Labs and Bing"
},
{
"names": [
"tr1ple (AntGroup FG)"
]
},
{
"names": [
"X1r0z"
]
},
{
"names": [
"Yu Wang"
],
"organization": "BMH Security Team"
}
],
"cve": "CVE-2023-21931",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "34520786"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0",
"P-5242V-14.1.1.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Shubham Shah, Sean Yeoh, Jason Haddix, Brendan Scarvell"
]
}
],
"cve": "CVE-2023-21932",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Hospitality OPERA 5 Property Services",
"text": "34551747"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: OXI). The supported version that is affected is 5.6. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services. While the vulnerability is in Oracle Hospitality OPERA 5 Property Services, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hospitality OPERA 5 Property Services accessible data as well as unauthorized update, insert or delete access to some of Oracle Hospitality OPERA 5 Property Services accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality OPERA 5 Property Services. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11580V-5.6"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11580V-5.6"
],
"url": "https://support.oracle.com/rs?type=doc&id=2935379.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L",
"version": "3.1"
},
"products": [
"P-11580V-5.6"
]
}
]
},
{
"cve": "CVE-2023-21933",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34559843"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior"
]
}
]
},
{
"cve": "CVE-2023-21934",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "35021301"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Difficult to exploit vulnerability allows low privileged attacker having User Account privilege with network access via TLS to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java VM accessible data as well as unauthorized access to critical data or complete access to all Java VM accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5(Java VM)V-19c",
"P-5(Java VM)V-21c"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5(Java VM)V-19c",
"P-5(Java VM)V-21c"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-5(Java VM)V-19c",
"P-5(Java VM)V-21c"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Zu-Ming Jiang"
]
}
],
"cve": "CVE-2023-21935",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34616553"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior"
]
}
]
},
{
"cve": "CVE-2023-21936",
"ids": [
{
"system_name": "Oracle Bug ID of JD Edwards EnterpriseOne Tools",
"text": "34640238"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are Prior to 9.2.7.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4781V-Prior to 9.2.7.3"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4781V-Prior to 9.2.7.3"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939855.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-4781V-Prior to 9.2.7.3"
]
}
]
},
{
"cve": "CVE-2023-21937",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Java SE",
"text": "34650372"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-856V-Oracle Java SE:20",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1",
"P-856V-Oracle Java SE:11.0.18"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-856V-Oracle Java SE:20",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1",
"P-856V-Oracle Java SE:11.0.18"
],
"url": "https://support.oracle.com/rs?type=doc&id=2935948.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 3.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-856V-Oracle Java SE:20",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1",
"P-856V-Oracle Java SE:11.0.18"
]
}
]
},
{
"cve": "CVE-2023-21938",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Java SE",
"text": "34650379"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.8, 21.3.4 and 22.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.8",
"P-856V-Oracle Java SE:20",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.4",
"P-856V-Oracle Java SE:11.0.18",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.8",
"P-856V-Oracle Java SE:20",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.4",
"P-856V-Oracle Java SE:11.0.18",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2935948.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 3.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.8",
"P-856V-Oracle Java SE:20",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.4",
"P-856V-Oracle Java SE:11.0.18",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.0"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"BeichenDream"
]
},
{
"names": [
"c0ny1"
]
}
],
"cve": "CVE-2023-21939",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Java SE",
"text": "34700794"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-856V-Oracle Java SE:20",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1",
"P-856V-Oracle Java SE:11.0.18"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-856V-Oracle Java SE:20",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1",
"P-856V-Oracle Java SE:11.0.18"
],
"url": "https://support.oracle.com/rs?type=doc&id=2935948.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-856V-Oracle Java SE:20",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1",
"P-856V-Oracle Java SE:11.0.18"
]
}
]
},
{
"cve": "CVE-2023-21940",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34712193"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior"
]
}
]
},
{
"cve": "CVE-2023-21941",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle BI Publisher",
"text": "34715957"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that are affected are 6.4.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1479V-6.4.0.0.0",
"P-1479V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1479V-6.4.0.0.0",
"P-1479V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-1479V-6.4.0.0.0",
"P-1479V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2023-21942",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "34722950"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Essbase (component: Security and Provisioning). The supported version that is affected is 21.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Essbase. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Essbase accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4379V-21.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4379V-21.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-4379V-21.4"
]
}
]
},
{
"cve": "CVE-2023-21943",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "34723105"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Essbase (component: Security and Provisioning). The supported version that is affected is 21.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Essbase. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Essbase accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4379V-21.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4379V-21.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-4379V-21.4"
]
}
]
},
{
"cve": "CVE-2023-21944",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "34723146"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle Essbase (component: Security and Provisioning). The supported version that is affected is 21.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Essbase. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Essbase accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-4379V-21.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4379V-21.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-4379V-21.4"
]
}
]
},
{
"cve": "CVE-2023-21945",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34741801"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior"
]
}
]
},
{
"cve": "CVE-2023-21946",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34745241"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior"
]
}
]
},
{
"cve": "CVE-2023-21947",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34760190"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior"
]
}
]
},
{
"cve": "CVE-2023-21948",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Solaris",
"text": "35073170"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Core). The supported version that is affected is 10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10006V-10"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10006V-10"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940069.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-10006V-10"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"AnhNH"
],
"organization": "Sacombank"
},
{
"names": [
"ChauUHM"
],
"organization": "Sacombank"
},
{
"names": [
"TungHT"
],
"organization": "Sacombank"
}
],
"cve": "CVE-2023-21952",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34788533"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-6.4.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.7,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-2025V-6.4.0.0.0"
]
}
]
},
{
"cve": "CVE-2023-21953",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34797257"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Partition). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Ramki Ramakrishna"
],
"organization": "Amazon"
}
],
"cve": "CVE-2023-21954",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Java SE",
"text": "34798040"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1",
"P-856V-Oracle Java SE:11.0.18"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1",
"P-856V-Oracle Java SE:11.0.18"
],
"url": "https://support.oracle.com/rs?type=doc&id=2935948.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1",
"P-856V-Oracle Java SE:11.0.18"
]
}
]
},
{
"cve": "CVE-2023-21955",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34801284"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Partition). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior"
]
}
]
},
{
"cve": "CVE-2023-21956",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "34803129"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2023-21959",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle iReceivables",
"text": "34824895"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: Attachments). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iReceivables. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iReceivables accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1106V-12.2.3-12.2.12"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1106V-12.2.3-12.2.12"
],
"url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-1106V-12.2.3-12.2.12"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"4ra1n"
],
"organization": "Chaitin Tech"
},
{
"names": [
"Y4tacker"
]
}
],
"cve": "CVE-2023-21960",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "34881912"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as unauthorized read access to a subset of Oracle WebLogic Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 5.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.6,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
},
"products": [
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2023-21962",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34848106"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior"
]
}
]
},
{
"cve": "CVE-2023-21963",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34857411"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Connection Handling). Supported versions that are affected are 5.7.40 and prior and 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-5.7.40 and prior",
"P-8478V-8.0.31 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-5.7.40 and prior",
"P-8478V-8.0.31 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 2.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
},
"products": [
"P-8478V-5.7.40 and prior",
"P-8478V-8.0.31 and prior"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"4ra1n"
],
"organization": "Chaitin Tech"
},
{
"names": [
"sw0rd1ight"
]
}
],
"cve": "CVE-2023-21964",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "34858275"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0",
"P-5242V-14.1.1.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"AnhNH"
],
"organization": "Sacombank"
},
{
"names": [
"ChauUHM"
],
"organization": "Sacombank"
},
{
"names": [
"TungHT"
],
"organization": "Sacombank"
}
],
"cve": "CVE-2023-21965",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
"text": "34858461"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-2025V-6.4.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-2025V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.7,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-2025V-6.4.0.0.0"
]
}
]
},
{
"cve": "CVE-2023-21966",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34867398"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: JSON). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Jonathan Looney"
],
"organization": "Netflix"
}
],
"cve": "CVE-2023-21967",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Java SE",
"text": "34873207"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-856V-Oracle Java SE:20",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1",
"P-856V-Oracle Java SE:11.0.18"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-856V-Oracle Java SE:20",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1",
"P-856V-Oracle Java SE:11.0.18"
],
"url": "https://support.oracle.com/rs?type=doc&id=2935948.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-856V-Oracle Java SE:20",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1",
"P-856V-Oracle Java SE:11.0.18"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Adam Reziouk"
],
"organization": "Airbus Cyber Vulnerabilities Service"
}
],
"cve": "CVE-2023-21968",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Java SE",
"text": "34878495"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-856V-Oracle Java SE:20",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1",
"P-856V-Oracle Java SE:11.0.18"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-856V-Oracle Java SE:20",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1",
"P-856V-Oracle Java SE:11.0.18"
],
"url": "https://support.oracle.com/rs?type=doc&id=2935948.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 3.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"P-856V-Oracle Java SE:8u361-perf",
"P-856V-Oracle Java SE:8u361",
"P-856V-Oracle Java SE:17.0.6",
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-856V-Oracle Java SE:20",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1",
"P-856V-Oracle Java SE:11.0.18"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Emad Al-Mousa"
],
"organization": "Saudi Aramco"
}
],
"cve": "CVE-2023-21969",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle SQL Developer",
"text": "35137077"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in Oracle SQL Developer (component: Installation). Supported versions that are affected are Prior to 23.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle SQL Developer executes to compromise Oracle SQL Developer. Successful attacks of this vulnerability can result in takeover of Oracle SQL Developer. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1875V-Prior to 23.1.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1875V-Prior to 23.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.7,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-1875V-Prior to 23.1.0"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Khanh Nguyen Duy Quoc"
]
}
],
"cve": "CVE-2023-21970",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle BI Publisher",
"text": "34907573"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Security). The supported version that is affected is 6.4.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1479V-6.4.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1479V-6.4.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936091.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.7,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-1479V-6.4.0.0.0"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Roman Wagner"
],
"organization": "Code Intelligence"
}
],
"cve": "CVE-2023-21971",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Connectors",
"text": "34918989"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors as well as unauthorized update, insert or delete access to some of MySQL Connectors accessible data and unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8576V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8576V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H",
"version": "3.1"
},
"products": [
"P-8576V-8.0.32 and prior"
]
}
]
},
{
"cve": "CVE-2023-21972",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34933045"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior"
]
}
]
},
{
"cve": "CVE-2023-21973",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle iProcurement",
"text": "34937704"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle iProcurement product of Oracle E-Business Suite (component: E-Content Manager Catalog). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iProcurement. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iProcurement, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle iProcurement accessible data as well as unauthorized read access to a subset of Oracle iProcurement accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-398V-12.2.3-12.2.12"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-398V-12.2.3-12.2.12"
],
"url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-398V-12.2.3-12.2.12"
]
}
]
},
{
"cve": "CVE-2023-21976",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34985359"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior"
]
}
]
},
{
"cve": "CVE-2023-21977",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "34986665"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Sharique Raza"
]
}
],
"cve": "CVE-2023-21978",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Application Object Library",
"text": "34989140"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: GUI). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Object Library accessible data as well as unauthorized read access to a subset of Oracle Application Object Library accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Application Object Library. CVSS 3.1 Base Score 6.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-510V-12.2.3-12.2.11"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-510V-12.2.3-12.2.11"
],
"url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L",
"version": "3.1"
},
"products": [
"P-510V-12.2.3-12.2.11"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"ADLab"
],
"organization": "Venustech"
},
{
"names": [
"aw0yo"
],
"organization": "Cyber KunLun"
},
{
"names": [
"Lai Han"
]
},
{
"names": [
"Liboheng"
],
"organization": "Tophant Starlight laboratory"
}
],
"cve": "CVE-2023-21979",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "35039991"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0",
"P-5242V-14.1.1.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Alex Rubin"
],
"organization": "Amazon Web Services IT Security"
},
{
"names": [
"Dan Urson"
],
"organization": "Amazon Web Services IT Security"
},
{
"names": [
"Martin Rakhmanov"
],
"organization": "Amazon Web Services IT Security"
}
],
"cve": "CVE-2023-21980",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "35054579"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 5.7.41 and prior and 8.0.32 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior",
"P-8478V-5.7.41 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior",
"P-8478V-5.7.41 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior",
"P-8478V-5.7.41 and prior"
]
}
]
},
{
"cve": "CVE-2023-21981",
"ids": [
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
"text": "35056430"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5085V-8.58",
"P-5085V-8.60",
"P-5085V-8.59"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5085V-8.58",
"P-5085V-8.59",
"P-5085V-8.60"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939793.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-5085V-8.58",
"P-5085V-8.59",
"P-5085V-8.60"
]
}
]
},
{
"cve": "CVE-2023-21982",
"ids": [
{
"system_name": "Oracle Bug ID of MySQL Server",
"text": "35061924"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8478V-8.0.32 and prior"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8478V-8.0.32 and prior"
],
"url": "https://support.oracle.com/rs?type=doc&id=2937307.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-8478V-8.0.32 and prior"
]
}
]
},
{
"cve": "CVE-2023-21984",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Solaris",
"text": "35121585"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Libraries). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10006V-11"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10006V-11"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940069.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-10006V-11"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Jean-Michel Huguet from NATO Cyber Security Centre (NCSC)"
]
},
{
"names": [
"Jerome Nokin from NATO Cyber Security Centre (NCSC)"
]
}
],
"cve": "CVE-2023-21985",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Solaris",
"text": "35157460"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.1 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10006V-10",
"P-10006V-11"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10006V-10",
"P-10006V-11"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940069.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-10006V-10",
"P-10006V-11"
]
}
]
},
{
"cve": "CVE-2023-21986",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle GraalVM Enterprise Edition",
"text": "35176597"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Native Image). Supported versions that are affected are Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle GraalVM Enterprise Edition executes to compromise Oracle GraalVM Enterprise Edition. While the vulnerability is in Oracle GraalVM Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle GraalVM Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GraalVM Enterprise Edition. CVSS 3.1 Base Score 5.7 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2935948.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.7,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L",
"version": "3.1"
},
"products": [
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Bien Pham"
],
"organization": "Qrious Security working with Trend Micro's Zero Day Initiative"
},
{
"names": [
"Thomas Bouzerar (MajorTomSec) from Synacktiv"
]
}
],
"cve": "CVE-2023-21987",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle VM VirtualBox",
"text": "35210486"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940494.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Thomas Bouzerar (MajorTomSec) from Synacktiv"
]
}
],
"cve": "CVE-2023-21988",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle VM VirtualBox",
"text": "35215887"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940494.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 3.8,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Dungdm (piers2)"
],
"organization": "Viettel Cyber Security working with Trend Micro's Zero Day Initiative"
}
],
"cve": "CVE-2023-21989",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle VM VirtualBox",
"text": "35216402"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940494.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.0,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Dungdm (piers2)"
],
"organization": "Viettel Cyber Security working with Trend Micro's Zero Day Initiative"
}
],
"cve": "CVE-2023-21990",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle VM VirtualBox",
"text": "35216431"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940494.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.2,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Bien Pham"
],
"organization": "Qrious Security working with Trend Micro's Zero Day Initiative"
}
],
"cve": "CVE-2023-21991",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle VM VirtualBox",
"text": "35216571"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940494.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 3.2,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
}
]
},
{
"cve": "CVE-2023-21992",
"ids": [
{
"system_name": "Oracle Bug ID of PeopleSoft Enterprise HCM Human Resources",
"text": "34792153"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Administer Workforce). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human Resources. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM Human Resources accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise HCM Human Resources accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5071V-9.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5071V-9.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939793.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-5071V-9.2"
]
}
]
},
{
"cve": "CVE-2023-21993",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Clinical Remote Data Capture",
"text": "35227378"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Clinical Remote Data Capture product of Oracle Health Sciences Applications (component: Forms). The supported version that is affected is 5.4.0.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Clinical Remote Data Capture. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Clinical Remote Data Capture accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1041V-5.4.0.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1041V-5.4.0.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938697.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-1041V-5.4.0.2"
]
}
]
},
{
"cve": "CVE-2023-21996",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "35038260"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0",
"P-5242V-14.1.1.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-5242V-14.1.1.0.0",
"P-5242V-12.2.1.3.0",
"P-5242V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2023-21997",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle User Management",
"text": "35041116"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle User Management accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-1475V-12.2.3-12.2.12"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1475V-12.2.3-12.2.12"
],
"url": "https://support.oracle.com/rs?type=doc&id=2484000.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-1475V-12.2.3-12.2.12"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Aobo Wang"
],
"organization": "Chaitin Security Research Lab"
},
{
"names": [
"Kun Yang"
],
"organization": "Chaitin Security Research Lab"
}
],
"cve": "CVE-2023-21998",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle VM VirtualBox",
"text": "34944265"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data as well as unauthorized read access to a subset of Oracle VM VirtualBox accessible data. Note: This vulnerability applies to Windows VMs only. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940494.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.6,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Lu Yu"
],
"organization": "Chaitin Security Research Lab"
}
],
"cve": "CVE-2023-21999",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle VM VirtualBox",
"text": "34988279"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data as well as unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940494.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 3.6,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Lu Yu"
],
"organization": "Chaitin Security Research Lab"
}
],
"cve": "CVE-2023-22000",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle VM VirtualBox",
"text": "34988285"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data as well as unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940494.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.6,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Luo Likang"
],
"organization": "NSFOCUS TIANJI Lab"
}
],
"cve": "CVE-2023-22001",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle VM VirtualBox",
"text": "35064434"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data as well as unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940494.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.6,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"products": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
}
]
},
{
"acknowledgments": [
{
"names": [
"Richard A. Chaaya (RAC)"
]
}
],
"cve": "CVE-2023-22002",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle VM VirtualBox",
"text": "35107937"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.44 and Prior to 7.0.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940494.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.0,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N",
"version": "3.1"
},
"products": [
"P-8370V-Prior to 7.0.8",
"P-8370V-Prior to 6.1.44"
]
}
]
},
{
"cve": "CVE-2023-22003",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Solaris",
"text": "34162408"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Solaris accessible data. CVSS 3.1 Base Score 3.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-10006V-10",
"P-10006V-11"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10006V-10",
"P-10006V-11"
],
"url": "https://support.oracle.com/rs?type=doc&id=2940069.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 3.3,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
"version": "3.1"
},
"products": [
"P-10006V-10",
"P-10006V-11"
]
}
]
},
{
"cve": "CVE-2023-22899",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Access Manager",
"text": "35012645"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Third Party (Zip4j)). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Access Manager accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-5565V-12.2.1.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5565V-12.2.1.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"P-5565V-12.2.1.4.0"
]
}
]
},
{
"cve": "CVE-2023-23914",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "35182060"
},
{
"system_name": "Oracle Bug ID of Oracle Healthcare Translational Research",
"text": "35182066"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Essbase (component: Essbase Web Platform (cURL)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Translational Research product of Oracle HealthCare Applications (component: DataStudio (cURL)). Supported versions that are affected are 4.1.0 and 4.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Translational Research. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Translational Research accessible data as well as unauthorized access to critical data or complete access to all Oracle Healthcare Translational Research accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
],
"known_not_affected": [
"P-4379V-21.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4379V-21.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939153.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-4379V-21.4"
]
},
{
"cvss_v3": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
]
}
]
},
{
"cve": "CVE-2023-23915",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "35182060"
},
{
"system_name": "Oracle Bug ID of Oracle Healthcare Translational Research",
"text": "35182066"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Essbase (component: Essbase Web Platform (cURL)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Translational Research product of Oracle HealthCare Applications (component: DataStudio (cURL)). Supported versions that are affected are 4.1.0 and 4.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Translational Research. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Translational Research accessible data as well as unauthorized access to critical data or complete access to all Oracle Healthcare Translational Research accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
],
"known_not_affected": [
"P-4379V-21.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4379V-21.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939153.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-4379V-21.4"
]
},
{
"cvss_v3": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
]
}
]
},
{
"cve": "CVE-2023-23916",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Essbase",
"text": "35182060"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Configuration Console",
"text": "35190927"
},
{
"system_name": "Oracle Bug ID of Oracle Healthcare Translational Research",
"text": "35182066"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Unified Data Repository",
"text": "35191061"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
"text": "35184965"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
"text": "35176502"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Oracle Linux (cURL)). Supported versions that are affected are 22.4.2 and 23.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle Essbase (component: Essbase Web Platform (cURL)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Translational Research product of Oracle HealthCare Applications (component: DataStudio (cURL)). Supported versions that are affected are 4.1.0 and 4.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Translational Research. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Healthcare Translational Research accessible data as well as unauthorized access to critical data or complete access to all Oracle Healthcare Translational Research accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (cURL)). Supported versions that are affected are 23.1.0 and 22.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Configuration Console product of Oracle Communications (component: Configuration (cURL)). Supported versions that are affected are 22.4.1 and 23.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Configuration Console. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Configuration Console. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Unified Data Repository product of Oracle Communications (component: Signaling (cURL)). The supported version that is affected is 22.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Unified Data Repository. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Unified Data Repository. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9427V-4.1.0",
"P-14123V-23.1.0",
"P-9427V-4.1.1",
"P-14250V-23.1.0",
"P-14119V-22.4.1",
"P-14122V-23.1.0",
"P-14122V-22.4.2",
"P-14250V-22.4.1",
"P-14123V-22.4.2"
],
"known_not_affected": [
"P-4379V-21.4"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14122V-23.1.0",
"P-14122V-22.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938420.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-4379V-21.4"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939153.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14123V-23.1.0",
"P-14123V-22.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938437.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14250V-23.1.0",
"P-14250V-22.4.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938418.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14119V-22.4.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938438.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14123V-23.1.0",
"P-14250V-23.1.0",
"P-14119V-22.4.1",
"P-14122V-23.1.0",
"P-14122V-22.4.2",
"P-14250V-22.4.1",
"P-14123V-22.4.2"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-4379V-21.4"
]
},
{
"cvss_v3": {
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"products": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
]
}
]
},
{
"cve": "CVE-2023-23918",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle GraalVM Enterprise Edition",
"text": "35096633"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Node (Node.js)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2935948.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1"
]
}
]
},
{
"cve": "CVE-2023-23919",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle GraalVM Enterprise Edition",
"text": "35096633"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Node (Node.js)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2935948.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1"
]
}
]
},
{
"cve": "CVE-2023-23920",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle GraalVM Enterprise Edition",
"text": "35096633"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Node (Node.js)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2935948.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1"
]
}
]
},
{
"cve": "CVE-2023-23931",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
"text": "35120824"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
"text": "35120819"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Cryptography)). The supported version that is affected is 22.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Network Exposure Function accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Installation and Configuration (Cryptography)). Supported versions that are affected are 22.4.0 and 23.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14123V-23.1.0",
"P-14122V-22.4.2",
"P-14123V-22.4.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14122V-22.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938420.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14123V-23.1.0",
"P-14123V-22.4.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938437.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
"version": "3.1"
},
"products": [
"P-14123V-23.1.0",
"P-14122V-22.4.2",
"P-14123V-22.4.0"
]
}
]
},
{
"cve": "CVE-2023-23934",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "35196359"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Werkzeug)). Supported versions that are affected are 22.4.0-22.4.4 and 23.1.0-23.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938436.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
]
}
]
},
{
"cve": "CVE-2023-23936",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle GraalVM Enterprise Edition",
"text": "35096633"
}
],
"notes": [
{
"category": "description",
"text": "Security-in-Depth issue in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Node (Node.js)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_not_affected": [
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2935948.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13497V-Oracle GraalVM Enterprise Edition:20.3.9",
"P-13497V-Oracle GraalVM Enterprise Edition:21.3.5",
"P-13497V-Oracle GraalVM Enterprise Edition:22.3.1"
]
}
]
},
{
"cve": "CVE-2023-24998",
"ids": [
{
"system_name": "Oracle Bug ID of Spatial and Graph (Apache Commons Fileupload)",
"text": "35154926"
},
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "35118583"
},
{
"system_name": "Oracle Bug ID of Oracle Database Server",
"text": "35175940"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Network Exposure Function",
"text": "35170830"
},
{
"system_name": "Oracle Bug ID of Oracle Banking APIs",
"text": "35170810"
},
{
"system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
"text": "35132983"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Element Manager",
"text": "35170842"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
"text": "35170833"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
"text": "35170844"
},
{
"system_name": "Oracle Bug ID of Oracle REST Data Services",
"text": "35170847"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Digital Experience",
"text": "35170816"
},
{
"system_name": "Oracle Bug ID of Oracle WebLogic Server",
"text": "35170849"
},
{
"system_name": "Oracle Bug ID of Oracle Documaker",
"text": "35170848"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console (Apache Commons FileUpload)). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Third Party (Apache Commons FileUpload)). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Middleware Common Libraries and Tools. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Spatial and Graph (Apache Commons Fileupload) component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via HTTP to compromise Spatial and Graph (Apache Commons Fileupload). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Spatial and Graph (Apache Commons Fileupload). CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking APIs product of Oracle Financial Services Applications (component: IDM - Authentication (Apache Commons FileUpload)). Supported versions that are affected are 18.2, 18.3, 19.1, 19.2, 21.1, 22.1 and 22.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking APIs. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking APIs. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: UI General (Apache Commons FileUpload)). Supported versions that are affected are 18.2, 18.3, 19.1, 19.2, 21.1, 22.1 and 22.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Digital Experience. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Banking Digital Experience. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Network Exposure Function product of Oracle Communications (component: Platform (Apache Commons FileUpload)). Supported versions that are affected are 22.4.2 and 23.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Network Exposure Function. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Network Exposure Function. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: Configuration (Apache Commons FileUpload)). Supported versions that are affected are 23.1.0 and 22.4.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Security Edge Protection Proxy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: BEServer (Apache Commons FileUpload)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Element Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Element Manager. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: BEServer (Apache Commons FileUpload)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Report Manager. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in Oracle REST Data Services (component: Oracle REST Data Services (Apache Commons FileUpload)). Supported versions that are affected are Prior to 23.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle REST Data Services. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle REST Data Services. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Documaker product of Oracle Insurance Applications (component: Development Tools (Apache Commons FileUpload)). Supported versions that are affected are 12.6.0.0.0, 12.6.2.0.0-12.6.4.0.0, 12.7.0.0.0 and 12.7.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Documaker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Documaker. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Third Party (Apache Commons FileUpload)). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Database Workload Manager (Apache Commons FileUpload) component of Oracle Database Server. The supported version that is affected is 21c. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via HTTP to compromise Oracle Database Workload Manager (Apache Commons FileUpload). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Database Workload Manager (Apache Commons FileUpload). CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14123V-23.1.0",
"P-13676V-21.1",
"P-14122V-23.1.0",
"P-5242(Third Party)V-14.1.1.0.0",
"P-12605V-18.2",
"P-12605V-19.1",
"P-5477V-12.7.0.0.0",
"P-13676V-22.1",
"P-13676V-22.2",
"P-9456V-Prior to 23.1.0",
"P-5242(Console)V-14.1.1.0.0",
"P-5477V-12.7.1.0.0",
"P-619V-19c",
"P-5242(Third Party)V-12.2.1.4.0",
"P-5242(Third Party)V-12.2.1.3.0",
"P-14122V-22.4.2",
"P-619V-21c",
"P-12605V-18.3",
"P-12605V-19.2",
"P-14123V-22.4.1",
"P-5477V-12.6.0.0.0",
"P-11052V-9.0.1",
"P-10770V-9.0.1",
"P-11052V-9.0.0",
"P-10770V-9.0.0",
"P-5(Oracle Database Workload Manager)V-21c",
"P-12605V-22.2",
"P-4647V-12.2.1.4.0",
"P-12605V-21.1",
"P-12605V-22.1",
"P-5242(Console)V-12.2.1.3.0",
"P-13676V-18.2",
"P-13676V-19.1",
"P-5477V-12.6.2.0.0-12.6.4.0.0",
"P-5242(Console)V-12.2.1.4.0",
"P-13676V-18.3",
"P-13676V-19.2"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5242(Third Party)V-12.2.1.4.0",
"P-5242(Third Party)V-12.2.1.3.0",
"P-4647V-12.2.1.4.0",
"P-5242(Third Party)V-14.1.1.0.0",
"P-5242(Console)V-12.2.1.3.0",
"P-5242(Console)V-12.2.1.4.0",
"P-5242(Console)V-14.1.1.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936090.2"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-619V-19c",
"P-5(Oracle Database Workload Manager)V-21c",
"P-9456V-Prior to 23.1.0",
"P-619V-21c"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13676V-21.1",
"P-12605V-18.3",
"P-12605V-19.2",
"P-12605V-18.2",
"P-12605V-19.1",
"P-13676V-22.1",
"P-12605V-22.2",
"P-13676V-22.2",
"P-12605V-21.1",
"P-12605V-22.1",
"P-13676V-18.2",
"P-13676V-19.1",
"P-13676V-18.3",
"P-13676V-19.2"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14122V-23.1.0",
"P-14122V-22.4.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938420.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14123V-23.1.0",
"P-14123V-22.4.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938437.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11052V-9.0.1",
"P-11052V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938441.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10770V-9.0.1",
"P-10770V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938447.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5477V-12.7.1.0.0",
"P-5477V-12.6.0.0.0",
"P-5477V-12.7.0.0.0",
"P-5477V-12.6.2.0.0-12.6.4.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939209.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14123V-23.1.0",
"P-13676V-21.1",
"P-14122V-23.1.0",
"P-5242(Third Party)V-14.1.1.0.0",
"P-12605V-18.2",
"P-12605V-19.1",
"P-5477V-12.7.0.0.0",
"P-13676V-22.1",
"P-13676V-22.2",
"P-5242(Console)V-14.1.1.0.0",
"P-5477V-12.7.1.0.0",
"P-5242(Third Party)V-12.2.1.4.0",
"P-5242(Third Party)V-12.2.1.3.0",
"P-14122V-22.4.2",
"P-12605V-18.3",
"P-12605V-19.2",
"P-14123V-22.4.1",
"P-5477V-12.6.0.0.0",
"P-11052V-9.0.1",
"P-10770V-9.0.1",
"P-11052V-9.0.0",
"P-10770V-9.0.0",
"P-12605V-22.2",
"P-4647V-12.2.1.4.0",
"P-12605V-21.1",
"P-12605V-22.1",
"P-5242(Console)V-12.2.1.3.0",
"P-13676V-18.2",
"P-13676V-19.1",
"P-5477V-12.6.2.0.0-12.6.4.0.0",
"P-5242(Console)V-12.2.1.4.0",
"P-13676V-18.3",
"P-13676V-19.2"
]
},
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-619V-19c",
"P-5(Oracle Database Workload Manager)V-21c",
"P-9456V-Prior to 23.1.0",
"P-619V-21c"
]
}
]
},
{
"cve": "CVE-2023-25136",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Healthcare Translational Research",
"text": "35166892"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Healthcare Translational Research product of Oracle HealthCare Applications (component: DataStudio (OpenSSH)). Supported versions that are affected are 4.1.0 and 4.1.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Translational Research. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Healthcare Translational Research as well as unauthorized update, insert or delete access to some of Oracle Healthcare Translational Research accessible data. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939153.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
"version": "3.1"
},
"products": [
"P-9427V-4.1.0",
"P-9427V-4.1.1"
]
}
]
},
{
"cve": "CVE-2023-25194",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle SQL Developer",
"text": "35127365"
},
{
"system_name": "Oracle Bug ID of Oracle Banking Digital Experience",
"text": "35127289"
},
{
"system_name": "Oracle Bug ID of Oracle Banking APIs",
"text": "35127284"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Regulatory Reporting",
"text": "35127340"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Analytical Applications Infrastructure",
"text": "35127319"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Behavior Detection Platform",
"text": "35127323"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Banking APIs product of Oracle Financial Services Applications (component: IDM - Authentication (Apache Kafka)). Supported versions that are affected are 22.1 and 22.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking APIs. Successful attacks of this vulnerability can result in takeover of Oracle Banking APIs. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: UI General (Apache Kafka)). Supported versions that are affected are 22.1 and 22.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Digital Experience. Successful attacks of this vulnerability can result in takeover of Oracle Banking Digital Experience. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (Apache Kafka)). Supported versions that are affected are 8.0.7.0, 8.0.8.0, 8.0.9.0, 8.1.0.0, 8.1.1.0, 8.1.2.0, 8.1.2.1 and 8.1.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Behavior Detection Platform product of Oracle Financial Services Applications (component: Application (Apache Kafka)). Supported versions that are affected are 8.0.8.1, 8.1.1.1, 8.1.2.3 and 8.1.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Behavior Detection Platform. Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Behavior Detection Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Regulatory Reporting product of Oracle Financial Services Applications (component: Application (Apache Kafka)). Supported versions that are affected are 8.0.8.1, 8.1.1.1, 8.1.2.3 and 8.1.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Regulatory Reporting. Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Regulatory Reporting. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Security-in-Depth issue in Oracle SQL Developer (component: Installation (Apache Kafka)). This vulnerability cannot be exploited in the context of this product.",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-9190V-8.1.2.3",
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-5680V-8.0.7.0",
"P-9190V-8.1.2.4",
"P-9142V-8.1.2.4",
"P-9142V-8.1.2.3",
"P-9142V-8.1.1.1",
"P-9142V-8.0.8.1",
"P-13676V-22.1",
"P-12605V-22.2",
"P-13676V-22.2",
"P-9190V-8.0.8.1",
"P-12605V-22.1",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5680V-8.1.2.2",
"P-9190V-8.1.1.1"
],
"known_not_affected": [
"P-1875V-Prior to 23.1.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13676V-22.1",
"P-12605V-22.2",
"P-13676V-22.2",
"P-12605V-22.1"
],
"url": "https://support.oracle.com"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-5680V-8.0.7.0",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5680V-8.1.2.2"
],
"url": "https://support.oracle.com/rs?type=doc&id=2939767.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9190V-8.1.2.3",
"P-9190V-8.1.2.4",
"P-9190V-8.0.8.1",
"P-9190V-8.1.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936356.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-9142V-8.0.8.1",
"P-9142V-8.1.2.4",
"P-9142V-8.1.2.3",
"P-9142V-8.1.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936339.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-1875V-Prior to 23.1.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2923348.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-9190V-8.1.2.3",
"P-5680V-8.0.9.0",
"P-5680V-8.0.8.0",
"P-5680V-8.0.7.0",
"P-9190V-8.1.2.4",
"P-9142V-8.1.2.4",
"P-9142V-8.1.2.3",
"P-9142V-8.1.1.1",
"P-9142V-8.0.8.1",
"P-13676V-22.1",
"P-12605V-22.2",
"P-13676V-22.2",
"P-9190V-8.0.8.1",
"P-12605V-22.1",
"P-5680V-8.1.1.0",
"P-5680V-8.1.0.0",
"P-5680V-8.1.2.1",
"P-5680V-8.1.2.0",
"P-5680V-8.1.2.2",
"P-9190V-8.1.1.1"
]
},
{
"cvss_v3": {
"baseScore": 0.0,
"baseSeverity": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N",
"version": "3.1"
},
"products": [
"P-1875V-Prior to 23.1.0"
]
}
]
},
{
"cve": "CVE-2023-25577",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Policy",
"text": "35196359"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Core Policy product of Oracle Communications (component: Policy (Werkzeug)). Supported versions that are affected are 22.4.0-22.4.4 and 23.1.0-23.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Cloud Native Core Policy. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Cloud Native Core Policy. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938436.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"P-14277V-22.4.0-22.4.4",
"P-14277V-23.1.0-23.1.1"
]
}
]
},
{
"cve": "CVE-2023-25613",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Cloud Native Configuration Console",
"text": "35190775"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Cloud Native Configuration Console product of Oracle Communications (component: Configuration (Apache Kerby)). Supported versions that are affected are 22.4.1 and 23.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Cloud Native Configuration Console. Successful attacks of this vulnerability can result in takeover of Oracle Communications Cloud Native Configuration Console. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-14250V-22.4.1",
"P-14250V-23.1.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-14250V-23.1.0",
"P-14250V-22.4.1"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938418.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-14250V-23.1.0",
"P-14250V-22.4.1"
]
}
]
},
{
"cve": "CVE-2023-25690",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
"text": "35218773"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Element Manager",
"text": "35218771"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: FEServer (Apache HTTP Server)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Element Manager. Successful attacks of this vulnerability can result in takeover of Oracle Communications Element Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: FEServer (Apache HTTP Server)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Report Manager. Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11052V-9.0.1",
"P-10770V-9.0.1",
"P-11052V-9.0.0",
"P-10770V-9.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11052V-9.0.1",
"P-11052V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938441.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10770V-9.0.1",
"P-10770V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938447.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-11052V-9.0.1",
"P-10770V-9.0.1",
"P-11052V-9.0.0",
"P-10770V-9.0.0"
]
}
]
},
{
"cve": "CVE-2023-27522",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Session Report Manager",
"text": "35218773"
},
{
"system_name": "Oracle Bug ID of Oracle Communications Element Manager",
"text": "35218771"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: FEServer (Apache HTTP Server)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Element Manager. Successful attacks of this vulnerability can result in takeover of Oracle Communications Element Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: FEServer (Apache HTTP Server)). Supported versions that are affected are 9.0.0 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Report Manager. Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-11052V-9.0.1",
"P-10770V-9.0.1",
"P-11052V-9.0.0",
"P-10770V-9.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-11052V-9.0.1",
"P-11052V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938441.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10770V-9.0.1",
"P-10770V-9.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938447.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"P-11052V-9.0.1",
"P-10770V-9.0.1",
"P-11052V-9.0.0",
"P-10770V-9.0.0"
]
}
]
},
{
"cve": "CVE-2023-28708",
"ids": [
{
"system_name": "Oracle Bug ID of Oracle Communications Policy Management",
"text": "35269907"
},
{
"system_name": "Oracle Bug ID of Oracle Financial Services Crime and Compliance Management Studio",
"text": "35269913"
}
],
"notes": [
{
"category": "description",
"text": "Vulnerability in the Oracle Communications Policy Management product of Oracle Communications (component: Core (Apache Tomcat)). The supported version that is affected is 12.6.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Communications Policy Management accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N).",
"title": "Vulnerability Description"
},
{
"category": "description",
"text": "Vulnerability in the Oracle Financial Services Crime and Compliance Management Studio product of Oracle Financial Services Applications (component: Studio (Apache Tomcat)). The supported version that is affected is 8.0.8.3.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Crime and Compliance Management Studio. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Financial Services Crime and Compliance Management Studio accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N).",
"title": "Vulnerability Description"
}
],
"product_status": {
"known_affected": [
"P-13595V-8.0.8.3.5",
"P-10900V-12.6.0.0.0"
]
},
"remediations": [
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-10900V-12.6.0.0.0"
],
"url": "https://support.oracle.com/rs?type=doc&id=2938443.1"
},
{
"category": "vendor_fix",
"details": "Oracle customers with valid support contracts",
"product_ids": [
"P-13595V-8.0.8.3.5"
],
"url": "https://support.oracle.com/rs?type=doc&id=2936386.1"
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"products": [
"P-13595V-8.0.8.3.5",
"P-10900V-12.6.0.0.0"
]
}
]
}
]
}